|
1121
|
8.8 |
HIGH
Network
|
redisbloom
|
redisbloom
|
RedisBloom is a probabilistic data structures module for Redis. In all versions of RedisBloom before 2.8.20, the module does not properly validate serialized values processed through the Redis RESTOR…
Update
|
CWE-122
Heap-based Buffer Overflow
|
CVE-2026-25589
|
2026-05-7 22:44 |
2026-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1122
|
7.5 |
HIGH
Network
|
owasp
|
modsecurity
|
ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. Libmodsecurity is one component of the ModSecurity v3 project. A segmentation fault occu…
New
|
CWE-125
Out-of-bounds Read
|
CVE-2026-30923
|
2026-05-7 22:41 |
2026-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1123
|
5.4 |
MEDIUM
Network
|
google
|
chrome
|
Insufficient validation of untrusted input in Dialog in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HT…
New
|
CWE-20 NVD-CWE-noinfo
Improper Input Validation
|
CVE-2026-7998
|
2026-05-7 22:40 |
2026-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1124
|
4.3 |
MEDIUM
Network
|
google
|
chrome
|
Inappropriate implementation in V8 in Google Chrome prior to 148.0.7778.96 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium…
New
|
CWE-200
Information Exposure
|
CVE-2026-7999
|
2026-05-7 22:39 |
2026-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1125
|
8.8 |
HIGH
Network
|
google
|
chrome
|
Insufficient validation of untrusted input in ChromeDriver in Google Chrome on Windows prior to 148.0.7778.96 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium se…
New
|
CWE-20 NVD-CWE-noinfo
Improper Input Validation
|
CVE-2026-8000
|
2026-05-7 22:39 |
2026-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1126
|
7.7 |
HIGH
Network
|
openclaw
|
openclaw
|
OpenClaw before 2026.4.14 contains a server-side request forgery vulnerability in browser SSRF policy that allows private-network navigation by default. Attackers can exploit this misconfiguration to…
Update
|
CWE-918 CWE-1188
Server-Side Request Forgery (SSRF) Insecure Default Initialization of Resource
|
CVE-2026-43527
|
2026-05-7 22:29 |
2026-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1127
|
6.1 |
MEDIUM
Network
|
apache
|
wicket
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache Wicket.
This issue affects Apache Wicket: from 8.0.0 through 8.17.0, 9.0.0, from 10.0.0 t…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-42509
|
2026-05-7 22:16 |
2026-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1128
|
9.1 |
CRITICAL
Network
|
apache
|
wicket
|
Missing invocation of Servlet http web request method changeSessionId after session binding can be exploited for a session fixation attack in Apache Wicket.
This issue affects Apache Wicket: from 8.…
New
|
CWE-384
Session Fixation
|
CVE-2026-40010
|
2026-05-7 22:16 |
2026-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1129
|
- |
|
-
|
-
|
Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, NamedPipeServer::OpenHandler copies the server field from NAMED_PIPE_OPEN_REQ into a fix…
New
|
CWE-121 CWE-170
Stack-based Buffer Overflow Improper Null Termination
|
CVE-2026-34464
|
2026-05-7 22:16 |
2026-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1130
|
- |
|
-
|
-
|
Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, several ProcessServer handlers (KillAllHandler, SuspendAllHandler, and RunSandboxedHandl…
New
|
CWE-121 CWE-170
Stack-based Buffer Overflow Improper Null Termination
|
CVE-2026-34462
|
2026-05-7 22:16 |
2026-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|