|
431
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Tegsoft Management and Information Services Trade Limited Company Online Support Application allo…
New
|
CWE-79
Cross-site Scripting
|
CVE-2025-14320
|
2026-05-4 18:15 |
2026-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
432
|
5.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was identified in osrg GoBGP up to 4.3.0. Affected by this issue is the function BMPPeerUpNotification.ParseBody/BMPStatisticsReport.ParseBody of the file pkg/packet/bmp/bmp.go of the…
New
|
CWE-119 CWE-125
Incorrect Access of Indexable Resource ('Range Error') Out-of-bounds Read
|
CVE-2026-7737
|
2026-05-4 16:16 |
2026-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
433
|
7.3 |
HIGH
Network
|
-
|
-
|
A vulnerability was determined in osrg GoBGP up to 4.3.0. Affected by this vulnerability is the function parseRibEntry of the file pkg/packet/mrt/mrt.go. Executing a manipulation can lead to integer …
New
|
CWE-189 CWE-191
Numeric Errors Integer Underflow (Wrap or Wraparound)
|
CVE-2026-7736
|
2026-05-4 16:16 |
2026-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
434
|
2.5 |
LOW
Local
|
-
|
-
|
mutt before 2.3.2 has a show_sig_summary NULL pointer dereference.
New
|
CWE-476
NULL Pointer Dereference
|
CVE-2026-43864
|
2026-05-4 16:16 |
2026-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
435
|
3.7 |
LOW
Network
|
-
|
-
|
mutt before 2.3.2 has an infinite loop in data_object_to_stream in crypt-gpgme.c.
New
|
CWE-253
Incorrect Check of Function Return Value
|
CVE-2026-43863
|
2026-05-4 16:16 |
2026-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
436
|
3.7 |
LOW
Network
|
-
|
-
|
In mutt before 2.3.2, the imap_auth_gss security level is mishandled.
New
|
CWE-843
Type Confusion
|
CVE-2026-43862
|
2026-05-4 16:16 |
2026-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
437
|
3.7 |
LOW
Network
|
-
|
-
|
mutt before 2.3.2 does not check for '\0' in url_pct_decode.
New
|
CWE-158
Improper Neutralization of Null Byte or NUL Character
|
CVE-2026-43861
|
2026-05-4 16:16 |
2026-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
438
|
3.7 |
LOW
Network
|
-
|
-
|
mutt before 2.3.2 sometimes truncates the hash_passwd by one byte for IMAP auth_cram MD5 digest.
New
|
CWE-193
Off-by-one Error
|
CVE-2026-43860
|
2026-05-4 16:16 |
2026-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
439
|
3.7 |
LOW
Network
|
-
|
-
|
mutt before 2.3.2 sometimes uses strfcpy instead of memcpy for the IMAP auth_cram MD5 digest.
New
|
CWE-158
Improper Neutralization of Null Byte or NUL Character
|
CVE-2026-43859
|
2026-05-4 16:16 |
2026-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
440
|
- |
|
-
|
-
|
A critical IDOR vulnerability has been discovered in Comet Backup affecting all versions from 20.11.0 to 26.1.1 and 26.2.1. The vulnerability allows a tenant administrator to impersonate any end-user…
New
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-29200
|
2026-05-4 16:16 |
2026-05-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|