|
321
|
3.3 |
LOW
Local
|
-
|
-
|
A security flaw has been discovered in GNU LibreDWG up to 0.14. This impacts the function dwg_next_entity of the file src/decode.c of the component DWG File Handler. The manipulation results in null …
New
|
CWE-404 CWE-476
Improper Resource Shutdown or Release NULL Pointer Dereference
|
CVE-2026-9503
|
2026-05-26 06:16 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
322
|
5.3 |
MEDIUM
Local
|
-
|
-
|
A vulnerability was identified in GNU LibreDWG up to 0.14. This affects the function decompress_R2004_section of the file src/decode.c of the component Dwgread Utility. The manipulation leads to heap…
New
|
CWE-119 CWE-122
Incorrect Access of Indexable Resource ('Range Error') Heap-based Buffer Overflow
|
CVE-2026-9502
|
2026-05-26 06:16 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
323
|
3.3 |
LOW
Local
|
-
|
-
|
A vulnerability was determined in GNU LibreDWG up to 0.14. The impacted element is the function decompress_R2004_section of the file src/decode.c of the component Dwgread Utility. Executing a manipul…
New
|
CWE-617
Reachable Assertion
|
CVE-2026-9501
|
2026-05-26 06:16 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
324
|
3.7 |
LOW
Network
|
-
|
-
|
PuTTY 0.71 before 0.84 has an assertion failure in ECDSA signature verification.
New
|
CWE-617
Reachable Assertion
|
CVE-2026-48852
|
2026-05-26 06:16 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
325
|
3.1 |
LOW
Network
|
-
|
-
|
PuTTY 0.77 before 0.84 uses a copy of the PuTTY icon as a trust indication for TELNET data but the trust status is not cleared between proxy authentication and the main session.
New
|
CWE-451
User Interface (UI) Misrepresentation of Critical Information
|
CVE-2026-48851
|
2026-05-26 06:16 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
326
|
3.7 |
LOW
Network
|
-
|
-
|
PuTTY 0.72 before 0.84 has a double free in RSA KEX.
New
|
CWE-415
Double Free
|
CVE-2026-48850
|
2026-05-26 06:16 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
327
|
- |
|
-
|
-
|
Exposure of Sensitive Information Through Data Queries vulnerability in Apache Syncope.
An administrator with adequate entitlements for Derived Schemas can create a malicious JEXL expression which a…
New
|
CWE-202
Exposure of Sensitive Information Through Data Queries
|
CVE-2026-42797
|
2026-05-26 06:16 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
328
|
- |
|
-
|
-
|
Improper Isolation or Compartmentalization vulnerability in Apache Syncope.
An administrator with adequate entitlements for Implementations can create a malicious Groovy class containing untrusted c…
New
|
CWE-653
Improper Isolation or Compartmentalization
|
CVE-2026-42782
|
2026-05-26 06:16 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
329
|
4.3 |
MEDIUM
Network
|
-
|
-
|
Cross-Site Request Forgery (CSRF) vulnerability in WpDevArt Organization chart allows Cross Site Request Forgery.
This issue affects Organization chart: from n/a through 1.7.5.
New
|
CWE-352
Origin Validation Error
|
CVE-2026-24597
|
2026-05-26 06:16 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
330
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Cross-Site Request Forgery (CSRF) vulnerability in Recorp Export WP Page to Static HTML/CSS allows Cross Site Request Forgery.
This issue affects Export WP Page to Static HTML/CSS: from n/a through …
New
|
CWE-352
Origin Validation Error
|
CVE-2026-24574
|
2026-05-26 06:16 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|