|
481
|
- |
|
-
|
-
|
Timing limitations of the HRNG in RS9116 when power save mode is enabled results in predictable values
|
CWE-332
Insufficient Entropy in PRNG
|
CVE-2026-3290
|
2026-05-15 23:11 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
482
|
5.9 |
MEDIUM
Network
|
-
|
-
|
Stack exhaustion vulnerability in the MongoDB PHP driver can cause application crashes when processing deeply nested BSON documents in unusual circumstances when the source of these BSON documents is…
|
CWE-674
Uncontrolled Recursion
|
CVE-2026-6811
|
2026-05-15 23:11 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
483
|
- |
|
-
|
-
|
Rapid7 Metasploit Pro is vulnerable to a local privilege escalation attack that allows users to gain SYSTEM level control of a Windows host. Upon startup the metasploitPostgreSQL service the subseque…
|
CWE-284 CWE-427 CWE-829
Improper Access Control Uncontrolled Search Path Element Inclusion of Functionality from Untrusted Control Sphere
|
CVE-2026-7373
|
2026-05-15 23:11 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
484
|
7.8 |
HIGH
Local
|
-
|
-
|
VMware Fusion contains a TOCTOU (Time-of-check Time-of-use) vulnerability that occurs during an operation performed by a SETUID binary. A malicious actor with local non-administrative user privileges…
|
CWE-367
Time-of-check Time-of-use (TOCTOU) Race Condition
|
CVE-2026-41702
|
2026-05-15 23:11 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
485
|
- |
|
-
|
-
|
Improper input validation in Delphix Continuous Data connectors allows an authenticated user to execute arbitrary operating system commands on the staging or target host.
|
CWE-78
OS Command
|
CVE-2026-8654
|
2026-05-15 23:11 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
486
|
8.8 |
HIGH
Network
|
-
|
-
|
Crabbox prior to v0.12.0 contains an authentication bypass vulnerability that allows non-admin shared-token callers to impersonate other owners or organizations by spoofing identity headers. Attacker…
|
CWE-287
Improper Authentication
|
CVE-2026-8621
|
2026-05-15 23:11 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
487
|
8.1 |
HIGH
Network
|
-
|
-
|
Crabbox prior to v0.12.0 contains a privilege escalation vulnerability that allows users with shared visibility-only access to obtain Code, WebVNC, and Egress agent tickets by sending POST requests t…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-8629
|
2026-05-15 23:11 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
488
|
7.2 |
HIGH
Network
|
-
|
-
|
Missing integrity verification in the Triton inference handler in Amazon SageMaker Python SDK v2 before v2.257.2 and v3 before v3.8.0 might allow a remote authenticated actor to achieve code executio…
|
CWE-354
Improper Validation of Integrity Check Value
|
CVE-2026-8597
|
2026-05-15 23:10 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
489
|
7.2 |
HIGH
Network
|
-
|
-
|
Cleartext storage of sensitive information in the ModelBuilder/Serve component in Amazon SageMaker Python SDK before v2.257.2 and v3 before v3.8.0 might allow a remote authenticated actor to extract …
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2026-8596
|
2026-05-15 23:10 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
490
|
- |
|
-
|
-
|
Improper input validation in the AMD OverDrive (AOD) System Management Mode (SMM) module could allow a privileged attacker to perform an out-of-bounds read, potentially resulting in loss of confident…
|
CWE-1274
Improper Access Control for Volatile Memory Containing Boot Code
|
CVE-2024-36345
|
2026-05-15 23:10 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|