|
1201
|
3.5 |
LOW
Network
|
-
|
-
|
Admidio is an open-source user management solution. Prior to version 5.0.9, several administrative operations in Admidio's preferences module (database backup, test email, htaccess generation) fire v…
|
CWE-352
Origin Validation Error
|
CVE-2026-41663
|
2026-05-7 23:51 |
2026-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1202
|
4.3 |
MEDIUM
Network
|
flowiseai
|
flowise
|
A weakness has been identified in FlowiseAI Flowise up to 3.0.12. Affected by this vulnerability is an unknown functionality of the component User Controller Handler. This manipulation of the argumen…
|
CWE-285 CWE-639
Improper Authorization Authorization Bypass Through User-Controlled Key
|
CVE-2026-8027
|
2026-05-7 23:50 |
2026-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1203
|
3.7 |
LOW
Network
|
flowiseai
|
flowise
|
A vulnerability was detected in FlowiseAI Flowise up to 3.0.12. This affects the function verify of the file packages/server/src/enterprise/services/account.service.ts of the component Endpoint. Perf…
|
CWE-200 CWE-284 NVD-CWE-noinfo
Information Exposure Improper Access Control
|
CVE-2026-8028
|
2026-05-7 23:47 |
2026-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1204
|
8.8 |
HIGH
Network
|
-
|
-
|
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Gosoft Software Industry and Trade Ltd. Co. Proticaret E-Commerce allows Cross-Site Scripting (XS…
|
CWE-79
Cross-site Scripting
|
CVE-2026-3953
|
2026-05-7 23:44 |
2026-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1205
|
9.6 |
CRITICAL
Network
|
google
|
chrome
|
Use after free in Views in Google Chrome prior to 148.0.7778.96 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security…
|
CWE-416
Use After Free
|
CVE-2026-7910
|
2026-05-7 23:43 |
2026-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1206
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Origin Validation Error vulnerability in TUBITAK BILGEM Software Technologies Research Institute Liderahenk allows Accessing Functionality Not Properly Constrained by ACLs.
This issue affects Lidera…
|
CWE-346
Origin Validation Error
|
CVE-2026-6508
|
2026-05-7 23:42 |
2026-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1207
|
8.3 |
HIGH
Network
|
-
|
-
|
Improperly controlled modification of Dynamically-Determined object attributes, Allocation of resources without limits or throttling vulnerability in DivvyDrive Information Technologies Inc. DivvyDri…
|
CWE-770 CWE-915
Allocation of Resources Without Limits or Throttling Improperly Controlled Modification of Dynamically-Determined Object Attributes
|
CVE-2025-14341
|
2026-05-7 23:42 |
2026-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1208
|
9.6 |
CRITICAL
Network
|
-
|
-
|
URL redirection to untrusted site ('open redirect') vulnerability in DivvyDrive Information Technologies Inc. DivvyDrive allows Parameter Injection.
This issue affects DivvyDrive: from 4.8.2.9 befor…
|
CWE-601
Open Redirect
|
CVE-2026-6795
|
2026-05-7 23:42 |
2026-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1209
|
8.8 |
HIGH
Network
|
-
|
-
|
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in DivvyDrive Information Technologies Inc. DivvyDrive allows Stored XSS.
This issue affects DivvyD…
|
CWE-79
Cross-site Scripting
|
CVE-2026-5784
|
2026-05-7 23:42 |
2026-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1210
|
8.8 |
HIGH
Network
|
-
|
-
|
Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in DivvyDrive Information Technologies Inc. DivvyDrive allows Cross-Site Scripting (XSS).
This issue affec…
|
CWE-80
Basic XSS
|
CVE-2026-6002
|
2026-05-7 23:42 |
2026-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|