|
11
|
7.5 |
HIGH
Network
|
h2o
|
h2o
|
A vulnerability was identified in h2oai h2o-3 up to 7402. Affected by this issue is the function importFiles of the file h2o-core/src/main/java/water/persist/PersistNFS.java of the component ImportFi…
New
|
CWE-200 CWE-284 NVD-CWE-noinfo
Information Exposure Improper Access Control
|
CVE-2026-8750
|
2026-05-20 03:22 |
2026-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
12
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Audiobookshelf is a self-hosted audiobook and podcast server. Prior to 2.32.2, the GET /api/libraries/:id/download endpoint validates that the requesting user has access to the library specified in t…
Update
|
CWE-863
Incorrect Authorization
|
CVE-2026-42883
|
2026-05-20 03:19 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
13
|
6.2 |
MEDIUM
Network
|
-
|
-
|
LobeHub is a work-and-lifestyle space to find, build, and collaborate with agent teammates that grow with you. Prior to 2.1.48, when LobeChat processes custom tags in the Render process of src/featur…
Update
|
CWE-79
Cross-site Scripting
|
CVE-2026-42045
|
2026-05-20 03:19 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
14
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Memory safety bugs present in Thunderbird 140.10 and Thunderbird 150. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been expl…
New
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2026-8975
|
2026-05-20 03:16 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
15
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Memory safety bugs present in Thunderbird 140.10 and Thunderbird 150. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been expl…
New
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2026-8974
|
2026-05-20 03:16 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
16
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Memory safety bugs present in Thunderbird 150. Some of these bugs showed evidence of memory corruption and we presume that with enough effort some of these could have been exploited to run arbitrary …
New
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2026-8973
|
2026-05-20 03:16 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
17
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Privilege escalation in the WebRTC: Audio/Video component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.
New
|
CWE-269
Improper Privilege Management
|
CVE-2026-8972
|
2026-05-20 03:16 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
18
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Same-origin policy bypass in the Networking: JAR component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.
New
|
CWE-346
Origin Validation Error
|
CVE-2026-8971
|
2026-05-20 03:16 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
19
|
7.3 |
HIGH
Network
|
-
|
-
|
Privilege escalation in the Security component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.
New
|
CWE-269
Improper Privilege Management
|
CVE-2026-8970
|
2026-05-20 03:16 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
20
|
8.1 |
HIGH
Network
|
-
|
-
|
Mitigation bypass in the DOM: Security component. This vulnerability was fixed in Firefox 151 and Thunderbird 151.
New
|
CWE-693
Protection Mechanism Failure
|
CVE-2026-8969
|
2026-05-20 03:16 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|