|
2661
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Incus is a system container and virtual machine manager. Prior to version 7.0.0, a missing error handling could lead an authenticated Incus user to cause a daemon crash through the import of a trunca…
|
CWE-476
NULL Pointer Dereference
|
CVE-2026-41647
|
2026-05-7 23:59 |
2026-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2662
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Incus is a system container and virtual machine manager. Prior to version 7.0.0, backup.GetInfo() trusts the inline backup/index.yaml config when present and only falls back to parsing the legacy bac…
|
CWE-476
NULL Pointer Dereference
|
CVE-2026-41684
|
2026-05-7 23:59 |
2026-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2663
|
9.1 |
CRITICAL
Network
|
-
|
-
|
CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. In version 0.31.4.0, an attacker can achieve Full Account…
|
CWE-79
Cross-site Scripting
|
CVE-2026-41201
|
2026-05-7 23:57 |
2026-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2664
|
- |
|
-
|
-
|
CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. Prior to version 0.31.5.0, ci4ms Backup::restore extracts…
|
CWE-22
Path Traversal
|
CVE-2026-41202
|
2026-05-7 23:57 |
2026-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2665
|
- |
|
-
|
-
|
CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. From version 0.26.0 to before version 0.31.8.0, the auth …
|
CWE-613
Insufficient Session Expiration
|
CVE-2026-41891
|
2026-05-7 23:57 |
2026-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2666
|
7.1 |
HIGH
Network
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bricks Builder allows Reflected XSS.
This issue affects Bricks Builder: from n/a through 1.9.2 t…
|
CWE-79
Cross-site Scripting
|
CVE-2026-41554
|
2026-05-7 23:56 |
2026-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2667
|
4.4 |
MEDIUM
Local
|
-
|
-
|
An off-by-one error (CWE-193) in the ConsumeUnit16Array and ConsumeUnit64Array functions in Velocidex Velociraptor before version 0.76.5 on Windows and Linux allows a local attacker to cause a Denial…
|
CWE-193
Off-by-one Error
|
CVE-2026-7572
|
2026-05-7 23:56 |
2026-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2668
|
5.0 |
MEDIUM
Network
|
-
|
-
|
An authorization bypass (CWE-639) in the GetUserRoles gRPC API endpoint in Velocidex Velociraptor below version 0.76.5 allows any authenticated low-privilege user to retrieve the complete ACL policy …
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-7573
|
2026-05-7 23:56 |
2026-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2669
|
- |
|
-
|
-
|
An authenticated (non-super) administrator can create a maintenance period with a JavaScript payload that is executed by any user that opens tooltip for that maintenance period in the Host navigator …
|
CWE-79
Cross-site Scripting
|
CVE-2026-23926
|
2026-05-7 23:56 |
2026-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2670
|
- |
|
-
|
-
|
A user able to connect to Agent 2 can inject an Oracle TNS connection string via the 'service' parameter. This can lead to Agent 2 connecting to an attacker-controlled server and leaking Oracle datab…
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2026-23927
|
2026-05-7 23:56 |
2026-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|