|
1441
|
9.6 |
CRITICAL
Network
|
-
|
-
|
CodeWhale is a DeepSeek + MiMo coding agent in terminal. Prior to 0.8.26, the task_create tool spawns durable sub-agents that inherit two insecure defaults, allow_shell defaults to true (config.rs:14…
|
CWE-94
Code Injection
|
CVE-2026-45374
|
2026-05-30 13:17 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1442
|
7.4 |
HIGH
Network
|
-
|
-
|
CodeWhale is a DeepSeek + MiMo coding agent in terminal. Prior to 0.8.26, although SSRF is validated against hostnames that resolve to private IPv6 addresses, when providing the IPV6 in URL as htt…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-45373
|
2026-05-30 13:17 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1443
|
- |
|
-
|
-
|
LinkAce is a self-hosted archive to collect website links. Prior to 2.5.6, LinkAce contains a stored cross-site scripting vulnerability that allows a low-privilege user to execute arbitrary JavaScrip…
|
CWE-79
Cross-site Scripting
|
CVE-2026-45343
|
2026-05-30 13:17 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1444
|
7.4 |
HIGH
Network
|
-
|
-
|
CodeWhale is a DeepSeek + MiMo coding agent in terminal. Prior to 0.8.22, the fetch_url tool validates the initial URL's resolved IP address against a restricted-IP blocklist (is_restricted_ip()) to …
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-45310
|
2026-05-30 13:17 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1445
|
8.1 |
HIGH
Network
|
-
|
-
|
Microsoft UFO open-source framework for intelligent automation across devices and platforms. In 3.0.1-4-ge2626659, Microsoft UFO uses the user-controlled task_name value directly when constructing se…
|
CWE-22 CWE-73
Path Traversal External Control of File Name or Path
|
CVE-2026-46402
|
2026-05-30 11:16 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1446
|
8.8 |
HIGH
Network
|
-
|
-
|
phpMyFAQ before 4.1.3 contains an insecure direct object reference vulnerability in the admin API user password endpoint that allows authenticated administrators to change any user's password without…
|
CWE-266
Incorrect Privilege Assignment
|
CVE-2026-35671
|
2026-05-30 11:16 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1447
|
4.5 |
MEDIUM
Local
|
-
|
-
|
NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. Prior to 0.24.14, aio->prov_data is stored as nni_quic_conn* during dialing, but read as ex_quic_conn* during dialer close. This …
|
CWE-843
Type Confusion
|
CVE-2026-44640
|
2026-05-30 07:16 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1448
|
9.1 |
CRITICAL
Network
|
ibm
|
aspera_high-speed_transfer_server_for_cloud_pak_for_integration
|
IBM Aspera HSTS for CP4I 1.5.1 through 1.5.19
|
CWE-287 NVD-CWE-noinfo
Improper Authentication
|
CVE-2026-7876
|
2026-05-30 06:25 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1449
|
7.5 |
HIGH
Network
|
-
|
-
|
When processing a request with a URL path starting with /status or /sysinfo, WOSHttpStatusModule.dll is to be loaded to handle such URL patterns. The WOSBin_LoadHttpModule function in the dll would b…
|
CWE-476
NULL Pointer Dereference
|
CVE-2026-8359
|
2026-05-30 05:26 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1450
|
7.5 |
HIGH
Network
|
-
|
-
|
Function calls to WOSCommonUtil.dll!WOSSysInfoGetDeviceInterface() in various DLLs (i.e., WOSProfileMgrModule.dll, WOSWebDavModule.dll) can return a NULL pointer (i.e., when no user is logged into th…
|
CWE-476
NULL Pointer Dereference
|
CVE-2026-8360
|
2026-05-30 05:26 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|