|
421
|
7.7 |
HIGH
Network
|
-
|
-
|
Improper input validation vulnerability in Progress Software MOVEit Automation allows Privilege Escalation.
This issue affects MOVEit Automation: from 2025.1.0 before 2025.1.5, from 2025.0.0 before …
New
|
CWE-20
Improper Input Validation
|
CVE-2026-5174
|
2026-05-1 02:20 |
2026-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
422
|
7.5 |
HIGH
Network
|
-
|
-
|
CryptPad 2025.3.1 allows unbounded WebSocket frame flood. A remote, unauthenticated attacker can significantly degrade or deny service for all users of a CryptPad instance. Fixed in 2026.2.2.
New
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2025-51846
|
2026-05-1 02:20 |
2026-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
423
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Synway SMG Gateway Management Software contains an OS command injection vulnerability in the RADIUS configuration endpoint at /en/9-2radius.php where the radius_address POST parameter is split and in…
New
|
CWE-78
OS Command
|
CVE-2025-71284
|
2026-05-1 02:20 |
2026-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
424
|
7.5 |
HIGH
Network
|
-
|
-
|
Weaver (Fanwei) E-cology 9.5 versions prior to 10.52 contain an arbitrary file read vulnerability in the XmlRpcServlet interface at the XML-RPC endpoint that allows unauthenticated remote attackers t…
New
|
CWE-22
Path Traversal
|
CVE-2022-50992
|
2026-05-1 02:19 |
2026-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
425
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Weaver (Fanwei) E-office versions prior to 10.0_20221201 contain an unauthenticated arbitrary file upload vulnerability in the OfficeServer.php endpoint that allows remote attackers to upload malicio…
New
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2022-50993
|
2026-05-1 02:19 |
2026-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
426
|
8.8 |
HIGH
Network
|
-
|
-
|
A Cross-Site Request Forgery (CSRF) vulnerability exists in the web management interface of the U-SPEED N300 Rounter V1.0.0. The device does not implement CSRF protection mechanisms such as anti-CSRF…
New
|
CWE-352
Origin Validation Error
|
CVE-2026-36960
|
2026-05-1 02:16 |
2026-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
427
|
9.8 |
CRITICAL
Network
|
-
|
-
|
cPanel and WHM versions after 11.40 contain an authentication bypass vulnerability in the login flow that allows unauthenticated remote attackers to gain unauthorized access to the control panel.
New
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2026-41940
|
2026-05-1 02:16 |
2026-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
428
|
- |
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
rtnetlink: add missing netlink_ns_capable() check for peer netns
rtnl_newlink() lacks a CAP_NET_ADMIN capability check on the pee…
New
|
-
|
CVE-2026-31692
|
2026-05-1 02:11 |
2026-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
429
|
- |
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
cifs: some missing initializations on replay
In several places in the code, we have a label to signify
the start of the code wher…
New
|
-
|
CVE-2026-31693
|
2026-05-1 02:11 |
2026-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
430
|
- |
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
Buffer overflow in drivers/xen/sys-hypervisor.c
The build id returned by HYPERVISOR_xen_version(XENVER_build_id) is
neither NUL t…
New
|
-
|
CVE-2026-31786
|
2026-05-1 02:11 |
2026-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|