5.7

CVSS3.1

CVE-2026-31205 - Stored XSS in Pluck CMS Page Editor Enabling Privilege Escalation

Cross Site Scripting vulnerability in Pluck CMS before v.4.7.21dev allows a remote attacker to escalate privileges via the editpage.php and the sanitizePageContent function

๐Ÿ“… Published: May 4, 2026, midnight ๐Ÿ”„ Last Modified: May 4, 2026, 7:30 p.m.

7.5

CVSS3.1

CVE-2026-37461 -

An out-of-bounds read in the ParseIP6Extended function (/bgp/bgp.go) of gobgp v4.3.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted BGP UPDATE message.

๐Ÿ“… Published: May 4, 2026, midnight ๐Ÿ”„ Last Modified: May 5, 2026, 5:45 p.m.

8.1

CVSS3.1

CVE-2025-67796 - Improper Authorization Allows Crossโ€‘Tenant Data Access in IKUS Rdiffweb

IKUS Rdiffweb before 2.10.5 has an improper authorization flaw that allows an attacker with any valid or stolen access token to act as other users. The API does not enforce binding between the authenticated subject and the targeted user/tenant, so crafted requests can read or modify other users datโ€ฆ

๐Ÿ“… Published: May 4, 2026, midnight ๐Ÿ”„ Last Modified: May 5, 2026, 7 p.m.

8.8

CVSS4.0

CVE-2026-39852 - Quarkus authorization bypass via semicolon path normalization inconsistency

Quarkus is a Java framework for building cloud-native applications. In versions prior to 3.20.6.1, 3.27.3.1, 3.33.1.1, 3.35.1.1, 3.34.7, and 3.35.2, a path normalization inconsistency between the security layer and the routing layer allows unauthenticated or lower-privileged users to bypass HTTP paโ€ฆ

๐Ÿ“… Published: May 4, 2026, midnight ๐Ÿ”„ Last Modified: May 6, 2026, 12:53 p.m.

4.9

CVSS3.1

CVE-2026-6948 - Unbounded Memory Allocation in VQLResponse Result-Set Writer

Velociraptor versions prior to 0.76.4 contain a resource exhaustion vulnerability in the server's agent control channel. This allows a compromised or rogue Velociraptor client to crash the server via out-of-memory (OOM) by sending crafted messages through the normal client communication channel.

๐Ÿ“… Published: May 3, 2026, 11:55 p.m. ๐Ÿ”„ Last Modified: May 4, 2026, 1:08 p.m.

5.3

CVSS4.0

CVE-2026-7712 - MindsDB Pickle pickle.loads deserialization

A security vulnerability has been detected in MindsDB up to 26.01. Affected is the function pickle.loads of the component Pickle Handler. The manipulation leads to deserialization. The attack is possible to be carried out remotely. The exploit has been disclosed publicly and may be used. The vendorโ€ฆ

๐Ÿ“… Published: May 3, 2026, 11:45 p.m. ๐Ÿ”„ Last Modified: May 5, 2026, 12:50 a.m.

6.9

CVSS4.0

CVE-2026-7711 - MindsDB Engine proc_wrapper.py exec unrestricted upload

A weakness has been identified in MindsDB up to 26.01. This impacts the function exec of the file mindsdb/integrations/handlers/byom_handler/proc_wrapper.py of the component Engine Handler. Executing a manipulation can lead to unrestricted upload. The attack can be executed remotely. The exploit haโ€ฆ

๐Ÿ“… Published: May 3, 2026, 11:30 p.m. ๐Ÿ”„ Last Modified: May 3, 2026, 11:30 p.m.

6.9

CVSS4.0

CVE-2026-7710 - YunaiV yudao-cloud Ruoyi-Vue-Pro JwtAuthenticationTokenFilter.java doFilterInternal improper authenโ€ฆ

A security flaw has been discovered in YunaiV yudao-cloud up to 3.8.0. This affects the function doFilterInternal of the file JwtAuthenticationTokenFilter.java of the component Ruoyi-Vue-Pro. Performing a manipulation of the argument mock-token results in improper authentication. Remote exploitatioโ€ฆ

๐Ÿ“… Published: May 3, 2026, 11:15 p.m. ๐Ÿ”„ Last Modified: May 3, 2026, 11:15 p.m.

5.3

CVSS4.0

CVE-2026-7709 - janeczku Calibre-Web Endpoint kobo_auth.py generate_auth_token improper authorization

A vulnerability was identified in janeczku Calibre-Web up to 0.6.26. The impacted element is the function generate_auth_token of the file cps/kobo_auth.py of the component Endpoint. Such manipulation of the argument user_id leads to improper authorization. The attack may be launched remotely. The eโ€ฆ

๐Ÿ“… Published: May 3, 2026, 11 p.m. ๐Ÿ”„ Last Modified: May 3, 2026, 11 p.m.

5.3

CVSS4.0

CVE-2026-7708 - Open5GS UDR subscription.c ogs_dbi_subscription_data denial of service

A vulnerability was determined in Open5GS up to 2.7.7. The affected element is the function ogs_dbi_subscription_data in the library /lib/dbi/subscription.c of the component UDR. This manipulation of the argument supi_id causes denial of service. The attack may be initiated remotely. The exploit haโ€ฆ

๐Ÿ“… Published: May 3, 2026, 10:45 p.m. ๐Ÿ”„ Last Modified: May 3, 2026, 10:45 p.m.
Total resulsts: 349182
Page 143 of 34,919
ยซ previous page ยป next page
Filters