|
231
|
9.1 |
CRITICAL
Network
|
ibm
|
aspera_high-speed_transfer_server_for_cloud_pak_for_integration
|
IBM Aspera HSTS for CP4I 1.5.1 through 1.5.19
Update
|
CWE-287 NVD-CWE-noinfo
Improper Authentication
|
CVE-2026-7876
|
2026-05-30 06:25 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
232
|
7.5 |
HIGH
Network
|
-
|
-
|
When processing a request with a URL path starting with /status or /sysinfo, WOSHttpStatusModule.dll is to be loaded to handle such URL patterns. The WOSBin_LoadHttpModule function in the dll would b…
Update
|
CWE-476
NULL Pointer Dereference
|
CVE-2026-8359
|
2026-05-30 05:26 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
233
|
7.5 |
HIGH
Network
|
-
|
-
|
Function calls to WOSCommonUtil.dll!WOSSysInfoGetDeviceInterface() in various DLLs (i.e., WOSProfileMgrModule.dll, WOSWebDavModule.dll) can return a NULL pointer (i.e., when no user is logged into th…
Update
|
CWE-476
NULL Pointer Dereference
|
CVE-2026-8360
|
2026-05-30 05:26 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
234
|
7.5 |
HIGH
Network
|
-
|
-
|
A path traversal vulnerability exists in WOSDefaultHttpModule.dll when processing a URL path starting with /woshome
Update
|
CWE-23
Relative Path Traversal
|
CVE-2026-8361
|
2026-05-30 05:26 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
235
|
9.8 |
CRITICAL
Network
|
-
|
-
|
A stack-based buffer overflow condition exists in WOSDefaultHttpModule.dll when processing a long URL path starting with /woshome
Update
|
CWE-121
Stack-based Buffer Overflow
|
CVE-2026-8362
|
2026-05-30 05:26 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
236
|
9.8 |
CRITICAL
Network
|
-
|
-
|
A stack-based buffer overflow condition exists in WOSDeviceDropFolder.dll when processing a long URL path starting with /resources:
Update
|
CWE-121
Stack-based Buffer Overflow
|
CVE-2026-8363
|
2026-05-30 05:26 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
237
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Gladinet Triofox Cloud Server Agent Access Service (GladServerAgentService.exe) listens on TCP port 7878 and processes remote HTTP messages with URL paths starting with /resources, /status, /sysinfo,…
Update
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2026-8364
|
2026-05-30 05:26 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
238
|
- |
|
-
|
-
|
A stored
cross-site scripting (XSS) vulnerability has been identified in the web
management interface of TP-Link's TL-SG108PE v5 switch due to improper sanitation of the SYSNAM
configuration paramete…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-34127
|
2026-05-30 05:25 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
239
|
7.7 |
HIGH
Network
|
-
|
-
|
FastGPT is an AI Agent building platform. Prior to 4.15.0-beta1, a Server-Side Request Forgery (SSRF) vulnerability allows an authenticated attacker to bypass the global isInternalAddress network pro…
New
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-44285
|
2026-05-30 05:23 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
240
|
6.3 |
MEDIUM
Network
|
-
|
-
|
FastGPT is an AI Agent building platform. Prior to 4.15.0-beta1, the JavaScript sandbox worker at projects/code-sandbox/src/pool/worker.ts:356 blocks dynamic import() with the regex /\bimport\s*\(/.t…
New
|
CWE-94 CWE-184
Code Injection Incomplete Blacklist
|
CVE-2026-44287
|
2026-05-30 05:23 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|