|
171
|
6.1 |
MEDIUM
Network
|
-
|
-
|
A Cross Site Scripting vulnerability in Alkacon OpenCms before 10.5.1 exists via cmis-online/type.
New
|
CWE-79
Cross-site Scripting
|
CVE-2023-42343
|
2026-05-9 00:58 |
2026-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
172
|
7.3 |
HIGH
Network
|
-
|
-
|
Alkacon OpenCms before 10.5.1 allows remote unauthenticated attackers to obtain sensitive information via a cmis-online/query XXE attack on a Chemistry servlet.
New
|
CWE-611
XXE
|
CVE-2023-42344
|
2026-05-9 00:58 |
2026-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
173
|
6.1 |
MEDIUM
Network
|
-
|
-
|
A Cross Site Scripting vulnerability in Alkacon OpenCms before 16 exists via updateModelGroups.jsp.
New
|
CWE-79
Cross-site Scripting
|
CVE-2023-42345
|
2026-05-9 00:58 |
2026-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
174
|
- |
|
-
|
-
|
Alkacon OpenCms before 16 allows XXE when the <!DOCTYPE> refers to an external host.
New
|
-
|
CVE-2023-42346
|
2026-05-9 00:58 |
2026-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
175
|
8.7 |
HIGH
Network
|
-
|
-
|
Brave CMS is an open-source CMS. Prior to commit 6c56603, page and article body content entered through the CKEditor rich-text editor is stored verbatim in the database and subsequently rendered with…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-41524
|
2026-05-9 00:58 |
2026-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
176
|
7.1 |
HIGH
Network
|
-
|
-
|
Brave CMS is an open-source CMS. Prior to commit 6c56603, the contact form is publicly accessible (no authentication required). User-supplied message text is passed through PHP's nl2br() function, wh…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-41576
|
2026-05-9 00:58 |
2026-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
177
|
5.5 |
MEDIUM
Local
|
-
|
-
|
Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From version 3.0.0 to before version 3.8.0, a vulnerability in Nuclei's JavaScript protocol runtime allows JavaScript templates to …
New
|
CWE-284
Improper Access Control
|
CVE-2026-41646
|
2026-05-9 00:58 |
2026-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
178
|
5.3 |
MEDIUM
Network
|
-
|
-
|
Nuclei is a vulnerability scanner built on a simple YAML-based DSL. From version 3.0.0 to before version 3.8.0, a vulnerability in Nuclei's expression evaluation engine makes it possible for a malici…
New
|
CWE-94
Code Injection
|
CVE-2026-41645
|
2026-05-9 00:58 |
2026-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
179
|
8.5 |
HIGH
Network
|
-
|
-
|
n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. In versions 2.47.4 through 2.47.13, the SDK embedder path (N8NDocumentationMCPServer…
New
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-42449
|
2026-05-9 00:57 |
2026-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
180
|
9.8 |
CRITICAL
Network
|
-
|
-
|
electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to version 3.3.8, a command injection vulnerability exists in github.com/elcterm/electerm/npm/install.j…
New
|
CWE-77
Command Injection
|
CVE-2026-41500
|
2026-05-9 00:54 |
2026-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|