|
431
|
9.1 |
CRITICAL
Network
|
openwebui
|
open_webui
|
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.0, the LDAP authentication endpoint does not validate that the submitted password is no…
New
|
CWE-287 NVD-CWE-noinfo
Improper Authentication
|
CVE-2026-44551
|
2026-05-19 03:35 |
2026-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
432
|
6.5 |
MEDIUM
Network
|
open5gs
|
open5gs
|
A vulnerability was detected in Open5GS up to 2.7.7. This affects an unknown function in the library /lib/sbi/message.c of the component NRF. Performing a manipulation of the argument service-names/s…
New
|
CWE-404
Improper Resource Shutdown or Release
|
CVE-2026-8729
|
2026-05-19 03:35 |
2026-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
433
|
6.5 |
MEDIUM
Network
|
open5gs
|
open5gs
|
A security vulnerability has been detected in Open5GS up to 2.7.7. The impacted element is the function ogs_sbi_discovery_option_parse_plmn_list in the library /lib/sbi/conv.c of the component NRF. S…
New
|
CWE-404
Improper Resource Shutdown or Release
|
CVE-2026-8728
|
2026-05-19 03:35 |
2026-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
434
|
4.3 |
MEDIUM
Network
|
tp-link
|
tl-wr720n_firmware
|
TP-Link TL-WR720N wireless router contains a cross-site request forgery vulnerability that allows attackers to perform unauthorized administrative actions by crafting malicious web requests. Attacker…
New
|
CWE-352
Origin Validation Error
|
CVE-2018-25321
|
2026-05-19 03:34 |
2026-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
435
|
6.5 |
MEDIUM
Network
|
open5gs
|
open5gs
|
A vulnerability was determined in Open5GS up to 2.7.7. Affected is the function ogs_sbi_subscription_data_add/ogs_sbi_nf_service_add in the library /lib/sbi/context.c of the component NRF. Executing …
New
|
CWE-404
Improper Resource Shutdown or Release
|
CVE-2026-8744
|
2026-05-19 03:34 |
2026-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
436
|
8.8 |
HIGH
Network
|
google
|
chrome
|
Heap buffer overflow in WebML in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Criti…
New
|
CWE-122
Heap-based Buffer Overflow
|
CVE-2026-8509
|
2026-05-19 03:34 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
437
|
6.5 |
MEDIUM
Network
|
open5gs
|
open5gs
|
A vulnerability was identified in Open5GS up to 2.7.7. Affected by this vulnerability is the function ogs_timer_add in the library /src/ausf/nausf-handler.c of the component AUSF. The manipulation le…
New
|
CWE-404
Improper Resource Shutdown or Release
|
CVE-2026-8745
|
2026-05-19 03:34 |
2026-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
438
|
9.6 |
CRITICAL
Network
|
google
|
chrome
|
Use after free in UI in Google Chrome prior to 148.0.7778.168 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
New
|
CWE-416
Use After Free
|
CVE-2026-8511
|
2026-05-19 03:34 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
439
|
8.3 |
HIGH
Network
|
google
|
chrome
|
Use after free in FileSystem in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially perform a sandbox escape via a cr…
New
|
CWE-416
Use After Free
|
CVE-2026-8512
|
2026-05-19 03:33 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
440
|
8.3 |
HIGH
Network
|
google
|
chrome
|
Use after free in Aura in Google Chrome prior to 148.0.7778.168 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Ch…
New
|
CWE-416
Use After Free
|
CVE-2026-8514
|
2026-05-19 03:33 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|