|
471
|
- |
|
-
|
-
|
Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to versions 19.2.21, 20.3.19, 21.2.9, and 22.0.0-next.8, a Se…
New
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-41423
|
2026-05-9 01:02 |
2026-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
472
|
4.7 |
MEDIUM
Network
|
-
|
-
|
go-git is an extensible git implementation library written in pure Go. Prior to versions 5.18.0 and 6.0.0-alpha.2, go-git may leak HTTP authentication credentials when following redirects during smar…
New
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2026-41506
|
2026-05-9 01:02 |
2026-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
473
|
9.8 |
CRITICAL
Network
|
-
|
-
|
math-codegen generates code from mathematical expressions. Prior to version 0.4.3, string literal content passed to cg.parse() is injected verbatim into a new Function() body without sanitization. Th…
New
|
CWE-94
Code Injection
|
CVE-2026-41507
|
2026-05-9 01:02 |
2026-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
474
|
- |
|
-
|
-
|
Dolibarr is an enterprise resource planning (ERP) and customer relationship management (CRM) software package. Versions 22.0.2 and earlier contains an authenticated remote code execution vulnerabilit…
New
|
CWE-74
Injection
|
CVE-2025-67486
|
2026-05-9 01:02 |
2026-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
475
|
- |
|
-
|
-
|
Nhost is an open source Firebase alternative with GraphQL. Prior to version 0.49.1, Nhost automatically links an incoming OAuth identity to an existing Nhost account when the email addresses match. T…
New
|
CWE-287
Improper Authentication
|
CVE-2026-41574
|
2026-05-9 01:02 |
2026-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
476
|
7.5 |
HIGH
Network
|
coredns.io
|
coredns
|
CoreDNS is a DNS server that chains plugins. In versions prior to 1.14.3, the tsig plugin can be bypassed on non-plain-DNS transports (DoT, DoH, DoH3, DoQ, and gRPC) because it trusts the transport w…
Update
|
CWE-303
Incorrect Implementation of Authentication Algorithm
|
CVE-2026-33190
|
2026-05-9 01:01 |
2026-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
477
|
7.5 |
HIGH
Network
|
coredns.io
|
coredns
|
CoreDNS is a DNS server that chains plugins. In versions prior to 1.14.3, the transfer plugin can select the wrong ACL stanza when both a parent zone and a more-specific subzone are configured. The l…
Update
|
CWE-863
Incorrect Authorization
|
CVE-2026-33489
|
2026-05-9 01:00 |
2026-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
478
|
9.8 |
CRITICAL
Network
|
coredns.io
|
coredns
|
CoreDNS is a DNS server written in Go. In versions prior to 1.14.3, the gRPC, QUIC, DoH, and DoH3 transport implementations incorrectly handle TSIG authentication. For gRPC and QUIC, the server check…
Update
|
CWE-287
Improper Authentication
|
CVE-2026-35579
|
2026-05-9 00:58 |
2026-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
479
|
6.1 |
MEDIUM
Network
|
-
|
-
|
A Cross Site Scripting vulnerability in Alkacon OpenCms before 10.5.1 exists via cmis-online/type.
New
|
CWE-79
Cross-site Scripting
|
CVE-2023-42343
|
2026-05-9 00:58 |
2026-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
480
|
7.3 |
HIGH
Network
|
-
|
-
|
Alkacon OpenCms before 10.5.1 allows remote unauthenticated attackers to obtain sensitive information via a cmis-online/query XXE attack on a Chemistry servlet.
New
|
CWE-611
XXE
|
CVE-2023-42344
|
2026-05-9 00:58 |
2026-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|