|
821
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Spring AI's support for Anthropic's Skills API used LLM-influenced filenames unsanitized in Path.resolve before writing files to disk. This could allow a malicious user to write files outside the int…
New
|
CWE-22
Path Traversal
|
CVE-2026-41863
|
2026-05-27 05:16 |
2026-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
822
|
3.3 |
LOW
Local
|
-
|
-
|
A security vulnerability has been detected in GPAC up to 2.4.0. Affected by this issue is the function Media_GetSample of the file src/isomedia/media.c of the component MP4Box. Such manipulation of t…
New
|
CWE-401 CWE-404
Missing Release of Memory after Effective Lifetime Improper Resource Shutdown or Release
|
CVE-2026-9572
|
2026-05-27 05:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
823
|
8.2 |
HIGH
Network
|
-
|
-
|
code100x contains an authentication bypass vulnerability in the Mobile API that allows unauthenticated attackers to impersonate arbitrary users by supplying a crafted JSON payload in the 'g' HTTP hea…
New
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-8890
|
2026-05-27 05:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
824
|
- |
|
-
|
-
|
Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accid…
New
|
-
|
CVE-2026-8453
|
2026-05-27 05:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
825
|
3.1 |
LOW
Network
|
-
|
-
|
TypeBot is a chatbot builder tool. In versions 3.15.2 and prior, the bot engine's the findResult query does not filter results by typebotId, allowing an authenticated user to load result data (user a…
New
|
CWE-639 CWE-862
Authorization Bypass Through User-Controlled Key Missing Authorization
|
CVE-2026-39967
|
2026-05-27 05:16 |
2026-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
826
|
- |
|
-
|
-
|
A cross-site scripting vulnerability exists in Aterm. Arbitrary scripts may be executed in the web browser of a user accessing the web management interface via adjacent network.
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-6059
|
2026-05-27 05:14 |
2026-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
827
|
- |
|
-
|
-
|
An OS Command Injection vulnerability exists in Aterm. If a malicious third person gains administrator access to the product’s web console, they may be able to execute arbitrary OS commands via adjac…
New
|
CWE-78
OS Command
|
CVE-2026-8652
|
2026-05-27 05:14 |
2026-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
828
|
- |
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
net: skbuff: propagate shared-frag marker through frag-transfer helpers
Two frag-transfer helpers (__pskb_copy_fclone() and skb_s…
New
|
-
|
CVE-2026-43503
|
2026-05-27 05:06 |
2026-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
829
|
8.5 |
HIGH
Network
|
-
|
-
|
A vulnerability in the `GitHubRepository` block of the `prefect-github` integration in Prefect version 3.6.18 allows an attacker to inject arbitrary git command-line options via the `reference` field…
New
|
CWE-88
Argument Injection
|
CVE-2026-3515
|
2026-05-27 05:06 |
2026-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
830
|
7.8 |
HIGH
Local
|
-
|
-
|
A critical remote code execution vulnerability exists in all versions of the HuggingFace transformers library prior to version 5.3.0. The vulnerability allows an attacker to craft a malicious `config…
New
|
CWE-1066
|
CVE-2026-4372
|
2026-05-27 05:06 |
2026-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|