|
571
|
- |
|
-
|
-
|
Execution with unnecessary privileges vulnerability in Broadcom Automic Automation Agent Unix on Linux x64, Linux Power 64 BE, Linux Power 64 LE, zLinux (zSeries), AIX, Solaris x64, Solaris Sparc 64 …
New
|
CWE-250
Execution with Unnecessary Privileges
|
CVE-2026-8370
|
2026-05-20 06:01 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
572
|
8.8 |
HIGH
Network
|
getgrav
|
grav
|
Grav is a file-based Web platform. In Grav 2.0.0-beta.2, a low-privileged authenticated API user with api.media.write can abuse /api/v1/blueprint-upload to write an arbitrary YAML file into user/acco…
Update
|
CWE-269 CWE-434
Improper Privilege Management Unrestricted Upload of File with Dangerous Type
|
CVE-2026-42844
|
2026-05-20 06:00 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
573
|
7.5 |
HIGH
Network
|
-
|
-
|
The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation and missing capability check in …
New
|
CWE-23
Relative Path Traversal
|
CVE-2026-8073
|
2026-05-20 06:00 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
574
|
6.5 |
MEDIUM
Network
|
-
|
-
|
The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.0.6. This is due to the plugin not p…
New
|
CWE-862
Missing Authorization
|
CVE-2026-8096
|
2026-05-20 06:00 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
575
|
7.8 |
HIGH
Local
|
protobufjs_project
|
protobufjs-cli
|
protobufjs-cli is the command line add-on for protobuf.js. Prior to 1.2.1 and 2.0.2, pbts invoked JSDoc by building a shell command string from input file paths and executing it through child_process…
Update
|
CWE-78
OS Command
|
CVE-2026-42290
|
2026-05-20 05:56 |
2026-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
576
|
5.3 |
MEDIUM
Network
|
protobufjs_project
|
protobufjs
|
protobufjs compiles protobuf definitions into JavaScript (JS) functions. Prior to 7.5.6 and 8.0.2, protobufjs includes a minimal UTF-8 decoder that accepted overlong UTF-8 byte sequences and decoded …
Update
|
CWE-176
Improper Handling of Unicode Encoding
|
CVE-2026-44288
|
2026-05-20 05:46 |
2026-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
577
|
8.7 |
HIGH
Network
|
protobufjs_project
|
protobufjs-cli
|
protobufjs-cli is the command line add-on for protobuf.js. Prior to 1.2.1 and 2.0.2, pbjs static code generation could emit unsafe JavaScript identifiers derived from schema-controlled names. When ge…
Update
|
CWE-94
Code Injection
|
CVE-2026-44295
|
2026-05-20 05:37 |
2026-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
578
|
7.2 |
HIGH
Network
|
dkfz
|
nnu-net
|
nnU-Net is a semantic segmentation framework that automatically adapts its pipeline to a dataset. Prior to 2.4.1, the nnU-Net Issue Triage workflow in .github/workflows/issue-triage.yml is vulnerable…
Update
|
CWE-74
Injection
|
CVE-2026-44246
|
2026-05-20 05:10 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
579
|
6.1 |
MEDIUM
Network
|
beaugunderson
|
ip-address
|
ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.1.1, Address6.group() and Address6.link() do not HTML-escape attacker-controlled content before…
Update
|
CWE-79
Cross-site Scripting
|
CVE-2026-42338
|
2026-05-20 05:04 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
580
|
8.8 |
HIGH
Network
|
tabby
|
tabby
|
Tabby (formerly Terminus) is a highly configurable terminal emulator. Prior to 1.0.233, Tabby registers itself as the handler for the tabby:// URL scheme on all platforms. The URL scheme handler supp…
Update
|
CWE-78
OS Command
|
CVE-2026-45035
|
2026-05-20 04:41 |
2026-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|