|
531
|
4.7 |
MEDIUM
Network
|
-
|
-
|
typescript-utcp is a typescript implementation of UTCP. Prior to 1.1.2, the @utcp/http package is vulnerable to a blind Server-Side Request Forgery (SSRF) caused by a trust-boundary inconsistency bet…
New
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-45366
|
2026-05-29 07:17 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
532
|
7.3 |
HIGH
Network
|
-
|
-
|
Better Auth is an authentication and authorization library for TypeScript. Prior to 1.4.17 and 1.5.0-beta.9, Better Auth's HTTP rate limiter keyed each request by the exact textual IP address it rece…
New
|
CWE-307
mproper Restriction of Excessive Authentication Attempts
|
CVE-2026-45364
|
2026-05-29 07:17 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
533
|
7.5 |
HIGH
Network
|
-
|
-
|
Lakeside SysTrack Agent versions prior to 11.2.1.28, 11.3.0.38, 11.4.0.24, 11.5.0.15 contain an out-of-bounds read vulnerability in the Command ID 30 UDP packet handler that allows remote attackers t…
New
|
CWE-125 CWE-754
Out-of-bounds Read Improper Check for Unusual or Exceptional Conditions
|
CVE-2026-39929
|
2026-05-29 07:16 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
534
|
6.1 |
MEDIUM
Network
|
-
|
-
|
A reflected cross-site scripting issue exists in URL handling.
New
|
CWE-80
Basic XSS
|
CVE-2026-9646
|
2026-05-29 06:16 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
535
|
9.9 |
CRITICAL
Network
|
-
|
-
|
Exposed methods allow authenticated users to create and execute arbitrary JavaScript code on the server. The scripts execute with full access, enabling complete system compromise as commands are exec…
New
|
CWE-78
OS Command
|
CVE-2026-9645
|
2026-05-29 06:16 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
536
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Marten is a .NET Transactional Document DB and Event Store on PostgreSQL. Prior to 8.36.1, Marten's full-text search APIs interpolated the user-supplied regConfig parameter directly into the generate…
New
|
CWE-89
SQL Injection
|
CVE-2026-45288
|
2026-05-29 06:16 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
537
|
7.5 |
HIGH
Network
|
benoitc
|
hackney
|
Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability in benoitc hackney allows HTTP Request/Response Splitting. The WebSocket upgrade code in src/hackney_ws.erl copies the host,…
Update
|
CWE-93
CRLF Injection
|
CVE-2026-47072
|
2026-05-29 05:27 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
538
|
7.5 |
HIGH
Network
|
benoitc
|
hackney
|
Improper Neutralization of CRLF Sequences vulnerability in benoitc hackney allows HTTP Request Splitting. hackney does not percent-encode carriage return (\r) or line feed (\n) characters in the URL …
Update
|
CWE-93
CRLF Injection
|
CVE-2026-47075
|
2026-05-29 05:26 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
539
|
5.4 |
MEDIUM
Network
|
mozilla
|
firefox
|
Firefox for iOS displayed specially crafted right-to-left (RTL) and internationalized domain names (IDNs) incorrectly in link preview UI surfaces. A crafted RTL hostname could visually reorder portio…
Update
|
CWE-451
User Interface (UI) Misrepresentation of Critical Information
|
CVE-2026-9078
|
2026-05-29 05:20 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
540
|
4.9 |
MEDIUM
Network
|
apache
|
syncope
|
Exposure of Sensitive Information Through Data Queries vulnerability in Apache Syncope.
An administrator with adequate entitlements for Derived Schemas can create a malicious JEXL expression which a…
Update
|
CWE-202
Exposure of Sensitive Information Through Data Queries
|
CVE-2026-42797
|
2026-05-29 05:19 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|