|
51
|
9.1 |
CRITICAL
Network
|
-
|
-
|
FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to 1.3.1-stable and 1.3.9-beta, attacker-controlled path input is joined with a trusted base path prior to sanitization, allo…
New
|
CWE-22
Path Traversal
|
CVE-2026-44542
|
2026-05-15 03:26 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
52
|
8.3 |
HIGH
Network
|
-
|
-
|
The HCL BigFix SCM Reporting site contains an outdated and unsupported version of the jQuery 1.x library. Since jQuery 1.x has reached end-of-life and no longer receives security updates, it may expo…
New
|
CWE-1104
Use of Unmaintained Third Party Components
|
CVE-2026-21821
|
2026-05-15 03:24 |
2026-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
53
|
4.3 |
MEDIUM
Network
|
-
|
-
|
CWE-601 URL redirection to untrusted site ('open redirect')
New
|
CWE-601
Open Redirect
|
CVE-2026-45448
|
2026-05-15 03:24 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
54
|
3.8 |
LOW
Physics
|
-
|
-
|
A side-channel attack, which requires a physical presence to the TPM, can lead to extraction of an Elliptic Curve Diffie-Hellman (ECDH) key.
New
|
CWE-1300
Improper Protection of Physical Side Channels
|
CVE-2026-6923
|
2026-05-15 03:24 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
55
|
4.0 |
MEDIUM
Local
|
-
|
-
|
An issue was discovered in GStreamer gst-plugins-good before 1.28.2. When parsing MP4 audio tracks, the isomp4 plugin's qtdemux_parse_trak function does not sufficiently validate atom data before per…
New
|
CWE-369
Divide By Zero
|
CVE-2026-46469
|
2026-05-15 03:24 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
56
|
4.0 |
MEDIUM
Local
|
-
|
-
|
An issue was discovered in GStreamer gst-plugins-good before 1.28.2. When parsing MP4 audio tracks, the isomp4 plugin's qtdemux_audio_caps function does not sufficiently validate atom data before per…
New
|
CWE-369
Divide By Zero
|
CVE-2026-46470
|
2026-05-15 03:24 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
57
|
- |
|
-
|
-
|
CWE-312: Cleartext Storage of Sensitive Information vulnerability exists that could cause the disclosure of a sensitive information which could result in revealing protected source code and loss of …
New
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2026-6332
|
2026-05-15 03:24 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
58
|
9.6 |
CRITICAL
Network
|
-
|
-
|
Exposure of sensitive information to an unauthorized actor in Microsoft Authenticator allows an unauthorized attacker to disclose information over a network.
New
|
CWE-200
Information Exposure
|
CVE-2026-41615
|
2026-05-15 03:19 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
59
|
8.1 |
HIGH
Network
|
-
|
-
|
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-42897
|
2026-05-15 03:19 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
60
|
9.8 |
CRITICAL
Network
|
vm2_project
|
vm2
|
vm2 is an open source vm/sandbox for Node.js. Prior to 3.11.3, it is possible to catch a host exception using the yield* expression inside an async generator. When the generator is closed using the r…
New
|
CWE-668
Exposure of Resource to Wrong Sphere
|
CVE-2026-45411
|
2026-05-15 03:19 |
2026-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|