|
181
|
9.6 |
CRITICAL
Network
|
-
|
-
|
MeshCore Card provides MeshCore Lovelace card for Home Assistant. Prior to 0.3.3, Meshcore node names are rendered without HTML escaping in meshcore-card, allowing any node within direct or indirect …
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-45323
|
2026-05-30 01:25 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
182
|
8.3 |
HIGH
Network
|
-
|
-
|
Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2026.4.1 for iOS and 2026.4.4 for Android, he Home Assistant Companion apps for Android and …
New
|
CWE-94 CWE-346 CWE-749 CWE-940
Code Injection Origin Validation Error Exposed Dangerous Method or Function Improper Verification of Source of a Communication Channel
|
CVE-2026-44698
|
2026-05-30 01:25 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
183
|
- |
|
-
|
-
|
Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Prior to 10.9.6 and 11.15.0, Mermaid's default configuration allows injecting CSS that applies…
New
|
CWE-94
Code Injection
|
CVE-2026-41159
|
2026-05-30 01:25 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
184
|
7.5 |
HIGH
Network
|
google
|
chrome
|
Use after free in iOS in Google Chrome on iOS prior to 148.0.7778.216 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML pag…
New
|
CWE-416
Use After Free
|
CVE-2026-9956
|
2026-05-30 01:20 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
185
|
8.2 |
HIGH
Network
|
-
|
-
|
LangChain is a framework for building agents and LLM-powered applications. Prior to 0.3.85 and 1.3.3, LangChain contains older runtime code paths that deserialize run inputs, run outputs, or other ap…
New
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-44843
|
2026-05-30 01:19 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
186
|
- |
|
-
|
-
|
Prometheus is an open-source monitoring system and time series database. From 2.49.0 to before 3.5.3 and 3.11.3, in the Prometheus server's legacy web UI (enabled via the command-line flag --enable-f…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-44903
|
2026-05-30 01:19 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
187
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Starlette is a lightweight ASGI framework/toolkit. Prior to version 1.0.1, the HTTP `Host` request header was not validated before being used to reconstruct `request.url`. Because the routing algorit…
New
|
CWE-444
HTTP Request Smuggling
|
CVE-2026-48710
|
2026-05-30 01:19 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
188
|
- |
|
-
|
-
|
A Server-Side Request Forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an attacker to cause the server to issue HTTP requests to internal services via the security…
New
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-8606
|
2026-05-30 01:19 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
189
|
- |
|
-
|
-
|
A server-side request forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to send crafted requests to internal services by exploiting insu…
New
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-9312
|
2026-05-30 01:19 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
190
|
7.4 |
HIGH
Local
|
-
|
-
|
In GDAL 3.1.0 through 3.13.0, scanForGeometryContainers in the netCDF driver allows code execution via a stack-based buffer overflow. It reads a geometry attribute into a fixed-size stack buffer with…
New
|
CWE-121
Stack-based Buffer Overflow
|
CVE-2026-49014
|
2026-05-30 01:19 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|