|
361
|
- |
|
-
|
-
|
mailcow-dockerized contains a stored cross-site scripting vulnerability in the administrator Queue Manager. The Queue Manager fetches mail queue entries from /api/v1/get/mailq/all, copies server-cont…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-7460
|
2026-05-20 23:23 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
362
|
8.6 |
HIGH
Network
|
tenable
|
terrascan
|
Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via the remote_url parameter in the remote directory scan endpoint (POST /v1/{iac}/{iacVersion}/{cloud}/remote/dir/sca…
New
|
CWE-73 CWE-610 CWE-918
External Control of File Name or Path Externally Controlled Reference to a Resource in Another Sphere Server-Side Request Forgery (SSRF)
|
CVE-2026-47357
|
2026-05-20 23:23 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
363
|
7.5 |
HIGH
Network
|
mozilla
|
firefox thunderbird
|
Spoofing issue in WebExtensions. This vulnerability was fixed in Firefox 151 and Thunderbird 151.
New
|
CWE-290
Authentication Bypass by Spoofing
|
CVE-2026-8960
|
2026-05-20 23:20 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
364
|
8.6 |
HIGH
Network
|
tenable
|
terrascan
|
Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via external URL resolution in uploaded IaC templates when running in server mode. When Terrascan parses uploaded ARM …
New
|
CWE-73 CWE-610 CWE-918
External Control of File Name or Path Externally Controlled Reference to a Resource in Another Sphere Server-Side Request Forgery (SSRF)
|
CVE-2026-47358
|
2026-05-20 23:18 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
365
|
6.5 |
MEDIUM
Network
|
struktur
|
libheif
|
libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and below, a crafted 792-byte HEIF sequence file with samples_per_chunk=0 in the stsc box causes an unsigned integer und…
New
|
CWE-125 CWE-476
Out-of-bounds Read NULL Pointer Dereference
|
CVE-2026-32738
|
2026-05-20 23:17 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
366
|
6.5 |
MEDIUM
Network
|
struktur
|
libheif
|
libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and below, a crafted 800-byte HEIF sequence file causes an infinite loop in Box_stts::get_sample_duration(), consuming 1…
New
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2026-32739
|
2026-05-20 23:17 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
367
|
6.1 |
MEDIUM
Network
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core allows Cross-Site Scripting (XSS).
This issue affects Drupal core: from 11.3.…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-6367
|
2026-05-20 23:17 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
368
|
6.1 |
MEDIUM
Network
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core allows Cross-Site Scripting (XSS).
This issue affects Drupal core: from 8.0.0…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-6365
|
2026-05-20 23:17 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
369
|
6.1 |
MEDIUM
Network
|
-
|
-
|
Template::Plugin::HTML versions through 3.102 for Perl allows HTML and JavaScript to be injected.
The html_filter function did not escape single quotes. HTML attributes inside of single quotes could…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-5090
|
2026-05-20 23:17 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
370
|
6.8 |
MEDIUM
Network
|
-
|
-
|
Trilium Notes is an open-source, cross-platform hierarchical note taking application for building large personal knowledge bases. Versions 0.102.1 and prior are vulnerable to Local File Inclusion, al…
New
|
CWE-22 CWE-73
Path Traversal External Control of File Name or Path
|
CVE-2026-35593
|
2026-05-20 23:16 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|