|
121
|
7.2 |
HIGH
Network
|
strapi
|
strapi
|
Strapi is an open source headless content management system. In versions on the 4.x branch prior to 4.26.1 and on the 5.x branch prior to 5.33.2, a database-query injection vulnerability existed in t…
New
|
CWE-89
SQL Injection
|
CVE-2026-22599
|
2026-05-16 12:25 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
122
|
6.5 |
MEDIUM
Network
|
strapi
|
strapi
|
Strapi is an open source headless content management system. In Strapi versions prior to 5.33.3, changing or resetting a user's password did not invalidate the user's existing refresh-token sessions …
New
|
CWE-613
Insufficient Session Expiration
|
CVE-2026-22706
|
2026-05-16 12:23 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
123
|
5.4 |
MEDIUM
Network
|
strapi
|
strapi
|
Strapi is an open source headless content management system. In Strapi versions prior to 5.33.3, the Upload plugin's Content API endpoints did not enforce the administrator-configured MIME type restr…
New
|
CWE-434 CWE-693
Unrestricted Upload of File with Dangerous Type Protection Mechanism Failure
|
CVE-2026-22707
|
2026-05-16 12:22 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
124
|
7.5 |
HIGH
Network
|
strapi
|
strapi
|
Strapi is an open source headless content management system. Strapi versions starting in 4.0.0 and prior to 5.37.0 did not sufficiently sanitize query parameters when filtering content via relational…
New
|
CWE-22 CWE-200 CWE-943
Path Traversal Information Exposure Improper Neutralization of Special Elements in Data Query Logic
|
CVE-2026-27886
|
2026-05-16 12:16 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
125
|
5.3 |
MEDIUM
Network
|
-
|
-
|
The Essential Chat Support plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.0.1. This is due to the plugin not properly verifying that a user is auth…
New
|
CWE-862
Missing Authorization
|
CVE-2026-8681
|
2026-05-16 12:16 |
2026-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
126
|
8.8 |
HIGH
Adjacent
|
zyxel
|
wre6505_firmware
|
** UNSUPPORTED WHEN ASSIGNED ** A command injection vulnerability in the CGI program of Zyxel WRE6505 v2 firmware version V1.00(ABDV.3)C0 could allow an adjacent attacker on the LAN to execute operat…
Update
|
CWE-78
OS Command
|
CVE-2026-7256
|
2026-05-16 12:08 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
127
|
4.4 |
MEDIUM
Local
|
zyxel
|
wre6505_firmware
|
** UNSUPPORTED WHEN ASSIGNED ** An insecure storage of sensitive information vulnerability in the configuration file of Zyxel WRE6505 v2 firmware version V1.00(ABDV.3)C0 could allow a local attacker …
Update
|
CWE-922
Insecure Storage of Sensitive Information
|
CVE-2026-7257
|
2026-05-16 12:08 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
128
|
7.5 |
HIGH
Network
|
zyxel
|
nwa1100-n_firmware
|
** UNSUPPORTED WHEN ASSIGNED ** A buffer overflow vulnerability in the formWep(), formWlAc(), formPasswordSetup(), formUpgradeCert(), and formDelcert() functions of the “webs” binary in Zyxel NWA1100…
Update
|
CWE-120
Classic Buffer Overflow
|
CVE-2026-7287
|
2026-05-16 12:08 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
129
|
6.5 |
MEDIUM
Adjacent
|
pengutronix
|
barebox
|
barebox prior to version 2026.04.0 contains an out-of-bounds read vulnerability in DHCP option parsing within the dhcp_message_type() function that fails to verify the options pointer remains within …
Update
|
CWE-125
Out-of-bounds Read
|
CVE-2026-34960
|
2026-05-16 12:07 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
130
|
9.8 |
CRITICAL
Network
|
openclaw
|
openclaw
|
A vulnerability was detected in OpenClaw up to 2026.1.24. The impacted element is the function handleBlueBubblesWebhookRequest of the file extensions/bluebubbles/src/monitor.ts of the component blueb…
Update
|
CWE-287
Improper Authentication
|
CVE-2026-8305
|
2026-05-16 12:06 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|