|
41
|
- |
|
-
|
-
|
In ScadaBR version 1.2.0, a CSRF vulnerability could allow an attacker to trigger any authenticated action through a victim's session by luring any logged-in user to a malicious webpage.
New
|
CWE-352
Origin Validation Error
|
CVE-2026-8604
|
2026-05-20 03:16 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
42
|
- |
|
-
|
-
|
In ScadaBR version 1.2.0, an OS Command Injection vulnerability could allow an attacker to execute commands as root on the SCADA system.
New
|
CWE-78
OS Command
|
CVE-2026-8603
|
2026-05-20 03:16 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
43
|
- |
|
-
|
-
|
In ScadaBR version 1.2.0, a Missing Authentication for Critical Function vulnerability could allow an unauthenticated attacker to send a HTTP GET requests to the SCADA system and inject arbitrary sen…
New
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2026-8602
|
2026-05-20 03:16 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
44
|
9.8 |
CRITICAL
Network
|
mozilla
|
firefox
|
Sandbox escape in the Profile Backup component. This vulnerability was fixed in Firefox 150.0.3, Firefox ESR 115.36, Firefox ESR 140.11, and Thunderbird 140.11.
Update
|
CWE-693
Protection Mechanism Failure
|
CVE-2026-8401
|
2026-05-20 03:16 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
45
|
5.3 |
MEDIUM
Network
|
mozilla
|
firefox
|
Other issue in the JavaScript Engine component. This vulnerability was fixed in Firefox 150.0.3, Firefox ESR 115.36, Firefox ESR 140.11, and Thunderbird 140.11.
Update
|
CWE-20 CWE-79 CWE-119
Improper Input Validation Cross-site Scripting Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2026-8391
|
2026-05-20 03:16 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
46
|
6.5 |
MEDIUM
Network
|
mozilla
|
firefox
|
Incorrect boundary conditions in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 150.0.3, Firefox ESR 115.36, Firefox ESR 140.11, and Thunderbird 140.11.
Update
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2026-8388
|
2026-05-20 03:16 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
47
|
6.5 |
MEDIUM
Network
|
-
|
-
|
LWP::UserAgent versions before 6.83 for Perl leak Authorization and Proxy-Authorization headers on cross-origin redirects.
On a 3xx response, the redirect handler strips only Host and Cookie before …
Update
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2026-8368
|
2026-05-20 03:16 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
48
|
- |
|
-
|
-
|
Java Deserialisation Vulnerability in Jaspersoft Reports Library leads to Remote Code Execution (RCE), potentially allowing code execution on the affected system
New
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-6009
|
2026-05-20 03:16 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
49
|
9.6 |
CRITICAL
Network
|
-
|
-
|
Windmill prior to 1.703.2 contains an incorrect default permissions vulnerability in nsjail sandbox configuration files where /etc is bind-mounted without read-write restrictions, allowing authentica…
New
|
CWE-276
Incorrect Default Permissions
|
CVE-2026-47107
|
2026-05-20 03:16 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
50
|
8.7 |
HIGH
Network
|
openwebui
|
open_webui
|
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.3, the audio transcription upload endpoint takes the file extension from the user-suppl…
Update
|
CWE-79 CWE-434 CWE-646
Cross-site Scripting Unrestricted Upload of File with Dangerous Type Reliance on File Name or Extension of Externally-Supplied File
|
CVE-2026-45315
|
2026-05-20 03:16 |
2026-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|