|
461
|
7.5 |
HIGH
Network
|
mozilla
|
firefox thunderbird
|
Spoofing issue in WebExtensions. This vulnerability was fixed in Firefox 151 and Thunderbird 151.
New
|
CWE-290
Authentication Bypass by Spoofing
|
CVE-2026-8960
|
2026-05-20 23:20 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
462
|
8.6 |
HIGH
Network
|
tenable
|
terrascan
|
Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via external URL resolution in uploaded IaC templates when running in server mode. When Terrascan parses uploaded ARM …
New
|
CWE-73 CWE-610 CWE-918
External Control of File Name or Path Externally Controlled Reference to a Resource in Another Sphere Server-Side Request Forgery (SSRF)
|
CVE-2026-47358
|
2026-05-20 23:18 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
463
|
6.5 |
MEDIUM
Network
|
struktur
|
libheif
|
libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and below, a crafted 792-byte HEIF sequence file with samples_per_chunk=0 in the stsc box causes an unsigned integer und…
New
|
CWE-125 CWE-476
Out-of-bounds Read NULL Pointer Dereference
|
CVE-2026-32738
|
2026-05-20 23:17 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
464
|
6.5 |
MEDIUM
Network
|
struktur
|
libheif
|
libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and below, a crafted 800-byte HEIF sequence file causes an infinite loop in Box_stts::get_sample_duration(), consuming 1…
New
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2026-32739
|
2026-05-20 23:17 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
465
|
6.1 |
MEDIUM
Network
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core allows Cross-Site Scripting (XSS).
This issue affects Drupal core: from 11.3.…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-6367
|
2026-05-20 23:17 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
466
|
6.1 |
MEDIUM
Network
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Drupal core allows Cross-Site Scripting (XSS).
This issue affects Drupal core: from 8.0.0…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-6365
|
2026-05-20 23:17 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
467
|
6.1 |
MEDIUM
Network
|
-
|
-
|
Template::Plugin::HTML versions through 3.102 for Perl allows HTML and JavaScript to be injected.
The html_filter function did not escape single quotes. HTML attributes inside of single quotes could…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-5090
|
2026-05-20 23:17 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
468
|
6.8 |
MEDIUM
Network
|
-
|
-
|
Trilium Notes is an open-source, cross-platform hierarchical note taking application for building large personal knowledge bases. Versions 0.102.1 and prior are vulnerable to Local File Inclusion, al…
New
|
CWE-22 CWE-73
Path Traversal External Control of File Name or Path
|
CVE-2026-35593
|
2026-05-20 23:16 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
469
|
6.8 |
MEDIUM
Network
|
-
|
-
|
EspoCRM is an open source customer relationship management application. Versions 9.3.3 and below allow authenticated users to upload SVG attachments through normal attachment-capable fields and later…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-33741
|
2026-05-20 23:16 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
470
|
6.5 |
MEDIUM
Network
|
-
|
-
|
libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and prior, when decoding a HEIF grid image with strict_decoding=false (the default), a corrupted tile silently fails to …
New
|
CWE-200 CWE-908
Information Exposure Use of Uninitialized Resource
|
CVE-2026-32814
|
2026-05-20 23:16 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|