|
81
|
7.3 |
HIGH
Network
|
-
|
-
|
Memory safety bugs present in Firefox 150.0.0 and Thunderbird 150.0.0. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exp…
New
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2026-7324
|
2026-04-29 01:16 |
2026-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
82
|
7.5 |
HIGH
Network
|
-
|
-
|
Information disclosure due to incorrect boundary conditions in the Audio/Video component. This vulnerability was fixed in Firefox 150.0.1, Firefox ESR 140.10.1, and Firefox ESR 115.35.1.
New
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2026-7320
|
2026-04-29 01:16 |
2026-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
83
|
7.3 |
HIGH
Network
|
-
|
-
|
The deprecated functions ns_printrrf, ns_printrr and fp_nquery in the GNU C Library version 2.2 and newer fail to enforce the caller-supplied buffer length, and can result in an out-of-bounds write w…
New
|
CWE-787
Out-of-bounds Write
|
CVE-2026-5435
|
2026-04-29 01:16 |
2026-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
84
|
- |
|
-
|
-
|
Cross-Site Scripting (XSS) vulnerability exists in FUEL CMS v1.5.2 and before within the asset upload functionality. The application fails to properly sanitize uploaded SVG files, allowing a low-priv…
New
|
-
|
CVE-2026-38948
|
2026-04-29 01:16 |
2026-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
85
|
- |
|
-
|
-
|
Authentication Bypass vulnerability exists in Netmaker versions prior to 1.5.0. The VerifyHostToken function in logic/jwts.go fails to validate the JWT signature when verifying host tokens. An attack…
New
|
-
|
CVE-2026-38651
|
2026-04-29 01:16 |
2026-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
86
|
9.8 |
CRITICAL
Network
|
-
|
-
|
MERCURY MIPC252W IP camera 1.0.5 Build 230306 Rel.79931n contains an improper authentication vulnerability in the RTSP service. After successful Digest authentication in an initial DESCRIBE request, …
New
|
CWE-287
Improper Authentication
|
CVE-2026-35903
|
2026-04-29 01:16 |
2026-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
87
|
7.5 |
HIGH
Network
|
-
|
-
|
An issue in Pro-Bit before v1.77.4 allows unauthenticated attackers to directly access sensitive directory and its subdirectories.
New
|
CWE-552
Files or Directories Accessible to External Parties
|
CVE-2025-69428
|
2026-04-29 01:16 |
2026-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
88
|
7.5 |
HIGH
Network
|
-
|
-
|
The Aranda File Server (AFS) component in Aranda Software Aranda Service Desk before 8.3.12 stores daily activity logs with predictable names in a publicly accessible directory, which allows unauthen…
New
|
CWE-377 CWE-532
Insecure Temporary File Inclusion of Sensitive Information in Log Files
|
CVE-2025-67223
|
2026-04-29 01:16 |
2026-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
89
|
- |
|
-
|
-
|
Insecure deserialization of untrusted input in StellarGroup HPX 1.11.0 under certain conditions may allow attackers to execute arbitrary code or other unspecified impacts.
New
|
-
|
CVE-2025-60889
|
2026-04-29 01:16 |
2026-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
90
|
5.3 |
MEDIUM
Network
|
-
|
-
|
An issue was discovered in Cista v0.15 and below. Insecure deserialization of untrusted input under certain conditions may lead to leaking of stack/heap addresses which may be used to bypass ASLR. Cl…
New
|
-
|
CVE-2025-60887
|
2026-04-29 01:16 |
2026-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|