|
541
|
9.9 |
CRITICAL
Network
|
-
|
-
|
Budibase is an open-source low-code platform. Prior to 3.38.2, packages/worker/src/api/routes/global/scim.ts attaches only two middlewares to the SCIM router: requireSCIM (checks the Enterprise featu…
New
|
CWE-862
Missing Authorization
|
CVE-2026-46425
|
2026-05-29 05:16 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
542
|
5.0 |
MEDIUM
Network
|
-
|
-
|
Local Deep Research is an AI-powered research assistant for deep, iterative research. Prior to 1.6.0, PDFService._markdown_to_html() constructs an HTML document by interpolating user-controlled value…
New
|
CWE-79 CWE-918
Cross-site Scripting Server-Side Request Forgery (SSRF)
|
CVE-2026-43979
|
2026-05-29 05:16 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
543
|
7.8 |
HIGH
Local
|
codesys
|
development_system
|
The affected product creates a directory with insecure default permissions during administrative installation. This allows a low-privileged local attacker to modify a temporary file defining the comp…
Update
|
CWE-276 NVD-CWE-noinfo
Incorrect Default Permissions
|
CVE-2026-44468
|
2026-05-29 05:11 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
544
|
7.0 |
HIGH
Local
|
codesys
|
development_system
|
The affected product extracts installation files to a temporary directory with incorrect default permissions during administrative installation. A low-privileged local attacker can exploit a TOCTOU r…
Update
|
CWE-276
Incorrect Default Permissions
|
CVE-2026-44469
|
2026-05-29 05:09 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
545
|
7.8 |
HIGH
Local
|
mediaarea
|
mediainfolib
|
MediaArea MediaInfoLib LXF parsing heap-based buffer overflow vulnerability
Update
|
CWE-191
Integer Underflow (Wrap or Wraparound)
|
CVE-2026-25104
|
2026-05-29 05:06 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
546
|
7.8 |
HIGH
Local
|
mediaarea
|
mediainfolib
|
MediaArea MediaInfoLib ID3v2 parsing heap buffer overflow vulnerability
Update
|
CWE-122
Heap-based Buffer Overflow
|
CVE-2026-25713
|
2026-05-29 05:03 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
547
|
7.5 |
HIGH
Network
|
joomla
|
joomla\!
|
Insufficient state checks lead to a vector that allows to bypass 2FA checks.
Update
|
CWE-287 NVD-CWE-noinfo
Improper Authentication
|
CVE-2026-48896
|
2026-05-29 04:46 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
548
|
7.5 |
HIGH
Network
|
joomla
|
joomla\!
|
Insufficient state checks lead to a vector that allows to bypass 2FA checks.
Update
|
CWE-287
Improper Authentication
|
CVE-2026-48897
|
2026-05-29 04:40 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
549
|
8.2 |
HIGH
Network
|
-
|
-
|
deepobj provides get, set, delete deep objects in javascript. Prior to 1.0.3, prototype pollution is possible when property paths contain __proto__/constructor/prototype. The property path must not b…
New
|
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
|
CVE-2026-46509
|
2026-05-29 04:16 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
550
|
7.5 |
HIGH
Network
|
-
|
-
|
Automad is a flat-file content management system and template engine. From 2.0.0-alpha.1 to 2.0.0-beta.27, a Broken Access Control vulnerability allows an unauthenticated attacker to retrieve the bcr…
New
|
CWE-200 CWE-306
Information Exposure Missing Authentication for Critical Function
|
CVE-2026-45332
|
2026-05-29 04:16 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|