|
791
|
9.8 |
CRITICAL
Network
|
ibm
|
engineering_lifecycle_management
|
IBM Engineering Lifecycle Management 7.0.3, 7.1.0, and 7.2.0 could allow an unauthenticated remote attacker to update server property files that would allow them to gain unauthorized access to the ap…
|
CWE-863
Incorrect Authorization
|
CVE-2026-3660
|
2026-05-30 04:31 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
792
|
9.6 |
CRITICAL
Network
|
amirraminfar
|
dozzle
|
Dozzle is a realtime log viewer for docker containers. Prior to 10.5.2, he WebSocket upgrader for the /exec and /attach endpoints uses CheckOrigin: func(r *http.Request) bool { return true }, accepti…
|
CWE-346
Origin Validation Error
|
CVE-2026-44985
|
2026-05-30 04:30 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
793
|
7.1 |
HIGH
Adjacent
|
free5gc
|
free5gc
|
free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, the AMF in Free5GC does not verify the UE Security Capabilities received in NGAP PathSwitchRequest messages against it…
|
CWE-358
Improperly Implemented Security Check for Standard
|
CVE-2026-42081
|
2026-05-30 04:24 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
794
|
8.6 |
HIGH
Network
|
amirraminfar
|
dozzle
|
Dozzle is a realtime log viewer for docker containers. Prior to 10.5.2, in a default dozzle deploy (the documented quickstart, no DOZZLE_AUTH_PROVIDER set), POST /api/notifications/test-webhook is re…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-45298
|
2026-05-30 04:23 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
795
|
7.5 |
HIGH
Network
|
tanium
|
server
|
Tanium addressed a denial of service vulnerability in Tanium Server.
|
CWE-772
Missing Release of Resource after Effective Lifetime
|
CVE-2026-9156
|
2026-05-30 04:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
796
|
7.8 |
HIGH
Local
|
synology
|
beedrive
|
Uncontrolled search path element vulnerability in OpenSSL DLL component in Synology BeeDrive for desktop before 1.3.2-13814 allows local users to execute arbitrary code via unspecified vectors.
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2023-52945
|
2026-05-30 04:13 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
797
|
8.8 |
HIGH
Local
|
docker
|
docker_desktop
|
The Docker CLI --use-api-socket flag bypasses Enhanced Container Isolation (ECI) restrictions in Docker Desktop. When ECI is enabled, Docker socket mounts from containers are denied unless explicitly…
|
CWE-863
Incorrect Authorization
|
CVE-2026-6406
|
2026-05-30 04:02 |
2026-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
798
|
6.1 |
MEDIUM
Network
|
heartcombo
|
devise
|
Devise is an authentication solution for Rails based on Warden. In versions 5.0.3 and below, when the Timeoutable module is enabled in Devise, the FailureApp#redirect_url method returns request.refer…
|
CWE-601
Open Redirect
|
CVE-2026-40295
|
2026-05-30 03:55 |
2026-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
799
|
5.5 |
MEDIUM
Local
|
bentoml
|
bentoml
|
BentoML is a Python library for building online serving systems optimized for AI apps and model inference. In versions 1.4.38 and prior, the build packaging workflow follows attacker-controlled symli…
|
CWE-59
Link Following
|
CVE-2026-40610
|
2026-05-30 03:53 |
2026-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
800
|
8.8 |
HIGH
Network
|
google
|
chrome
|
Out of bounds write in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: Critical)
|
CWE-787
Out-of-bounds Write
|
CVE-2026-9879
|
2026-05-30 03:46 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|