|
2601
|
6.5 |
MEDIUM
Network
|
-
|
-
|
The HCL DominoIQ RAG feature is affected by a Broken Access Control vulnerability. Under certain circumstances, document level access restrictions will be ignored when determining what data to retur…
|
CWE-862
Missing Authorization
|
CVE-2026-21836
|
2026-05-20 23:23 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2602
|
6.5 |
MEDIUM
Adjacent
|
mozilla
|
firefox
|
Firefox for iOS hosted Reader mode on an unauthenticated local web server, allowing another application on the same device to request arbitrary URLs and receive the response rendered with the signed-…
|
CWE-200 CWE-306
Information Exposure Missing Authentication for Critical Function
|
CVE-2026-8706
|
2026-05-20 23:23 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2603
|
8.6 |
HIGH
Network
|
tenable
|
terrascan
|
Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via the webhook_url parameter in the file scan endpoint (POST /v1/{iac}/{iacVersion}/{cloud}/local/file/scan) when run…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-47356
|
2026-05-20 23:23 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2604
|
- |
|
-
|
-
|
mailcow-dockerized contains a stored cross-site scripting vulnerability in the administrator Queue Manager. The Queue Manager fetches mail queue entries from /api/v1/get/mailq/all, copies server-cont…
|
CWE-79
Cross-site Scripting
|
CVE-2026-7460
|
2026-05-20 23:23 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2605
|
8.6 |
HIGH
Network
|
tenable
|
terrascan
|
Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via the remote_url parameter in the remote directory scan endpoint (POST /v1/{iac}/{iacVersion}/{cloud}/remote/dir/sca…
|
CWE-73 CWE-610 CWE-918
External Control of File Name or Path Externally Controlled Reference to a Resource in Another Sphere Server-Side Request Forgery (SSRF)
|
CVE-2026-47357
|
2026-05-20 23:23 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2606
|
7.5 |
HIGH
Network
|
mozilla
|
firefox thunderbird
|
Spoofing issue in WebExtensions. This vulnerability was fixed in Firefox 151 and Thunderbird 151.
|
CWE-290
Authentication Bypass by Spoofing
|
CVE-2026-8960
|
2026-05-20 23:20 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2607
|
8.6 |
HIGH
Network
|
tenable
|
terrascan
|
Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via external URL resolution in uploaded IaC templates when running in server mode. When Terrascan parses uploaded ARM …
|
CWE-73 CWE-610 CWE-918
External Control of File Name or Path Externally Controlled Reference to a Resource in Another Sphere Server-Side Request Forgery (SSRF)
|
CVE-2026-47358
|
2026-05-20 23:18 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2608
|
6.5 |
MEDIUM
Network
|
struktur
|
libheif
|
libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and below, a crafted 792-byte HEIF sequence file with samples_per_chunk=0 in the stsc box causes an unsigned integer und…
|
CWE-125 CWE-476
Out-of-bounds Read NULL Pointer Dereference
|
CVE-2026-32738
|
2026-05-20 23:17 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2609
|
6.5 |
MEDIUM
Network
|
struktur
|
libheif
|
libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and below, a crafted 800-byte HEIF sequence file causes an infinite loop in Box_stts::get_sample_duration(), consuming 1…
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2026-32739
|
2026-05-20 23:17 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2610
|
6.1 |
MEDIUM
Network
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core allows Cross-Site Scripting (XSS).
This issue affects Drupal core: from 11.3.…
|
CWE-79
Cross-site Scripting
|
CVE-2026-6367
|
2026-05-20 23:17 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|