|
771
|
10.0 |
CRITICAL
Network
|
-
|
-
|
HestiaCP versions 1.9.0 through 1.9.4 contain a deserialization vulnerability in the web terminal component caused by a session format mismatch between PHP and Node.js that allows unauthenticated rem…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-43633
|
2026-05-19 23:43 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
772
|
6.5 |
MEDIUM
Network
|
vercel
|
turborepo
|
Turborepo is a high-performance build system for JavaScript and TypeScript codebases. Prior to 2.9.14, Turborepo's self-hosted login and SSO browser flows did not validate a CSRF state value on the l…
|
CWE-352 CWE-384
Origin Validation Error Session Fixation
|
CVE-2026-45773
|
2026-05-19 23:41 |
2026-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
773
|
9.8 |
CRITICAL
Network
|
vercel
|
turborepo
|
Turborepo is a high-performance build system for JavaScript and TypeScript codebases. From 1.1.0 to before 2.9.14, Turborepo can be vulnerable to arbitrary code execution when run in untrusted reposi…
|
CWE-426
Untrusted Search Path
|
CVE-2026-45772
|
2026-05-19 23:41 |
2026-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
774
|
7.5 |
HIGH
Network
|
ws_project
|
ws
|
ws is an open source WebSocket client and server for Node.js. Prior to 8.20.1, the websocket.close() implementation is vulnerable to uninitialized memory disclosure when a TypedArray is passed as the…
|
CWE-908
Use of Uninitialized Resource
|
CVE-2026-45736
|
2026-05-19 23:39 |
2026-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
775
|
7.5 |
HIGH
Network
|
-
|
-
|
The Fortis for WooCommerce WordPress plugin before 1.3.1 may leak sensitive API keys to unauthenticated attackers, allowing them to query Fortis' API and retrieve sensitive customer information, like…
|
-
|
CVE-2025-15609
|
2026-05-19 23:38 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
776
|
9.8 |
CRITICAL
Network
|
-
|
-
|
The Piotnet Addons for Elementor Pro plugin for WordPress is vulnerable to arbitrary file upload due to missing file type validation in the 'pafe_ajax_form_builder' function in all versions up to, an…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2026-4885
|
2026-05-19 23:38 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
777
|
9.8 |
CRITICAL
Network
|
-
|
-
|
The Piotnet Forms plugin for WordPress is vulnerable to arbitrary file upload due to missing file type validation in the 'piotnetforms_ajax_form_builder' function in all versions up to, and including…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2026-4883
|
2026-05-19 23:38 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
778
|
7.5 |
HIGH
Network
|
-
|
-
|
The Contest Gallery plugin for WordPress is vulnerable to SQL Injection via the 'form_input' parameter in versions up to, and including, 28.1.6. This is due to insufficient escaping on the user suppl…
|
CWE-89
SQL Injection
|
CVE-2026-8912
|
2026-05-19 23:38 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
779
|
6.3 |
MEDIUM
Network
|
tencent
|
weknora
|
A vulnerability has been found in Tencent WeKnora up to 0.3.6. Affected by this issue is the function getKnowledgeBaseForInitialization of the file internal/handler/initialization.go of the component…
|
CWE-285 CWE-639
Improper Authorization Authorization Bypass Through User-Controlled Key
|
CVE-2026-8786
|
2026-05-19 23:30 |
2026-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
780
|
5.3 |
MEDIUM
Network
|
google
|
chrome
|
Object lifecycle issue in Dawn in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium se…
|
CWE-664
Improper Control of a Resource Through its Lifetime
|
CVE-2026-8582
|
2026-05-19 23:30 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|