|
3601
|
6.5 |
MEDIUM
Network
|
kilo
|
kilo_code
|
A vulnerability was detected in Kilo-Org kilocode up to 7.0.47. This vulnerability affects the function Bun.file of the file packages/opencode/src/kilocode/review/worktree-diff.ts of the component Fi…
|
CWE-22
Path Traversal
|
CVE-2026-8765
|
2026-05-20 06:21 |
2026-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3602
|
5.3 |
MEDIUM
Network
|
-
|
-
|
In the AWS Secrets Manager and SSM Parameter Store secrets backends of `apache-airflow-providers-amazon` prior to 9.28.0, the team-scoping logic could resolve a `conn_id` containing a `/` (e.g. `"my_…
|
CWE-863
Incorrect Authorization
|
CVE-2026-42526
|
2026-05-20 06:16 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3603
|
8.7 |
HIGH
Local
|
-
|
-
|
JWT tokens that were used by workers in Kubernetes Executors have been exposed to users who had read only access to Kuberentes Pods. This could allow users with just read-only access to perform actio…
|
CWE-538
File and Directory Information Exposure
|
CVE-2026-27173
|
2026-05-20 06:16 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3604
|
- |
|
-
|
-
|
Discourse is an open-source discussion platform. In versions prior to 2026.1.4, 2026.3.1, 2026.4.1 and 2026.5.0-latest.1, a vulnerability in the discourse-subscriptions plugin allows users to gain a…
|
CWE-862
Missing Authorization
|
CVE-2026-34154
|
2026-05-20 06:08 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3605
|
5.9 |
MEDIUM
Network
|
-
|
-
|
LIVE555 before 2026.04.22 contains an authorization bypass vulnerability in RTSP session command handling that allows attackers to replay valid Session tokens from unauthenticated connections. Attack…
|
CWE-863
Incorrect Authorization
|
CVE-2026-41470
|
2026-05-20 06:08 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3606
|
- |
|
-
|
-
|
Execution with unnecessary privileges vulnerability in Broadcom Automic Automation Agent Unix on Linux x64, Linux Power 64 BE, Linux Power 64 LE, zLinux (zSeries), AIX, Solaris x64, Solaris Sparc 64 …
|
CWE-250
Execution with Unnecessary Privileges
|
CVE-2026-8370
|
2026-05-20 06:01 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3607
|
8.8 |
HIGH
Network
|
getgrav
|
grav
|
Grav is a file-based Web platform. In Grav 2.0.0-beta.2, a low-privileged authenticated API user with api.media.write can abuse /api/v1/blueprint-upload to write an arbitrary YAML file into user/acco…
|
CWE-269 CWE-434
Improper Privilege Management Unrestricted Upload of File with Dangerous Type
|
CVE-2026-42844
|
2026-05-20 06:00 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3608
|
7.5 |
HIGH
Network
|
-
|
-
|
The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation and missing capability check in …
|
CWE-23
Relative Path Traversal
|
CVE-2026-8073
|
2026-05-20 06:00 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3609
|
6.5 |
MEDIUM
Network
|
-
|
-
|
The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.0.6. This is due to the plugin not p…
|
CWE-862
Missing Authorization
|
CVE-2026-8096
|
2026-05-20 06:00 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3610
|
7.8 |
HIGH
Local
|
protobufjs_project
|
protobufjs-cli
|
protobufjs-cli is the command line add-on for protobuf.js. Prior to 1.2.1 and 2.0.2, pbts invoked JSDoc by building a shell command string from input file paths and executing it through child_process…
|
CWE-78
OS Command
|
CVE-2026-42290
|
2026-05-20 05:56 |
2026-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|