|
651
|
- |
|
-
|
-
|
Improper input validation in Delphix Continuous Data connectors allows an authenticated user to execute arbitrary operating system commands on the staging or target host.
|
CWE-78
OS Command
|
CVE-2026-8654
|
2026-05-15 23:11 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
652
|
8.8 |
HIGH
Network
|
-
|
-
|
Crabbox prior to v0.12.0 contains an authentication bypass vulnerability that allows non-admin shared-token callers to impersonate other owners or organizations by spoofing identity headers. Attacker…
|
CWE-287
Improper Authentication
|
CVE-2026-8621
|
2026-05-15 23:11 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
653
|
8.1 |
HIGH
Network
|
-
|
-
|
Crabbox prior to v0.12.0 contains a privilege escalation vulnerability that allows users with shared visibility-only access to obtain Code, WebVNC, and Egress agent tickets by sending POST requests t…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-8629
|
2026-05-15 23:11 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
654
|
7.2 |
HIGH
Network
|
-
|
-
|
Missing integrity verification in the Triton inference handler in Amazon SageMaker Python SDK v2 before v2.257.2 and v3 before v3.8.0 might allow a remote authenticated actor to achieve code executio…
|
CWE-354
Improper Validation of Integrity Check Value
|
CVE-2026-8597
|
2026-05-15 23:10 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
655
|
7.2 |
HIGH
Network
|
-
|
-
|
Cleartext storage of sensitive information in the ModelBuilder/Serve component in Amazon SageMaker Python SDK before v2.257.2 and v3 before v3.8.0 might allow a remote authenticated actor to extract …
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2026-8596
|
2026-05-15 23:10 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
656
|
- |
|
-
|
-
|
Improper input validation in the AMD OverDrive (AOD) System Management Mode (SMM) module could allow a privileged attacker to perform an out-of-bounds read, potentially resulting in loss of confident…
|
CWE-1274
Improper Access Control for Volatile Memory Containing Boot Code
|
CVE-2024-36345
|
2026-05-15 23:10 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
657
|
- |
|
-
|
-
|
Improper Input validation in the AMD Secure Processor (ASP) PCI driver may allow a local attacker to create a buffer overflow condition, potentially resulting in a crash or denial of service
|
CWE-120
Classic Buffer Overflow
|
CVE-2025-0045
|
2026-05-15 23:10 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
658
|
- |
|
-
|
-
|
Incorrect default permissions in the installation directory for the AMD general-purpose input/output controller (GPIO) could allow an attacker to achieve privilege escalation resulting in arbitrary c…
|
CWE-276
Incorrect Default Permissions
|
CVE-2025-48512
|
2026-05-15 23:10 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
659
|
- |
|
-
|
-
|
An improper input validation vulnerability within the AMD Platform Management Framework (PMF) driver can allow a local attacker to read or write Out-of-Bounds, potentially resulting in privilege esca…
|
CWE-787
Out-of-bounds Write
|
CVE-2025-48519
|
2026-05-15 23:10 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
660
|
- |
|
-
|
-
|
An improper input validation vulnerability within the AMD Platform Management Framework (PMF) driver can allow a local attacker to read Out-of-Bounds potentially resulting in information disclosure o…
|
CWE-125
Out-of-bounds Read
|
CVE-2025-48520
|
2026-05-15 23:10 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|