|
1161
|
5.3 |
MEDIUM
Network
|
-
|
-
|
Cross-site request forgery (CSRF) vulnerabilities allow attackers to exploit a user's authenticated session to forge cross-site requests, inducing the execution of unintended operations such as tampe…
New
|
CWE-352
Origin Validation Error
|
CVE-2026-49001
|
2026-05-27 17:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1162
|
7.0 |
HIGH
Network
|
-
|
-
|
An insecure password scheme refers to vulnerabilities arising from improper selection of encryption algorithms, inadequate key management, or flawed code implementation, which may lead to data leakag…
New
|
CWE-310
Cryptographic Issues
|
CVE-2026-49000
|
2026-05-27 17:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1163
|
5.7 |
MEDIUM
Network
|
-
|
-
|
Attackers carefully craft malicious scripts, such as JavaScript, and inject them into target systems; when other users access pages containing such malicious content, the scripts are automatically lo…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-48999
|
2026-05-27 17:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1164
|
- |
|
-
|
-
|
IO::Compress versions from 2.207 before 2.220 for Perl ship a zipdetails CLI tool that crashes with undefined subroutine on Info-ZIP Unix Extra Field with 8-byte UID or GID.
When decode_ux() in bin/…
New
|
CWE-755
Improper Handling of Exceptional Conditions
|
CVE-2026-48961
|
2026-05-27 17:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1165
|
- |
|
-
|
-
|
IO::Uncompress::Unzip versions before 2.220 for Perl allow CPU exhaustion via per-byte read loop in fastForward.
fastForward() compares length $offset (the digit count of the offset, 1 to 19) agains…
New
|
CWE-407
Inefficient Algorithmic Complexity
|
CVE-2026-48959
|
2026-05-27 17:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1166
|
- |
|
-
|
-
|
IO::Uncompress::Unzip versions before 2.215 for Perl propagate uncaught exception when parsing zip header with malformed DOS date.
_dosToUnixTime() decodes the local-file-header last-modification da…
New
|
CWE-248
Uncaught Exception
|
CVE-2025-15649
|
2026-05-27 17:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1167
|
4.3 |
MEDIUM
Network
|
-
|
-
|
Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.6 and 11.0.0.0, including 9.3.x and 8.3.x, expose Hadoop cluster credentials in plain text through the Cluster Test API. Al…
New
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2026-2255
|
2026-05-27 13:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1168
|
6.3 |
MEDIUM
Network
|
-
|
-
|
Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.6 and 11.0.0.0, including 9.3.x and 8.3.x, does not apply ACLs on certain API endpoints related to platform mail notficatio…
New
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2026-2254
|
2026-05-27 13:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1169
|
7.7 |
HIGH
Network
|
-
|
-
|
Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.7 and 11.0.0.0, including 9.3.x and 8.3.x, does not prevent certain XML parsers from resolving external entities.
New
|
CWE-611
XXE
|
CVE-2026-2253
|
2026-05-27 13:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1170
|
- |
|
-
|
-
|
In OpenStack Swift before 2.36.2 and 2.37.2, s3api middleware enters an infinite loop when processing a truncated aws-chunked PUT request body. The StreamingInput class repeatedly appends an empty bu…
New
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2026-49017
|
2026-05-27 11:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|