|
1421
|
5.4 |
MEDIUM
Network
|
-
|
-
|
Plunk is an open-source email platform built on top of AWS SES. Prior to version 0.9.0, a stored cross-site scripting (XSS) vulnerability exists in the campaign management feature, where the email bo…
Update
|
CWE-79
Cross-site Scripting
|
CVE-2026-42192
|
2026-05-13 01:45 |
2026-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1422
|
- |
|
-
|
-
|
SolidCAM-GPPL-IDE is an unofficial, independently developed extension, Postprocessor IDE for SolidCAM. From version 1.0.0 to before version 1.0.2, Opening a .gpp file in the SolidCAM Postprocessor ID…
Update
|
CWE-400 CWE-611 CWE-776
Uncontrolled Resource Consumption XXE XML Entity Expansion
|
CVE-2026-42212
|
2026-05-13 01:43 |
2026-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1423
|
- |
|
-
|
-
|
SolidCAM-GPPL-IDE is an unofficial, independently developed extension, Postprocessor IDE for SolidCAM. From version 1.0.0 to before version 1.0.2, the inc "filename" directive in GPPL postprocessor f…
Update
|
CWE-22 CWE-200 CWE-295 CWE-918
Path Traversal Information Exposure Improper Certificate Validation Server-Side Request Forgery (SSRF)
|
CVE-2026-42213
|
2026-05-13 01:43 |
2026-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1424
|
6.8 |
MEDIUM
Network
|
-
|
-
|
There is an Access Control Vulnerability in some HikCentral Professional versions. This could allow an unauthenticated user to obtain the admin permission.
Update
|
CWE-284
Improper Access Control
|
CVE-2026-1749
|
2026-05-13 01:42 |
2026-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1425
|
5.3 |
MEDIUM
Adjacent
|
-
|
-
|
Some EZVIZ products utilize older versions of cloud feature modules with legacy API interfaces, which pose a data transmission risk. Attackers can exploit this by eavesdropping on network requests to…
Update
|
-
|
CVE-2026-32683
|
2026-05-13 01:42 |
2026-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1426
|
7.2 |
HIGH
Network
|
-
|
-
|
Some Hikvision switch products (discontinued since December 2023) are vulnerable to authenticated remote command execution due to insufficient input validation. Attackers with valid credentials can e…
Update
|
CWE-78
OS Command
|
CVE-2026-3828
|
2026-05-13 01:42 |
2026-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1427
|
- |
|
-
|
-
|
FastGPT is an AI Agent building platform. In versions 4.14.13 and prior, the code-sandbox component suffers from insufficient resource isolation and uncontrolled resource consumption. The service rel…
Update
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2026-42343
|
2026-05-13 01:41 |
2026-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1428
|
7.5 |
HIGH
Network
|
-
|
-
|
pygeoapi is a Python server implementation of the OGC API suite of standards. From version 0.23.0 to before version 0.23.3, a raw string path concatenation vulnerability in pygeoapi's STAC FileSystem…
Update
|
CWE-22
Path Traversal
|
CVE-2026-42351
|
2026-05-13 01:41 |
2026-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1429
|
8.6 |
HIGH
Network
|
-
|
-
|
pygeoapi is a Python server implementation of the OGC API suite of standards. From version 0.23.0 to before version 0.23.3, OGC API process execution requests can use the subscriber object to reques…
Update
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-42352
|
2026-05-13 01:41 |
2026-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1430
|
8.1 |
HIGH
Network
|
-
|
-
|
Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to version 2.1.0, /users/login issues a temporary JWT (temp_token) for TOTP-enabled…
Update
|
CWE-304
Missing Critical Step in Authentication
|
CVE-2026-42452
|
2026-05-13 01:40 |
2026-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|