|
241
|
7.5 |
HIGH
Network
|
ws_project
|
ws
|
ws is an open source WebSocket client and server for Node.js. Prior to 8.20.1, the websocket.close() implementation is vulnerable to uninitialized memory disclosure when a TypedArray is passed as the…
New
|
CWE-908
Use of Uninitialized Resource
|
CVE-2026-45736
|
2026-05-19 23:39 |
2026-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
242
|
7.5 |
HIGH
Network
|
-
|
-
|
The Fortis for WooCommerce WordPress plugin before 1.3.1 may leak sensitive API keys to unauthenticated attackers, allowing them to query Fortis' API and retrieve sensitive customer information, like…
New
|
-
|
CVE-2025-15609
|
2026-05-19 23:38 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
243
|
9.8 |
CRITICAL
Network
|
-
|
-
|
The Piotnet Addons for Elementor Pro plugin for WordPress is vulnerable to arbitrary file upload due to missing file type validation in the 'pafe_ajax_form_builder' function in all versions up to, an…
New
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2026-4885
|
2026-05-19 23:38 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
244
|
9.8 |
CRITICAL
Network
|
-
|
-
|
The Piotnet Forms plugin for WordPress is vulnerable to arbitrary file upload due to missing file type validation in the 'piotnetforms_ajax_form_builder' function in all versions up to, and including…
New
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2026-4883
|
2026-05-19 23:38 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245
|
7.5 |
HIGH
Network
|
-
|
-
|
The Contest Gallery plugin for WordPress is vulnerable to SQL Injection via the 'form_input' parameter in versions up to, and including, 28.1.6. This is due to insufficient escaping on the user suppl…
New
|
CWE-89
SQL Injection
|
CVE-2026-8912
|
2026-05-19 23:38 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246
|
4.6 |
MEDIUM
Network
|
-
|
-
|
An Angular template injection vulnerability was discovered in the Reports functionality due to improper validation of an input parameter. An authenticated user with report privileges can define a mal…
New
|
CWE-1336
Improper Neutralization of Special Elements Used in a Template Engine
|
CVE-2025-40900
|
2026-05-19 23:37 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247
|
6.3 |
MEDIUM
Network
|
tencent
|
weknora
|
A vulnerability has been found in Tencent WeKnora up to 0.3.6. Affected by this issue is the function getKnowledgeBaseForInitialization of the file internal/handler/initialization.go of the component…
New
|
CWE-285 CWE-639
Improper Authorization Authorization Bypass Through User-Controlled Key
|
CVE-2026-8786
|
2026-05-19 23:30 |
2026-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248
|
5.3 |
MEDIUM
Network
|
google
|
chrome
|
Object lifecycle issue in Dawn in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium se…
New
|
CWE-664
Improper Control of a Resource Through its Lifetime
|
CVE-2026-8582
|
2026-05-19 23:30 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249
|
7.5 |
HIGH
Network
|
vercel
|
ai
|
A vulnerability has been found in vercel ai up to 3.0.97. Impacted is the function run of the file .github/workflows/prettier-on-automerge.yml of the component PR Branch Name Interpolation. The manip…
New
|
CWE-77 CWE-78
Command Injection OS Command
|
CVE-2026-8767
|
2026-05-19 23:29 |
2026-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250
|
4.3 |
MEDIUM
Network
|
google
|
chrome
|
Heap buffer overflow in GPU in Google Chrome on Android prior to 148.0.7778.168 allowed a remote attacker to perform an out of bounds memory write via a crafted HTML page. (Chromium security severity…
New
|
CWE-122
Heap-based Buffer Overflow
|
CVE-2026-8552
|
2026-05-19 23:27 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|