|
1671
|
- |
|
-
|
-
|
PredatorSense version 3.00.3136 to 3.00.3196 contain Local Privilege Escalation (LPE) vulnerability.The program exposes a Windows Named Pipe that uses a custom protocol to invoke internal functions. …
|
CWE-22 CWE-269 CWE-284 CWE-732
Path Traversal Improper Privilege Management Improper Access Control Incorrect Permission Assignment for Critical Resource
|
CVE-2026-8069
|
2026-05-9 00:34 |
2026-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1672
|
- |
|
-
|
-
|
Daptin is a GraphQL/JSON-API headless CMS. Prior to version 0.11.5, processFuzzySearch in server/resource/resource_findallpaginated.go:1484 splits the user-supplied column parameter by comma and inte…
|
CWE-89
SQL Injection
|
CVE-2026-44349
|
2026-05-9 00:17 |
2026-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1673
|
7.1 |
HIGH
Network
|
-
|
-
|
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.214, the Change Customer modal correctly hides out-of-scope customers through the mailbox-filte…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-41906
|
2026-05-9 00:16 |
2026-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1674
|
6.1 |
MEDIUM
Network
|
-
|
-
|
If a trusted template author were to write a <script> tag containing an empty 'type' attribute or a 'type' attribute with an ASCII whitespace, the execution of the template would incorrectly escape a…
|
-
|
CVE-2026-39826
|
2026-05-9 00:16 |
2026-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1675
|
6.1 |
MEDIUM
Network
|
-
|
-
|
CVE-2026-27142 fixed a vulnerability in which URLs were not correctly escaped inside of a <meta> tag's <content> attribute. If the URL content were to insert ASCII whitespaces around the '=' rune ins…
|
-
|
CVE-2026-39823
|
2026-05-9 00:16 |
2026-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1676
|
7.5 |
HIGH
Network
|
-
|
-
|
Well-crafted inputs reaching ParseAddress, ParseAddressList, and ParseDate were able to trigger excessive CPU exhaustion and memory allocations.
|
-
|
CVE-2026-39820
|
2026-05-9 00:16 |
2026-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1677
|
7.5 |
HIGH
Network
|
-
|
-
|
When using LookupCNAME with the cgo DNS resolver, a very long CNAME response can trigger a double-free of C memory and a crash.
|
-
|
CVE-2026-33811
|
2026-05-9 00:16 |
2026-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1678
|
7.8 |
HIGH
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: SCO: fix race conditions in sco_sock_connect()
sco_sock_connect() checks sk_state and sk_type without holding
the sock…
|
CWE-362
Race Condition
|
CVE-2026-43023
|
2026-05-8 23:56 |
2026-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1679
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: hci_sync: hci_cmd_sync_queue_once() return -EEXIST if exists
hci_cmd_sync_queue_once() needs to indicate whether a que…
|
NVD-CWE-noinfo
|
CVE-2026-43022
|
2026-05-8 23:53 |
2026-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1680
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
Bluetooth: hci_sync: fix leaks when hci_cmd_sync_queue_once fails
When hci_cmd_sync_queue_once() returns with error, the destroy …
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2026-43021
|
2026-05-8 23:50 |
2026-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|