|
171
|
7.3 |
HIGH
Local
|
axis
|
axis_os
|
An ACAP configuration file lacked sufficient input validation, which could allow command injection and potentially lead to privilege escalation. This vulnerability can only be exploited if the Axis d…
Update
|
CWE-1287
Improper Validation of Specified Type of Input
|
CVE-2026-0802
|
2026-05-20 01:05 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
172
|
7.3 |
HIGH
Local
|
axis
|
axis_os
|
ACAP applications can gain elevated privileges due to improper input validation during the installation process, potentially leading to privilege escalation. This vulnerability can only be exploited …
Update
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2026-0541
|
2026-05-20 00:40 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
173
|
6.1 |
MEDIUM
Network
|
-
|
-
|
Versions of the package jsondiffpatch before 0.7.6 are vulnerable to Cross-site Scripting (XSS) via the annotated formatter due to improper sanitization of JSON values and property names. If an appli…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-8656
|
2026-05-20 00:38 |
2026-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
174
|
8.2 |
HIGH
Network
|
-
|
-
|
Versions of the package jsondiffpatch before 0.7.6 are vulnerable to Prototype Pollution via the jsondiffpatch.patch() and jsondiffpatch/formatters/jsonpatch.patch() APIs. An attacker can perform pro…
New
|
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
|
CVE-2026-8657
|
2026-05-20 00:38 |
2026-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
175
|
7.5 |
HIGH
Network
|
-
|
-
|
This affects versions of the package exifreader before 4.39.0. A crafted image containing an ICC mluc tag can set an attacker-controlled record count together with a zero record size. During parsing,…
New
|
CWE-1284
Improper Validation of Specified Quantity in Input
|
CVE-2026-8813
|
2026-05-20 00:38 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
176
|
5.3 |
MEDIUM
Network
|
-
|
-
|
Versions of the package exifreader before 4.39.0 are vulnerable to Improper Handling of Highly Compressed Data (Data Amplification) due to decompressing PNG zTXt metadata without enforcing a built-in…
New
|
CWE-409
Improper Handling of Highly Compressed Data (Data Amplification)
|
CVE-2026-8814
|
2026-05-20 00:38 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
177
|
9.8 |
CRITICAL
Network
|
microsoft
|
edge_chromium
|
Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability
New
|
CWE-20 CWE-94 CWE-119
Improper Input Validation Code Injection Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2026-45495
|
2026-05-20 00:35 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
178
|
7.3 |
HIGH
Network
|
apache
|
ofbiz
|
Server-Side Request Forgery (SSRF) vulnerability in Apache OFBiz via Content component operations.
This issue affects Apache OFBiz: before 24.09.06.
Users are recommended to upgrade to version 24.0…
New
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-29226
|
2026-05-20 00:29 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
179
|
6.5 |
MEDIUM
Network
|
apache
|
ofbiz
|
Improper Input Validation vulnerability in Apache OFBiz.
This issue affects Apache OFBiz: before 24.09.06.
Users are recommended to upgrade to version 24.09.06, which fixes the issue.
New
|
CWE-20 NVD-CWE-noinfo
Improper Input Validation
|
CVE-2026-31378
|
2026-05-20 00:29 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
180
|
6.1 |
MEDIUM
Network
|
apache
|
ofbiz
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Improper Control of Generation of…
New
|
CWE-22 CWE-79 CWE-94
Path Traversal Cross-site Scripting Code Injection
|
CVE-2026-31379
|
2026-05-20 00:27 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|