|
81
|
8.1 |
HIGH
Network
|
agilonhealth
|
minerva
|
An insecure direct object reference (IDOR) vulnerability in MphRx's Minerva V3.6.0, specifically in the endpoint '/minerva/moUser/show/'. If this vulnerability is successfully exploited, an authentic…
Update
|
CWE-284
Improper Access Control
|
CVE-2026-5780
|
2026-05-5 23:22 |
2026-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
82
|
5.5 |
MEDIUM
Local
|
canonical
|
pdfunite
|
PDFunite 0.41.0 contains a buffer overflow vulnerability that allows local attackers to crash the application by processing malformed PDF files during merge operations. Attackers can trigger a segmen…
Update
|
CWE-120
Classic Buffer Overflow
|
CVE-2018-25306
|
2026-05-5 23:22 |
2026-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
83
|
8.8 |
HIGH
Network
|
agilonhealth
|
minerva
|
An insecure direct object reference (IDOR) vulnerability in MphRx's Minerva V3.6.0, specifically in the '/minerva/user/updateUserProfile' endpoint. This allows an authenticated user to modify the inf…
Update
|
CWE-284
Improper Access Control
|
CVE-2026-5779
|
2026-05-5 23:20 |
2026-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
84
|
9.8 |
CRITICAL
Network
|
-
|
-
|
A security vulnerability has been detected in EFM ipTIME NAS1dual 1.5.24. This issue affects the function get_csrf_whites of the file /cgi/advanced/misc_main.cgi. Such manipulation leads to stack-bas…
New
|
CWE-119 CWE-121
Incorrect Access of Indexable Resource ('Range Error') Stack-based Buffer Overflow
|
CVE-2026-7834
|
2026-05-5 23:16 |
2026-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
85
|
5.0 |
MEDIUM
Network
|
-
|
-
|
An issue that could allow a dashboard configuration to be viewed from outside of the authorized organization scope has been resolved. This is an instance of CWE-269: Improper Privilege Management, an…
New
|
CWE-269
Improper Privilege Management
|
CVE-2026-7778
|
2026-05-5 23:16 |
2026-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
86
|
- |
|
-
|
-
|
In Eclipse Open9J versions 0.21 to 0.58, a pre-authentication remote attacker can crash JITServer by sending a 32-byte crafted TCP message.
New
|
CWE-125
Out-of-bounds Read
|
CVE-2026-6918
|
2026-05-5 23:16 |
2026-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
87
|
7.5 |
HIGH
Network
|
-
|
-
|
The WeePie Cookie Allow plugin for WordPress is vulnerable to SQL Injection via the 'consent' parameter in all versions up to, and including, 3.4.11 due to insufficient escaping on the user supplied …
New
|
CWE-89
SQL Injection
|
CVE-2026-4304
|
2026-05-5 23:16 |
2026-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
88
|
7.2 |
HIGH
Network
|
-
|
-
|
OpenSTAManager version 2.10 and earlier contains an arbitrary file upload vulnerability in the module update functionality (modules/aggiornamenti/upload_modules.php)
New
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2026-38751
|
2026-05-5 23:16 |
2026-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
89
|
- |
|
-
|
-
|
An issue was discovered in Gambio 4.9.2.0 (patched in 2024-02 v1.0.0 for GX4 v4.0.0.0 to v4.9.2.0). The password reset function can be bypassed to set arbitrary passwords for arbitrary accounts if th…
New
|
-
|
CVE-2026-34408
|
2026-05-5 23:16 |
2026-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
90
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Traccar is an open source GPS tracking system. In versions between 6.11.1 and 6.13.0, the CSV export functionality writes position data, including user-controlled device and computed attributes, to C…
New
|
CWE-1236
Improper Neutralization of Formula Elements in a CSV File
|
CVE-2026-27644
|
2026-05-5 23:16 |
2026-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|