|
541
|
- |
|
-
|
-
|
Mermaid is a JavaScript tool that uses Markdown-inspired text to create and modify diagrams and charts. Versions 10.9.5 and earlier, as well as 11.0.0-alpha.1 through 11.14.0, are vulnerable to HTML …
|
CWE-94
Code Injection
|
CVE-2026-41149
|
2026-05-23 13:16 |
2026-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
542
|
- |
|
-
|
-
|
Mantis Bug Tracker (MantisBT) is an open source issue tracker. In versions 2.28.1 and below, improper escaping of the redirection page (retrieved from the request's Referer header) allows an attacker…
|
CWE-79
Cross-site Scripting
|
CVE-2026-40598
|
2026-05-23 13:16 |
2026-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
543
|
6.5 |
MEDIUM
Network
|
-
|
-
|
TypeBot is a chatbot builder tool. In versions 3.16.0 and prior, the WhatsApp Cloud API webhook endpoint (POST /v1/workspaces/{workspaceId}/whatsapp/{credentialsId}/webhook) does not verify the x-hub…
|
CWE-287 CWE-345
Improper Authentication Insufficient Verification of Data Authenticity
|
CVE-2026-39969
|
2026-05-23 13:16 |
2026-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
544
|
5.4 |
MEDIUM
Network
|
-
|
-
|
TypeBot is a chatbot builder tool. In versions prior to 3.16.0, the Typebot viewer (packages/embeds/js) renders anchor tags from rich text bubble content without filtering the javascript: URI scheme.…
|
CWE-79
Cross-site Scripting
|
CVE-2026-39964
|
2026-05-23 13:16 |
2026-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
545
|
8.1 |
HIGH
Network
|
-
|
-
|
(Externally Controlled Reference to a Resource in Another Sphere), (Authorization Bypass Through User-Controlled Key) vulnerability in Apache Camel K. Authorized users in a Kubernetes namespace can c…
|
CWE-610 CWE-639
Externally Controlled Reference to a Resource in Another Sphere Authorization Bypass Through User-Controlled Key
|
CVE-2026-45760
|
2026-05-23 12:16 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
546
|
8.1 |
HIGH
Network
|
-
|
-
|
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when a rewrite directive uses a regex pattern with distinct, overlapping Perl-Co…
|
CWE-122
Heap-based Buffer Overflow
|
CVE-2026-9256
|
2026-05-23 10:16 |
2026-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
547
|
10.0 |
CRITICAL
Network
|
-
|
-
|
Improper authentication in Azure Resource Manager (ARM) allows an unauthorized attacker to elevate privileges over a network.
|
CWE-287
Improper Authentication
|
CVE-2026-47280
|
2026-05-23 08:16 |
2026-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
548
|
8.8 |
HIGH
Network
|
-
|
-
|
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-45659
|
2026-05-23 08:16 |
2026-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
549
|
6.8 |
MEDIUM
Physics
|
microsoft
|
windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2025
|
Microsoft is aware of a security feature bypass vulnerability in Windows publicly referred to as "YellowKey". The proof of concept for this vulnerability has been made public violating coor…
|
CWE-77
Command Injection
|
CVE-2026-45585
|
2026-05-23 08:16 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
550
|
10.0 |
CRITICAL
Network
|
-
|
-
|
Origin validation error in Microsoft Entra ID allows an unauthorized attacker to elevate privileges over a network.
|
CWE-346
Origin Validation Error
|
CVE-2026-42901
|
2026-05-23 08:16 |
2026-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|