|
571
|
6.1 |
MEDIUM
Network
|
-
|
-
|
Sidekiq-cron thru 2.3.1, an open-source scheduling add-on for Sidekiq, is vulnerable to a cross-site scripting (xss) vulnerability via crafted URL being rended from cron.erb.
|
CWE-79
Cross-site Scripting
|
CVE-2025-67202
|
2026-05-9 08:16 |
2026-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
572
|
9.8 |
CRITICAL
Network
|
-
|
-
|
NPM package next-npm-version1.0.1 is vulnerable to Command injection.
|
CWE-94
Code Injection
|
CVE-2025-63706
|
2026-05-9 08:16 |
2026-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
573
|
9.8 |
CRITICAL
Network
|
-
|
-
|
npm package parse-ini v1.0.6 is vulnerable to Prototype Pollution in index.js().
|
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
|
CVE-2025-63703
|
2026-05-9 08:16 |
2026-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
574
|
7.5 |
HIGH
Network
|
-
|
-
|
Pathological inputs could cause DoS through consumePhrase when parsing an email address according to RFC 5322.
|
-
|
CVE-2026-42499
|
2026-05-9 07:16 |
2026-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
575
|
- |
|
-
|
-
|
Emlog is an open source website building system. Prior to version 2.6.11, direct SQL injection in article creation and update functions allows attackers to execute arbitrary SQL commands, potentially…
|
CWE-89
SQL Injection
|
CVE-2026-42287
|
2026-05-9 07:16 |
2026-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
576
|
- |
|
-
|
-
|
Emlog is an open source website building system. Prior to version 2.6.11, missing CSRF protection in critical admin functions allows attackers to trick authenticated administrators into performing un…
|
CWE-352
Origin Validation Error
|
CVE-2026-42286
|
2026-05-9 07:16 |
2026-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
577
|
- |
|
-
|
-
|
SolidCAM-GPPL-IDE is an unofficial, independently developed extension, Postprocessor IDE for SolidCAM. From version 1.0.0 to before version 1.0.2, the inc "filename" directive in GPPL postprocessor f…
|
CWE-22 CWE-200 CWE-295 CWE-918
Path Traversal Information Exposure Improper Certificate Validation Server-Side Request Forgery (SSRF)
|
CVE-2026-42213
|
2026-05-9 07:16 |
2026-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
578
|
- |
|
-
|
-
|
Roadiz is a polymorphic content management system based on a node system. Prior to versions 2.3.43, 2.5.45, 2.6.31, and 2.7.18, the roadiz/openid package generates an OIDC nonce in OAuth2LinkGenerato…
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2026-42206
|
2026-05-9 07:16 |
2026-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
579
|
8.8 |
HIGH
Network
|
-
|
-
|
Avo is a framework to create admin panels for Ruby on Rails apps. Prior to version 3.31.2, a broken access control vulnerability was identified in the ActionsController of the Avo framework. Due to i…
|
CWE-284 CWE-639
Improper Access Control Authorization Bypass Through User-Controlled Key
|
CVE-2026-42205
|
2026-05-9 07:16 |
2026-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
580
|
6.5 |
MEDIUM
Network
|
-
|
-
|
nova-toggle-5 enables fliping booleans in the index. Prior to version 1.3.0, the toggle endpoint (POST/nova-vendor/nova-toggle/toggle/{resource}/{resourceId}) was protected only by web + auth:<guard>…
|
CWE-285
Improper Authorization
|
CVE-2026-42202
|
2026-05-9 07:16 |
2026-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|