|
881
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was found in Investintech SlimPDFReader up to 2.0.13. Affected by this vulnerability is the function sub_3B4610 of the file SlimPDFReader.exe. The manipulation results in stack-based …
|
CWE-119 CWE-121
Incorrect Access of Indexable Resource ('Range Error') Stack-based Buffer Overflow
|
CVE-2026-8733
|
2026-05-19 06:16 |
2026-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
882
|
- |
|
-
|
-
|
* Countermeasures for DPA within SYMCRYPTO
engine on SixG301xxx devices are not sufficiently random and will
eventually repeat.
* KSU keys using SYMCRYPTO will be
impacted by this vulnerability.
|
CWE-331
Insufficient Entropy
|
CVE-2025-14972
|
2026-05-19 05:27 |
2026-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
883
|
8.2 |
HIGH
Network
|
-
|
-
|
A buffer underflow vulnerability has been identified in the ogg123 utility from the vorbis-tools 1.4.3 package in function remotethread in remote.c. This vulnerability occurs in the remote control fu…
|
CWE-124
Buffer Underflow
|
CVE-2026-34253
|
2026-05-19 05:23 |
2026-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
884
|
7.5 |
HIGH
Network
|
-
|
-
|
An issue in Nodemailer smtp_server before v.3.18.3 allows a remote attacker to cause a denial of service via the SMTPStream._write, lib/smtp-stream.js components
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2026-38728
|
2026-05-19 05:23 |
2026-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
885
|
4.6 |
MEDIUM
Network
|
-
|
-
|
HCL Connections contains a broken access control vulnerability that may allow unauthorized user to update data in certain scenarios.
|
CWE-863
Incorrect Authorization
|
CVE-2026-21789
|
2026-05-19 05:23 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
886
|
8.2 |
HIGH
Local
|
-
|
-
|
Das U-Boot before 2026.04 allows FIT (Flat Image Tree) signature verification bypass because hashed-nodes is omitted from a hash.
|
CWE-346
Origin Validation Error
|
CVE-2026-46728
|
2026-05-19 05:23 |
2026-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
887
|
4.6 |
MEDIUM
Local
|
-
|
-
|
Claude HUD through 0.0.12, patched in commit 234d9aa, constructs OSC 8 terminal hyperlink escape sequences using raw cwd and branchUrl values without stripping control characters or encoding embedded…
|
CWE-150
Improper Neutralization of Escape, Meta, or Control Sequences
|
CVE-2026-47090
|
2026-05-19 05:19 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
888
|
3.3 |
LOW
Local
|
-
|
-
|
Claude HUD through 0.0.12, patched in commit 234d9aa, contains a path traversal vulnerability that allows attackers to read arbitrary files by supplying an unvalidated transcript_path value via stdin…
|
CWE-22
Path Traversal
|
CVE-2026-47091
|
2026-05-19 05:19 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
889
|
7.8 |
HIGH
Local
|
-
|
-
|
Claude HUD through 0.0.12, patched in commit 234d9aa, contains a command injection vulnerability that allows local attackers to execute arbitrary commands by manipulating the COMSPEC environment vari…
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2026-47092
|
2026-05-19 05:19 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
890
|
9.8 |
CRITICAL
Network
|
-
|
-
|
iDS6 DSSPro Digital Signage System 6.2 contains a CAPTCHA security bypass vulnerability that allows attackers to bypass authentication by requesting the autoLoginVerifyCode object. Attackers can retr…
|
CWE-307
mproper Restriction of Excessive Authentication Attempts
|
CVE-2020-37228
|
2026-05-19 05:16 |
2026-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|