|
271
|
3.1 |
LOW
Network
|
-
|
-
|
A format string argument mismatch in Netatalk 3.0.3 through 4.4.2 allows a remote authenticated attacker to cause a minor denial of service via crafted input that triggers incorrect format string pro…
New
|
CWE-134
Use of Externally-Controlled Format String
|
CVE-2026-7835
|
2026-05-22 00:20 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272
|
3.1 |
LOW
Network
|
-
|
-
|
An incorrect calculation in the hextoint macro in Netatalk 2.0.0 through 4.4.2 due to improper uppercase character handling allows a remote authenticated attacker to cause limited data modification v…
New
|
CWE-682
Incorrect Calculation
|
CVE-2026-7836
|
2026-05-22 00:20 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273
|
3.1 |
LOW
Network
|
-
|
-
|
A dead bounds check in the Spotlight RPC unmarshaller in Netatalk 3.0.0 through 4.4.2 results in an unreachable code path that provides no effective bounds protection, which may allow a remote authen…
New
|
CWE-561
Dead Code
|
CVE-2026-44057
|
2026-05-22 00:20 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
274
|
3.7 |
LOW
Network
|
-
|
-
|
Netatalk 3.1.2 through 4.4.2 is compiled without FORTIFY_SOURCE, which disables built-in buffer overflow detection at runtime, potentially allowing a remote attacker to cause a minor denial of servic…
New
|
CWE-693
Protection Mechanism Failure
|
CVE-2026-44071
|
2026-05-22 00:20 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
275
|
3.7 |
LOW
Network
|
-
|
-
|
Netatalk 2.1.0 through 4.4.2 combines multiple errno values using bitwise OR, resulting in incorrect error codes when multiple error conditions occur simultaneously, which may allow a remote attacker…
New
|
CWE-682
Incorrect Calculation
|
CVE-2026-44074
|
2026-05-22 00:20 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276
|
3.7 |
LOW
Network
|
-
|
-
|
A missing break statement in DSI OpenSession processing in Netatalk 1.5.0 through 4.4.2 causes a DSIOPT_ATTNQUANT switch case to fall through into DSIOPT_SERVQUANT, resulting in unintended session op…
New
|
CWE-484
|
CVE-2026-44075
|
2026-05-22 00:20 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277
|
3.7 |
LOW
Network
|
-
|
-
|
A time-of-check time-of-use (TOCTOU) condition in the ad_flush function in Netatalk 3.0.0 through 4.4.2 involves root-privileged file operations, which may allow a remote attacker to cause limited da…
New
|
CWE-367
Time-of-check Time-of-use (TOCTOU) Race Condition
|
CVE-2026-7837
|
2026-05-22 00:20 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278
|
10.0 |
CRITICAL
Network
|
-
|
-
|
Unrestricted Upload of File with Dangerous Type vulnerability in WP Swings Gift Cards For WooCommerce Pro allows Using Malicious Files.
This issue affects Gift Cards For WooCommerce Pro: from n/a th…
New
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2026-45444
|
2026-05-22 00:19 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279
|
6.1 |
MEDIUM
Network
|
-
|
-
|
TeleJSON prior to 6.0.0 contains a DOM-based cross-site scripting vulnerability in the parse() function that allows attackers to execute arbitrary JavaScript by delivering a crafted JSON payload cont…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-47099
|
2026-05-22 00:19 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280
|
4.3 |
MEDIUM
Network
|
-
|
-
|
The Broadstreet plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.52.2 via the get_sponsored_meta AJAX action due to missing validation on…
New
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-1881
|
2026-05-22 00:19 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|