|
1681
|
5.4 |
MEDIUM
Network
|
-
|
-
|
TypeBot is a chatbot builder tool. In versions prior to 3.16.0, the Typebot viewer (packages/embeds/js) renders anchor tags from rich text bubble content without filtering the javascript: URI scheme.…
|
CWE-79
Cross-site Scripting
|
CVE-2026-39964
|
2026-05-23 13:16 |
2026-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1682
|
8.1 |
HIGH
Network
|
-
|
-
|
(Externally Controlled Reference to a Resource in Another Sphere), (Authorization Bypass Through User-Controlled Key) vulnerability in Apache Camel K. Authorized users in a Kubernetes namespace can c…
|
CWE-610 CWE-639
Externally Controlled Reference to a Resource in Another Sphere Authorization Bypass Through User-Controlled Key
|
CVE-2026-45760
|
2026-05-23 12:16 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1683
|
8.1 |
HIGH
Network
|
-
|
-
|
NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_rewrite_module module. This vulnerability exists when a rewrite directive uses a regex pattern with distinct, overlapping Perl-Co…
|
CWE-122
Heap-based Buffer Overflow
|
CVE-2026-9256
|
2026-05-23 10:16 |
2026-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1684
|
6.8 |
MEDIUM
Physics
|
microsoft
|
windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2025
|
Microsoft is aware of a security feature bypass vulnerability in Windows publicly referred to as "YellowKey". The proof of concept for this vulnerability has been made public violating coor…
|
CWE-77
Command Injection
|
CVE-2026-45585
|
2026-05-23 08:16 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1685
|
4.3 |
MEDIUM
Network
|
apache
|
cxf
|
An LDAP injection vulnerability in the LDAP Certificate repository of the XKMS server in Apache CXF may allow an attacker to retrieve arbitrary certificates from the repository.
Users are recommende…
|
CWE-90
LDAP Injection
|
CVE-2026-44930
|
2026-05-23 07:16 |
2026-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1686
|
5.3 |
MEDIUM
Network
|
apache
|
cxf
|
Insecure XML parser configuration in Apache CXF's WS-Transfer module may allow attackers to perform XXE attacks.
Users are recommended to upgrade to versions 4.2.1, 4.1.6 or 3.6.11, which fix this is…
|
CWE-611
XXE
|
CVE-2026-44618
|
2026-05-23 07:16 |
2026-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1687
|
- |
|
-
|
-
|
TypeBot is a chatbot builder tool. Versions 3.15.2 and prior contain a critical stored XSS vulnerability in the app.typebot.io profile picture upload form. The application fails to sanitize or restri…
|
CWE-79
Cross-site Scripting
|
CVE-2026-39970
|
2026-05-23 06:16 |
2026-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1688
|
9.8 |
CRITICAL
Network
|
kovidgoyal
|
kitty
|
Kitty is a cross-platform GPU based terminal. In versions 0.46.2 and below, the handle_compose_command() function in kitty/graphics.c performs bounds validation on composition offsets using unsigned …
|
CWE-125 CWE-190 CWE-787
Out-of-bounds Read Integer Overflow or Wraparound Out-of-bounds Write
|
CVE-2026-33642
|
2026-05-23 06:05 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1689
|
8.8 |
HIGH
Network
|
kovidgoyal
|
kitty
|
Kitty is a cross-platform GPU based terminal. Versions 0.46.2 and below contain a heap buffer overflow in load_image_data() that allows any process which can write to the terminal's stdin to crash ki…
|
CWE-122
Heap-based Buffer Overflow
|
CVE-2026-33633
|
2026-05-23 06:04 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1690
|
9.6 |
CRITICAL
Network
|
lfprojects
|
mlflow
|
In MLflow version 3.9.0, the MLflow Assistant feature introduced improper origin validation in its /ajax-api endpoints. This vulnerability allows a remote attacker to exploit cross-origin requests fr…
|
CWE-346
Origin Validation Error
|
CVE-2026-2611
|
2026-05-23 06:00 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|