|
171
|
9.9 |
CRITICAL
Network
|
-
|
-
|
Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.29.1 and earlier, a command injection vulnerability exists in the Docker file upload functionality. When an authenticated user uplo…
New
|
CWE-77
Command Injection
|
CVE-2026-45663
|
2026-05-30 01:29 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
172
|
8.8 |
HIGH
Network
|
google
|
chrome
|
Use after free in XML in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
New
|
CWE-416
Use After Free
|
CVE-2026-9947
|
2026-05-30 01:29 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
173
|
8.3 |
HIGH
Network
|
google
|
chrome
|
Use after free in Core in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTM…
New
|
CWE-416
Use After Free
|
CVE-2026-9949
|
2026-05-30 01:28 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
174
|
8.3 |
HIGH
Network
|
google
|
chrome
|
Use after free in UI in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
New
|
CWE-416
Use After Free
|
CVE-2026-9951
|
2026-05-30 01:28 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
175
|
8.8 |
HIGH
Network
|
google
|
chrome
|
Use after free in WebAudio in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
New
|
CWE-416
Use After Free
|
CVE-2026-9952
|
2026-05-30 01:27 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
176
|
5.9 |
MEDIUM
Network
|
-
|
-
|
SharpCompress is a fully managed C# library to deal with many compression types and formats. In 0.47.4 and earlier, a path traversal vulnerability in IArchive.WriteToDirectory() allows a malicious ar…
New
|
CWE-22
Path Traversal
|
CVE-2026-44788
|
2026-05-30 01:25 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
177
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Streamlink is a CLI utility which pipes video streams from various services into a video player. Prior to 8.4.0, Streamlink's HLS and DASH parsers do not validate the URI scheme of segment entries an…
New
|
CWE-22
Path Traversal
|
CVE-2026-44353
|
2026-05-30 01:25 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
178
|
6.1 |
MEDIUM
Network
|
-
|
-
|
Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to 1.6.12 and 1.7.1, an unauthenticated open redirect in Authlib's OpenIDImplicitGrant and OpenIDHybridGrant authoriza…
New
|
CWE-601 CWE-863
Open Redirect Incorrect Authorization
|
CVE-2026-44681
|
2026-05-30 01:25 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
179
|
7.5 |
HIGH
Network
|
-
|
-
|
MapServer is a system for developing web-based GIS applications. From 6.4.0 to before 8.6.3, msSLDParseUserStyle always calls _SLDApplyRuleValues(psRule, psLayer, 1); for any <Rule> carrying <ElseFil…
New
|
CWE-129 CWE-476
Improper Validation of Array Index NULL Pointer Dereference
|
CVE-2026-45104
|
2026-05-30 01:25 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
180
|
- |
|
-
|
-
|
CloudNativePG is a platform designed to manage PostgreSQL databases within Kubernetes environments. Prior to 1.29.1 and 1.28.3, the CloudNativePG metrics exporter opens its PostgreSQL connection as t…
New
|
CWE-250 CWE-271 CWE-426
Execution with Unnecessary Privileges Privilege Dropping / Lowering Errors Untrusted Search Path
|
CVE-2026-44477
|
2026-05-30 01:25 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|