|
971
|
- |
|
-
|
-
|
MaxKB is an open-source AI assistant for enterprise. MaxKB 2.8.0 and prior are vulnerable to a server-side request forgery (SSRF) bypass in the OSS file service URL fetch functionality due to inconsi…
New
|
CWE-367 CWE-918
Time-of-check Time-of-use (TOCTOU) Race Condition Server-Side Request Forgery (SSRF)
|
CVE-2026-42336
|
2026-05-28 04:41 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
972
|
- |
|
-
|
-
|
MaxKB is an open-source AI assistant for enterprise. MaxKB 2.8.0 and prior are vulnerable to a broken access control vulnerability in the OSS file service URL fetch API (chat/api/oss/get_url). The en…
New
|
CWE-862
Missing Authorization
|
CVE-2026-42337
|
2026-05-28 04:41 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
973
|
7.5 |
HIGH
Network
|
-
|
-
|
MaxKB is an open-source AI assistant for enterprise. Prior to 2.9.0, MaxKB's webhook trigger endpoint (/api/trigger/v1/webhook/{trigger_id}) is accessible without authentication. The WebhookAuth clas…
New
|
CWE-287 CWE-306
Improper Authentication Missing Authentication for Critical Function
|
CVE-2026-44847
|
2026-05-28 04:41 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
974
|
- |
|
-
|
-
|
MaxKB is an open-source AI assistant for enterprise. Prior to 2.9.1, SSRF via work_flow_template Import. Authenticated users can supply arbitrary URLs in work_flow_template.downloadUrl which are fetc…
New
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-45412
|
2026-05-28 04:41 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
975
|
- |
|
-
|
-
|
MaxKB is an open-source AI assistant for enterprise. Prior to 2.9.1, user passwords are stored using unsalted MD5 hashes, making them trivially crackable via rainbow tables or GPU-accelerated brute f…
New
|
CWE-328
Use of Weak Hash
|
CVE-2026-45413
|
2026-05-28 04:41 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
976
|
7.4 |
HIGH
Network
|
-
|
-
|
epa4all-client is the Java Client for epa4all / ePA 3.0 in the Telematik Infrastruktur. Prior to 1.2.2, an attacker who can MITM the TLS connection between the client and the IDP (within the TI netwo…
New
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2026-45575
|
2026-05-28 04:41 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
977
|
6.5 |
MEDIUM
Adjacent
|
-
|
-
|
epa4all-client is the Java Client for epa4all / ePA 3.0 in the Telematik Infrastruktur. In 1.2.4 and earlier, any network-reachable caller can write arbitrary documents to any patient's electronic he…
New
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2026-47672
|
2026-05-28 04:41 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
978
|
8.1 |
HIGH
Adjacent
|
-
|
-
|
epa4all-client is the Java Client for epa4all / ePA 3.0 in the Telematik Infrastruktur. Prior to 1.2.1, in SignedPublicKeysTrustValidatorImpl.isTrusted(), the ECDSA signature verification at line 45…
New
|
CWE-295
Improper Certificate Validation
|
CVE-2026-44900
|
2026-05-28 04:41 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
979
|
8.1 |
HIGH
Adjacent
|
-
|
-
|
epa4all-client is the Java Client for epa4all / ePA 3.0 in the Telematik Infrastruktur. Prior to 1.2.2, an attacker on the network path between the ePA service and the Konnektor can present any TLS c…
New
|
CWE-295
Improper Certificate Validation
|
CVE-2026-45574
|
2026-05-28 04:41 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
980
|
- |
|
-
|
-
|
Missing Authorization vulnerability in oban-bg oban_web ('Elixir.Oban.Web.Jobs.DetailComponent' modules) allows unauthorized job worker substitution.
The handle_event("save-job", ...) handler in 'El…
New
|
CWE-862
Missing Authorization
|
CVE-2026-48592
|
2026-05-28 04:38 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|