|
101
|
9.1 |
CRITICAL
Network
|
-
|
-
|
Valtimo is an open-source business process automation platform. com.ritense.valtimo:document from 12.0.0 to before 12.32.0, com.ritense.valtimo:case from 13.0.0 to before 13.23.0, and com.ritense.val…
New
|
CWE-94
Code Injection
|
CVE-2026-42555
|
2026-05-15 03:13 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
102
|
8.8 |
HIGH
Network
|
arubanetworks
|
arubaos sd-wan
|
Command injection vulnerabilities exist in the command line interface (CLI) service accessed by the PAPI protocol of AOS-8 and AOS-10 Operating Systems. Successful exploitation of these vulnerabiliti…
New
|
CWE-77
Command Injection
|
CVE-2026-44870
|
2026-05-15 03:13 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
103
|
7.5 |
HIGH
Network
|
-
|
-
|
Twisted is an event-based framework for internet applications, supporting Python 3.6+. Prior to 26.4.0rc2, the twisted.names module is vulnerable to a Denial of Service (DoS) attack via resource exha…
New
|
CWE-400 CWE-407
Uncontrolled Resource Consumption Inefficient Algorithmic Complexity
|
CVE-2026-42304
|
2026-05-15 03:12 |
2026-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
104
|
9.1 |
CRITICAL
Network
|
-
|
-
|
OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.8, an authenticated Remote Code Execution (RCE) vulnerability in the OPNsense core allows a user with user-management privileg…
New
|
CWE-78
OS Command
|
CVE-2026-44194
|
2026-05-15 03:12 |
2026-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
105
|
- |
|
-
|
-
|
Flowsint is an open-source OSINT graph exploration tool designed for cybersecurity investigation, transparency, and verification. Prior to 1.2.3, Flowsint allows a user to create investigations, whic…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-42159
|
2026-05-15 03:12 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
106
|
- |
|
-
|
-
|
MagicMirror² is an open source modular smart mirror platform. Prior to 2.36.0, an unauthenticated Server-Side Request Forgery (SSRF) vulnerability in the /cors endpoint allows any remote attacker to …
New
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-42281
|
2026-05-15 03:12 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
107
|
7.7 |
HIGH
Local
|
-
|
-
|
DevSpace is a client-only developer tool for cloud-native development with Kubernetes. Prior to 6.3.21, DevSpace's UI server WebSocket accepts connections from all origins by default, and therefore s…
New
|
CWE-200 CWE-306
Information Exposure Missing Authentication for Critical Function
|
CVE-2026-42283
|
2026-05-15 03:12 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
108
|
4.3 |
MEDIUM
Network
|
-
|
-
|
DataHub is an open-source metadata platform. Prior to 1.5.0.3, The DataHub frontend (datahub-frontend-react) deserializes attacker-controlled Java objects from the REDIRECT_URL HTTP cookie during the…
New
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-44501
|
2026-05-15 03:12 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
109
|
9.1 |
CRITICAL
Network
|
n8n-mcp
|
n8n-mcp
|
n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. From version 2.18.7 to before version 2.50.2, there is an authenticated server-side …
Update
|
CWE-367 CWE-918
Time-of-check Time-of-use (TOCTOU) Race Condition Server-Side Request Forgery (SSRF)
|
CVE-2026-44694
|
2026-05-15 03:10 |
2026-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
110
|
4.3 |
MEDIUM
Network
|
n8n-mcp
|
n8n-mcp
|
n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior to version 2.47.13, when n8n-mcp runs in HTTP transport mode, authenticated MC…
Update
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2026-42282
|
2026-05-15 03:07 |
2026-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|