|
941
|
5.4 |
MEDIUM
Network
|
apache
|
shiro
|
Apache Shiro’s Jakarta EE module used the HTTP Referer header in certain cases to issue redirect after a user login.
In affected versions, insufficient validation of this client-controlled value coul…
Update
|
CWE-601
Open Redirect
|
CVE-2026-48589
|
2026-05-28 22:38 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
942
|
6.1 |
MEDIUM
Network
|
mistune_project
|
mistune
|
Mistune is a Python Markdown parser with renderers and plugins. Prior to 3.2.1, the Image directive plugin validates the :width: and :height: options with a regex compiled as _num_re = re.compile(r"^…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-44899
|
2026-05-28 22:38 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
943
|
8.8 |
HIGH
Network
|
tanium
|
connect
|
Tanium addressed an unauthorized code execution vulnerability in Connect.
New
|
CWE-78
OS Command
|
CVE-2026-9207
|
2026-05-28 22:31 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
944
|
10.0 |
CRITICAL
Network
|
free5gc
|
free5gc
|
free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NEF mounts the nnef-pfdmanagement route group without inbound OAuth2/bearer-token authorization. A network a…
New
|
CWE-863
Incorrect Authorization
|
CVE-2026-44330
|
2026-05-28 22:06 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
945
|
7.5 |
HIGH
Network
|
-
|
-
|
The Rocket.Chat DDP method autoTranslate.translateMessage in versions <8.5.0, <8.4.2, <8.3.4, <8.2.4, <8.1.5, <8.0.5, <7.13.8, and <7.10.12 accepts a client-supplied IMessage object and passes it dir…
New
|
CWE-284
Improper Access Control
|
CVE-2026-32995
|
2026-05-28 14:16 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
946
|
9.9 |
CRITICAL
Network
|
-
|
-
|
A flaw was found in KubeVirt's virt-handler component. This vulnerability allows an authenticated OpenShift user with edit permissions in a single namespace to exploit improper symlink validation whe…
Update
|
CWE-59
Link Following
|
CVE-2026-7374
|
2026-05-28 12:16 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
947
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Gladinet Triofox Cloud Server Agent Access Service (GladServerAgentService.exe) listens on TCP port 7878 and processes remote HTTP messages with URL paths starting with /resources, /status, /sysinfo,…
New
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2026-8364
|
2026-05-28 06:16 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
948
|
9.8 |
CRITICAL
Network
|
-
|
-
|
A stack-based buffer overflow condition exists in WOSDeviceDropFolder.dll when processing a long URL path starting with /resources:
New
|
CWE-121
Stack-based Buffer Overflow
|
CVE-2026-8363
|
2026-05-28 06:16 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
949
|
7.5 |
HIGH
Network
|
-
|
-
|
A path traversal vulnerability exists in WOSDefaultHttpModule.dll when processing a URL path starting with /woshome
New
|
CWE-23
Relative Path Traversal
|
CVE-2026-8361
|
2026-05-28 06:16 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
950
|
7.5 |
HIGH
Network
|
-
|
-
|
Function calls to WOSCommonUtil.dll!WOSSysInfoGetDeviceInterface() in various DLLs (i.e., WOSProfileMgrModule.dll, WOSWebDavModule.dll) can return a NULL pointer (i.e., when no user is logged into th…
New
|
CWE-476
NULL Pointer Dereference
|
CVE-2026-8360
|
2026-05-28 06:16 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|