|
121
|
8.8 |
HIGH
Network
|
-
|
-
|
Twig versions 2.16.x and 3.9.0 through 3.25.x contain a sandbox bypass vulnerability when using a SourcePolicyInterface that allows attackers with template rendering capabilities to pass arbitrary PH…
New
|
CWE-693
Protection Mechanism Failure
|
CVE-2026-24425
|
2026-05-20 23:25 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
122
|
7.3 |
HIGH
Network
|
-
|
-
|
An authorization vulnerability exists in Innoshop 0.6.0. After logging into the frontend, an attacker can directly access backend application interfaces, leading to further dangerous operations.
New
|
CWE-284
Improper Access Control
|
CVE-2026-39250
|
2026-05-20 23:25 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
123
|
4.3 |
MEDIUM
Network
|
-
|
-
|
Missing authorization vulnerability exists in Movable Type. Under certain conditions, when a user without administrator privileges signs in to the product, unintended update processing may be execute…
New
|
CWE-862
Missing Authorization
|
CVE-2026-44392
|
2026-05-20 23:25 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
124
|
8.1 |
HIGH
Network
|
-
|
-
|
In memcached before 1.6.42, username data for SASL password database authentication has a timing side channel because a loop exits as soon as a valid username is found by sasl_server_userdb_checkpass.
New
|
CWE-208
Information Exposure Through Timing Discrepancy
|
CVE-2026-47783
|
2026-05-20 23:24 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
125
|
8.1 |
HIGH
Network
|
-
|
-
|
In memcached before 1.6.42, password data for SASL password database authentication has a timing side channel because memcmp is used by sasl_server_userdb_checkpass.
New
|
CWE-208
Information Exposure Through Timing Discrepancy
|
CVE-2026-47784
|
2026-05-20 23:24 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
126
|
4.0 |
MEDIUM
Local
|
-
|
-
|
HCL BigFix Service Management (SM) is susceptible to a Configuration – 'Insecure Use of Base Image Version'. Using outdated or insecure base images may introduce known vulnerabilities, potentially i…
New
|
-
|
CVE-2025-31973
|
2026-05-20 23:23 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
127
|
3.7 |
LOW
Network
|
-
|
-
|
HCL BigFix Service Management (SM) is affected by a security misconfiguration due to a missing or insecure “X-Content-Type-Options” header. This could allow browsers to perform MIME-type sniffing, p…
New
|
CWE-200
Information Exposure
|
CVE-2025-31985
|
2026-05-20 23:23 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
128
|
6.5 |
MEDIUM
Network
|
-
|
-
|
The HCL DominoIQ RAG feature is affected by a Broken Access Control vulnerability. Under certain circumstances, document level access restrictions will be ignored when determining what data to retur…
New
|
CWE-862
Missing Authorization
|
CVE-2026-21836
|
2026-05-20 23:23 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
129
|
6.5 |
MEDIUM
Adjacent
|
mozilla
|
firefox
|
Firefox for iOS hosted Reader mode on an unauthenticated local web server, allowing another application on the same device to request arbitrary URLs and receive the response rendered with the signed-…
New
|
CWE-200 CWE-306
Information Exposure Missing Authentication for Critical Function
|
CVE-2026-8706
|
2026-05-20 23:23 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
130
|
8.6 |
HIGH
Network
|
tenable
|
terrascan
|
Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via the webhook_url parameter in the file scan endpoint (POST /v1/{iac}/{iacVersion}/{cloud}/local/file/scan) when run…
New
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-47356
|
2026-05-20 23:23 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|