|
591
|
8.2 |
HIGH
Network
|
-
|
-
|
exiftool-vendored provides cross-platform Node.js access to ExifTool. Prior to 35.19.0, exiftool-vendored starts ExifTool in -stay_open True -@ - mode, where arguments are read from stdin one per lin…
New
|
CWE-88
Argument Injection
|
CVE-2026-43893
|
2026-05-14 03:27 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
592
|
- |
|
-
|
-
|
pam_authnft is a PAM session module binding nftables firewall rules to authenticated sessions via cgroupv2 inodes. Prior to 0.2.0-alpha, a heap buffer over-read in peer_lookup_tcp (src/peer_lookup.c:…
New
|
CWE-125 CWE-191
Out-of-bounds Read Integer Underflow (Wrap or Wraparound)
|
CVE-2026-43916
|
2026-05-14 03:27 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
593
|
9.1 |
CRITICAL
Network
|
-
|
-
|
sealed-env is a cross-stack, zero-trust secret management library for Node.js and Java/Spring Boot. In sealed-env enterprise mode, versions 0.1.0-alpha.1 through 0.1.0-alpha.3 embedded the operator's…
New
|
CWE-200 CWE-522
Information Exposure Insufficiently Protected Credentials
|
CVE-2026-45091
|
2026-05-14 03:27 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
594
|
8.2 |
HIGH
Network
|
-
|
-
|
Open-WebSearch is a multi-engine MCP server, CLI, and local daemon for agent web search and content retrieval. Prior to 2.1.7, isPublicHttpUrl / assertPublicHttpUrl in src/utils/urlSafety.ts do not r…
New
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-42260
|
2026-05-14 03:27 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
595
|
- |
|
-
|
-
|
MinIO is a high-performance object storage system. From RELEASE.2022-07-24T01-54-52Z to before RELEASE.2026-04-14T21-32-45Z, A path traversal vulnerability in MinIO's ReadMultiple internode storage-R…
New
|
CWE-22
Path Traversal
|
CVE-2026-42600
|
2026-05-14 03:26 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
596
|
5.8 |
MEDIUM
Network
|
-
|
-
|
Outline is a service that allows for collaborative documentation. Prior to 1.7.1, the Slack integration callback for GET /auth/slack.post accepts an unsigned, session-independent OAuth state value. A…
New
|
CWE-352
Origin Validation Error
|
CVE-2026-44695
|
2026-05-14 03:26 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
597
|
- |
|
-
|
-
|
Fiber is a web framework for Go. Prior to 2.52.12 and 3.1.0, Cross-Site Scripting vulnerability in Go Fiber allows a remote attacker to inject arbitrary HTML/JavaScript by supplying Accept: text/html…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-42554
|
2026-05-14 03:26 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
598
|
- |
|
-
|
-
|
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 8.6.76 and 9.9.0-alpha.2, a race condition in the MFA SMS one-time password (OTP) logi…
New
|
CWE-362
Race Condition
|
CVE-2026-43930
|
2026-05-14 03:26 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
599
|
8.8 |
HIGH
Network
|
-
|
-
|
YetAnotherForum.NET (YAF.NET) is a C# ASP.NET forum. Prior to 4.0.5, Any admin OnPost… handler executes its side effects before the ResultFilterAttribute rewrites the response to a 302 to /Info/4. Th…
New
|
CWE-89 CWE-841
SQL Injection Improper Enforcement of Behavioral Workflow
|
CVE-2026-43937
|
2026-05-14 03:24 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
600
|
8.1 |
HIGH
Network
|
-
|
-
|
YetAnotherForum.NET (YAF.NET) is a C# ASP.NET forum. Prior to 4.0.5 and 3.2.12, the application's database logger (YAFNET.Core/Logger/DbLogger.cs) captures the incoming request's User-Agent header in…
New
|
CWE-79 CWE-80 CWE-116
Cross-site Scripting Basic XSS Improper Encoding or Escaping of Output
|
CVE-2026-43938
|
2026-05-14 03:24 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|