|
411
|
8.8 |
HIGH
Network
|
anthropic
|
claude_code
|
In versions 2.1.63 through 2.1.83 of Claude Code, the folder trust determination logic used the git worktree commondir file without validating its contents. An attacker could craft a malicious reposi…
Update
|
CWE-20 CWE-77 NVD-CWE-noinfo
Improper Input Validation Command Injection
|
CVE-2026-40068
|
2026-05-13 01:21 |
2026-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
412
|
6.5 |
MEDIUM
Network
|
langgenius
|
dify
|
Dify before version 1.14.0 contains an authorization bypass vulnerability that allows authenticated users to read the full contents of files uploaded by other users within the same tenant by supplyin…
Update
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-41950
|
2026-05-13 01:20 |
2026-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
413
|
7.5 |
HIGH
Network
|
openmrs
|
openmrs
|
OpenMRS Core is an open source electronic medical record system platform. In versions 2.7.8 and earlier and versions 2.8.0 through 2.8.5, the `/openmrs/moduleResources/{moduleid}` endpoint is vulnera…
Update
|
CWE-22
Path Traversal
|
CVE-2026-40075
|
2026-05-13 01:18 |
2026-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
414
|
8.1 |
HIGH
Network
|
getgrav
|
grav
|
Grav is a file-based Web platform. Prior to 2.0.0-beta.2, a business logic vulnerability in the Grav Admin Panel allows a low-privileged user (with only user creation permissions) to overwrite existi…
New
|
CWE-269 CWE-285 CWE-639 CWE-837
Improper Privilege Management Improper Authorization Authorization Bypass Through User-Controlled Key Improper Enforcement of a Single, Unique Action
|
CVE-2026-42609
|
2026-05-13 01:16 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
415
|
6.5 |
MEDIUM
Network
|
getgrav
|
grav
|
Grav is a file-based Web platform. Prior to 2.0.0-beta.2, a low-privileged user (EX: Content Editor with only pages.update permissions) can bypass the existing Twig sandbox restrictions by utilizing …
New
|
CWE-863
Incorrect Authorization
|
CVE-2026-42610
|
2026-05-13 01:16 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
416
|
8.9 |
HIGH
Network
|
getgrav
|
grav
|
Grav is a file-based Web platform. Prior to 2.0.0-beta.2, a low-privileged (with the ability to create a page) user can cause XSS with the injection of svg element. The XSS can further be escalated t…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-42611
|
2026-05-13 01:16 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
417
|
5.4 |
MEDIUM
Network
|
getgrav
|
grav
|
Grav is a file-based Web platform. Prior to 2.0.0-beta.2, a stored Cross-Site Scripting (XSS) vulnerability in getgrav/grav allows publisher-level accounts to execute arbitrary JavaScript. The issue …
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-42612
|
2026-05-13 01:16 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
418
|
4.8 |
MEDIUM
Network
|
getgrav
|
grav
|
Grav is a file-based Web platform. Prior to 2.0.0-beta.2, an authenticated user with page editing permissions can inject an executable JavaScript event-handler attribute into rendered image HTML thro…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-42841
|
2026-05-13 01:16 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
419
|
9.6 |
CRITICAL
Network
|
-
|
-
|
On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated via the legitimate …
New
|
CWE-506
Embedded Malicious Code
|
CVE-2026-45321
|
2026-05-13 01:16 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
420
|
8.1 |
HIGH
Network
|
-
|
-
|
YetAnotherForum.NET (YAF.NET) is a C# ASP.NET forum. Prior to 4.0.5 and 3.2.12, the application's database logger (YAFNET.Core/Logger/DbLogger.cs) captures the incoming request's User-Agent header in…
New
|
CWE-79 CWE-80 CWE-116
Cross-site Scripting Basic XSS Improper Encoding or Escaping of Output
|
CVE-2026-43938
|
2026-05-13 01:16 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|