|
971
|
7.2 |
HIGH
Network
|
arubanetworks
|
arubaos sd-wan
|
Command injection vulnerabilities exist in the web-based management interface of AOS-8 and AOS-10 Operating Systems. Successful exploitation could allow an authenticated remote attacker to upload arb…
New
|
CWE-77
Command Injection
|
CVE-2026-44854
|
2026-05-15 00:12 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
972
|
7.2 |
HIGH
Network
|
arubanetworks
|
arubaos sd-wan
|
Command injection vulnerabilities exist in the web-based management interface of AOS-8 and AOS-10 Operating Systems. Successful exploitation could allow an authenticated remote attacker to upload arb…
New
|
CWE-77
Command Injection
|
CVE-2026-44853
|
2026-05-15 00:05 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
973
|
7.0 |
HIGH
Local
|
microsoft
|
windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2012 windows_server_2016 w…
|
Double free in Windows Link-Layer Discovery Protocol (LLDP) allows an authorized attacker to elevate privileges locally.
Update
|
CWE-415
Double Free
|
CVE-2026-34341
|
2026-05-15 00:00 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
974
|
7.0 |
HIGH
Local
|
microsoft
|
windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2012 windows_server_2016 w…
|
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Print Spooler Components allows an authorized attacker to elevate privileges locally.
|
CWE-362
Race Condition
|
CVE-2026-34342
|
2026-05-14 23:59 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
975
|
7.8 |
HIGH
Local
|
microsoft
|
windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2012 windows_server_2016 w…
|
Heap-based buffer overflow in Windows Application Identity (AppID) Subsystem allows an authorized attacker to elevate privileges locally.
|
CWE-122
Heap-based Buffer Overflow
|
CVE-2026-34343
|
2026-05-14 23:58 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
976
|
7.8 |
HIGH
Local
|
ashlar
|
argon cobalt cobalt_share lithium xenon
|
An Out-of-Bounds Write vulnerability is present in Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions 12.6.1204.216 and prior that could allow an attacker to execute arbitrary cod…
|
CWE-787
Out-of-bounds Write
|
CVE-2025-65086
|
2026-05-14 23:57 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
977
|
7.8 |
HIGH
Local
|
ashlar
|
argon cobalt cobalt_share lithium xenon
|
An Out-of-Bounds Read vulnerability is present in Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions 12.6.1204.216 and prior that could allow an attacker to disclose information o…
|
CWE-125
Out-of-bounds Read
|
CVE-2025-65087
|
2026-05-14 23:57 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
978
|
7.8 |
HIGH
Local
|
ashlar
|
argon cobalt cobalt_share lithium xenon
|
An Out-of-Bounds Read vulnerability is present in Ashlar-Vellum Cobalt, Xenon, Argon, Lithium, and Cobalt Share versions 12.6.1204.216 and prior that could allow an attacker to disclose information o…
|
CWE-125
Out-of-bounds Read
|
CVE-2025-65088
|
2026-05-14 23:57 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
979
|
8.8 |
HIGH
Network
|
requarks
|
wiki.js
|
Wiki.js is an open source wiki app built on Node.js. Prior to 2.5.313, the users.update GraphQL mutation accepts an arbitrary groups array and applies it directly to the database with no validation o…
|
CWE-269 NVD-CWE-noinfo
Improper Privilege Management
|
CVE-2026-44224
|
2026-05-14 23:56 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
980
|
6.7 |
MEDIUM
Local
|
microsoft
|
windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2012 windows_server_2016 w…
|
Double free in Windows Rich Text Edit allows an authorized attacker to elevate privileges locally.
|
CWE-415
Double Free
|
CVE-2026-21530
|
2026-05-14 23:56 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|