|
131
|
5.5 |
MEDIUM
Local
|
-
|
-
|
Gryph provides a security layer for AI coding agents. Prior to 0.7.0, Gryph implements logging levels that determine what content is logged to a local sqlite database. The README incorrectly mentions…
Update
|
CWE-212
Improper Removal of Sensitive Information Before Storage or Transfer
|
CVE-2026-45046
|
2026-06-2 03:26 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
132
|
8.7 |
HIGH
Network
|
-
|
-
|
RELATE is a web-based courseware package. Versions prior to commit 555f0efb1c5bd7531c07cd73724d7e566a81f620 have a stored cross-site scripting vulnerability that allows any enrolled student to execut…
Update
|
CWE-79
Cross-site Scripting
|
CVE-2026-42197
|
2026-06-2 03:26 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
133
|
3.1 |
LOW
Network
|
apache
|
airflow
|
Exploitation requires the attacker to already be an authenticated Airflow worker holding a valid Log-server JWT issued for at least one Dag. Apache Airflow's Log server authorized JWT tokens against …
New
|
CWE-863
Incorrect Authorization
|
CVE-2026-45426
|
2026-06-2 03:25 |
2026-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
134
|
4.3 |
MEDIUM
Network
|
apache
|
airflow
|
The Event Log detail endpoint `GET /api/v2/eventLogs/{event_log_id}` in Apache Airflow fetched audit-log rows directly by numeric ID after only the generic Audit Log permission check, while the colle…
New
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-46764
|
2026-06-2 03:24 |
2026-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
135
|
7.5 |
HIGH
Network
|
apache
|
fluss
|
Apache Fluss versions prior to 0.9.1 configure the Netty LengthFieldBasedFrameDecoder with Integer.MAX_VALUE as the maximum frame length, allowing unauthenticated remote attackers to exhaust JVM heap…
New
|
CWE-400 CWE-770
Uncontrolled Resource Consumption Allocation of Resources Without Limits or Throttling
|
CVE-2026-49361
|
2026-06-2 03:24 |
2026-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
136
|
8.0 |
HIGH
Network
|
openclaw
|
openclaw
|
OpenClaw before 2026.5.18 contains an authorization bypass vulnerability in QQBot native approval buttons that fails to enforce configured approver identity. Non-approver users can click approval but…
Update
|
CWE-862
Missing Authorization
|
CVE-2026-35630
|
2026-06-2 03:23 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
137
|
8.2 |
HIGH
Network
|
-
|
-
|
GuardDog is a CLI tool to identify malicious PyPI packages. From 1.0.0 to 2.9.0, the programmatic remote project scanning path rewrites attacker-controlled repository URLs using a blind string replac…
Update
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-44971
|
2026-06-2 03:23 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
138
|
6.2 |
MEDIUM
Local
|
-
|
-
|
go-ipld-prime is an implementation of the InterPlanetary Linked Data (IPLD) spec interfaces, a batteries-included codec implementations of IPLD for CBOR and JSON, and tooling for basic operations on …
Update
|
CWE-674
Uncontrolled Recursion
|
CVE-2026-42328
|
2026-06-2 03:23 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
139
|
8.8 |
HIGH
Network
|
-
|
-
|
elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.68, an authenticated SQL injection vulnerability in the elFinder MySQL volume driver (elFinderVolu…
Update
|
CWE-89
SQL Injection
|
CVE-2026-44521
|
2026-06-2 03:23 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
140
|
- |
|
-
|
-
|
Cinny is a Matrix client. Prior to 4.10.3, A remote authenticated attacker who shares a room with a victim and has permissions to create room emotes (for example in a DM) can cause the victim's clien…
Update
|
CWE-20
Improper Input Validation
|
CVE-2026-42553
|
2026-06-2 03:23 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|