|
271
|
5.3 |
MEDIUM
Network
|
-
|
-
|
Northern.tech Mender Client 5 before 5.0.4 allows a Cryptographic signature verification bypass.
New
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2025-67903
|
2026-05-30 01:16 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272
|
5.5 |
MEDIUM
Local
|
-
|
-
|
IO::Uncompress::Unzip versions before 2.215 for Perl propagate uncaught exception when parsing zip header with malformed DOS date.
_dosToUnixTime() decodes the local-file-header last-modification da…
New
|
CWE-248
Uncaught Exception
|
CVE-2025-15649
|
2026-05-30 01:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273
|
7.5 |
HIGH
Network
|
-
|
-
|
Heatmiser Wifi Thermostat 1.7 contains a credential disclosure vulnerability that allows unauthenticated attackers to retrieve administrative credentials by accessing the networkSetup.htm page. Attac…
New
|
CWE-256
Plaintext Storage of a Password
|
CVE-2018-25396
|
2026-05-30 01:16 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
274
|
7.1 |
HIGH
Network
|
-
|
-
|
LangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to LangSmith SDK Python 0.8.0 and JS/TS 0.6.0, the LangSmith SDK's prompt pull methods (pull_prompt / pull_promp…
New
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-45134
|
2026-05-30 01:12 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
275
|
5.4 |
MEDIUM
Network
|
-
|
-
|
AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Prior to 0.6.59, POST /api/blocks/{block_id}/execute endpoint executes block…
New
|
CWE-770 CWE-841
Allocation of Resources Without Limits or Throttling Improper Enforcement of Behavioral Workflow
|
CVE-2026-45023
|
2026-05-30 01:07 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276
|
7.5 |
HIGH
Network
|
google
|
chrome
|
Uninitialized Use in iOS in Google Chrome on iOS prior to 148.0.7778.216 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code inside a sandbox vi…
New
|
CWE-457
Use of Uninitialized Variable
|
CVE-2026-9963
|
2026-05-30 01:06 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277
|
7.5 |
HIGH
Network
|
dell
|
unisphere_for_powermax_virtual_appliance
|
Dell Unisphere for PowerMax vApp version prior to 10.0.0.2, contains an authorization bypass vulnerability in the Unisphere for VMAX application running in vApp
New
|
CWE-285
Improper Authorization
|
CVE-2022-34363
|
2026-05-30 00:53 |
2026-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278
|
6.5 |
MEDIUM
Network
|
golang
|
net
|
Parsing arbitrary HTML can consume excessive CPU time, possibly leading to denial of service.
New
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2026-25680
|
2026-05-30 00:47 |
2026-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279
|
6.5 |
MEDIUM
Network
|
-
|
-
|
The OpenTelemetry.Exporter.Instana exports telemetry to Instana backend. Prior to 1.1.0, the OpenTelemetry.Exporter.Instana NuGet package does not validate HTTPS/TLS certificates are valid when sendi…
New
|
CWE-295
Improper Certificate Validation
|
CVE-2026-44213
|
2026-05-30 00:42 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280
|
- |
|
-
|
-
|
The vulnerability in the Tassos Framework Plugin allows users to delete arbitrary files on the affected sites.
New
|
CWE-284
Improper Access Control
|
CVE-2026-48906
|
2026-05-30 00:42 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|