|
1591
|
7.8 |
HIGH
Local
|
-
|
-
|
Weak authentication in Dynamics Business Central allows an authorized attacker to elevate privileges locally.
|
CWE-1390
Weak Authentication
|
CVE-2026-40417
|
2026-05-14 00:34 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1592
|
7.8 |
HIGH
Local
|
-
|
-
|
Use after free in Microsoft Office Click-To-Run allows an authorized attacker to elevate privileges locally.
|
CWE-416
Use After Free
|
CVE-2026-40418
|
2026-05-14 00:34 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1593
|
7.8 |
HIGH
Local
|
-
|
-
|
Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally.
|
CWE-416
Use After Free
|
CVE-2026-40419
|
2026-05-14 00:34 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1594
|
8.8 |
HIGH
Local
|
-
|
-
|
Improper access control in Microsoft Office Click-To-Run allows an authorized attacker to elevate privileges locally.
|
CWE-284
Improper Access Control
|
CVE-2026-40420
|
2026-05-14 00:34 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1595
|
7.2 |
HIGH
Network
|
-
|
-
|
An administrative user with access to configure webhooks can execute arbitrary commands by configuring and then triggering webhooks containing specific FreeMarker template syntax.
This issue affe…
|
CWE-77
Command Injection
|
CVE-2026-8431
|
2026-05-14 00:34 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1596
|
8.8 |
HIGH
Network
|
-
|
-
|
An issue in MongoDB Server's time-series collection implementation allows an authenticated user with database write privileges to trigger an out-of-bounds memory write in the mongod process. The issu…
|
CWE-787
Out-of-bounds Write
|
CVE-2026-8053
|
2026-05-14 00:34 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1597
|
2.7 |
LOW
Network
|
-
|
-
|
When schema validation is enabled on a collection and an update or insert would violate the collection's schema, the local server log message generated may not have all user data redacted.
This is…
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2026-8200
|
2026-05-14 00:34 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1598
|
4.3 |
MEDIUM
Network
|
-
|
-
|
Using a densely populated chars mask and a large input string in the MongoDB aggregation operators $trim, $ltrim, and $rtrim, an authenticated user with aggregation permissions can pin CPU utilizatio…
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2026-8202
|
2026-05-14 00:34 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1599
|
4.8 |
MEDIUM
Network
|
-
|
-
|
Stored cross-site scripting (XSS) vulnerability in pgAdmin 4 Browser Tree and Explain Visualizer modules.
User-controlled PostgreSQL object names (database, schema, table, column, etc.) were assigne…
|
CWE-79
Cross-site Scripting
|
CVE-2026-7814
|
2026-05-14 00:34 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1600
|
9.9 |
CRITICAL
Network
|
-
|
-
|
Authorization vulnerability in pgAdmin 4 server mode affecting Server Groups, Servers, Shared Servers, Background Processes, and Debugger modules.
Multiple endpoints fetched user-owned objects witho…
|
CWE-284
Improper Access Control
|
CVE-2026-7813
|
2026-05-14 00:34 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|