|
1401
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Net::CIDR::Lite versions before 0.24 for Perl does not properly validate IP address and CIDR mask inputs, which may allow IP ACL bypass.
Inputs containing a trailing newline or non-ASCII digit chara…
New
|
CWE-1289
Improper Validation of Unsafe Equivalence in Input
|
CVE-2026-45190
|
2026-05-13 01:48 |
2026-05-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1402
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Net::CIDR::Lite versions before 0.24 for Perl does not properly consider extraneous zero characters in CIDR mask values, which may allow IP ACL bypass.
Mask forms like "/00" and "/01" pass validatio…
New
|
CWE-1289
Improper Validation of Unsafe Equivalence in Input
|
CVE-2026-45191
|
2026-05-13 01:48 |
2026-05-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1403
|
7.5 |
HIGH
Network
|
-
|
-
|
XML::LibXML versions through 2.0210 for Perl read out-of-bounds heap memory when parsing XML node names containing truncated UTF-8 byte sequences.
A node name ending in the middle of a multi byte UT…
New
|
CWE-125
Out-of-bounds Read
|
CVE-2026-8177
|
2026-05-13 01:48 |
2026-05-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1404
|
6.5 |
MEDIUM
Network
|
-
|
-
|
WebDyne::Session versions through 2.075 for Perl generates the session id insecurely.
The session handler generates the session id from an MD5 hash seeded with a call to the built-in rand() function…
New
|
CWE-338 CWE-340
Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) Generation of Predictable Numbers or Identifiers
|
CVE-2026-5084
|
2026-05-13 01:48 |
2026-05-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1405
|
6.5 |
MEDIUM
Network
|
-
|
-
|
HTTP::Tiny versions before 0.093 for Perl do not validate CRLF in HTTP request lines or control field header values.
The unvalidated inputs are the method and URI in the request line, the URL host t…
New
|
CWE-113
HTTP Response Splitting
|
CVE-2026-7010
|
2026-05-13 01:48 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1406
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Akilli Commerce Software Technologies Ltd. Co. E-Commerce Website allows SQL Injection.
This iss…
New
|
CWE-89
SQL Injection
|
CVE-2025-6577
|
2026-05-13 01:47 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1407
|
8.8 |
HIGH
Network
|
-
|
-
|
Authorization bypass through User-Controlled key vulnerability in ABIS Technology Ltd. Co. BAPSİS allows Exploitation of Trusted Identifiers.
This issue affects BAPSİS: before v.202604152042.
New
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-6001
|
2026-05-13 01:47 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1408
|
8.8 |
HIGH
Network
|
-
|
-
|
Incorrect Authorization vulnerability in E-Kalite Software Hardware Engineering Design and Internet Services Industry and Trade Ltd. Co. Turboard FOR-S allows Privilege Escalation.
This issue affect…
New
|
CWE-863
Incorrect Authorization
|
CVE-2026-2465
|
2026-05-13 01:47 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1409
|
- |
|
-
|
-
|
An improper authorization vulnerability in HCL BigFix WebUI allows an authenticated user without Master Operator privileges to access internal data (site names, versions, and configuration variables)…
Update
|
CWE-863
Incorrect Authorization
|
CVE-2025-15633
|
2026-05-13 01:45 |
2026-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1410
|
- |
|
-
|
-
|
A missing authorization vulnerability in HCL BigFix WebUI allows an authenticated user without proper permissions to view sensitive environmental information via direct URL access to the unauthorized…
Update
|
CWE-862
Missing Authorization
|
CVE-2025-15634
|
2026-05-13 01:45 |
2026-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|