|
871
|
6.1 |
MEDIUM
Network
|
-
|
-
|
A cross-site scripting (XSS) vulnerability exists in Alinto SOGo, version 5.12.7. A maliciously crafted ICS calendar invitation files allows arbitrary JavaScript execution within the authenticated S…
New
|
-
|
CVE-2026-8496
|
2026-05-15 01:07 |
2026-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
872
|
- |
|
-
|
-
|
Comarch ERP Optima client connects to a database using a high privileged account regardless of an application account to which a user logs in. It is possible for a local attacker who controls the cli…
New
|
CWE-266
Incorrect Privilege Assignment
|
CVE-2025-68420
|
2026-05-15 01:07 |
2026-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
873
|
- |
|
-
|
-
|
Comarch ERP Optima client makes use of a hard-coded password for a database user. These credentials cannot be changed. It is possible for a remote attacker to gain an access to the database with elev…
New
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2025-68421
|
2026-05-15 01:07 |
2026-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
874
|
- |
|
-
|
-
|
WEBCON BPS is vulnerable to Reflected XSS via one of parameters used by "/openinmobileapp" endpoint. An attacker can send a specially crafted URL that, when opened by an authenticated user, results i…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-1630
|
2026-05-15 01:07 |
2026-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
875
|
- |
|
-
|
-
|
An integer overflow vulnerability in the simdjson document-builder API allows incorrect buffer size calculations in "string_builder::escape_and_append()" when processing very large input strings on p…
New
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2026-8295
|
2026-05-15 01:04 |
2026-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
876
|
- |
|
-
|
-
|
Verba is affected by a Stored Cross-Site Scripting (XSS) vulnerability within its login logging mechanism. When an unauthenticated remote attacker attempts to log in using an incorrect username and p…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-21730
|
2026-05-15 01:04 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
877
|
7.8 |
HIGH
Local
|
microsoft
|
windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2012 windows_server_2016 w…
|
Integer overflow or wraparound in Windows Storage Spaces Controller allows an authorized attacker to elevate privileges locally.
Update
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2026-35415
|
2026-05-15 00:57 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
878
|
7.0 |
HIGH
Local
|
microsoft
|
windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2012 windows_server_2016 w…
|
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
Update
|
CWE-416
Use After Free
|
CVE-2026-35416
|
2026-05-15 00:55 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
879
|
7.8 |
HIGH
Local
|
microsoft
|
windows_10_1809 windows_10_21h2 windows_10_22h2 windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2019 windows_server_2022 windows_server_2022_…
|
Access of resource using incompatible type ('type confusion') in Windows Win32K - ICOMP allows an authorized attacker to elevate privileges locally.
Update
|
CWE-843
Type Confusion
|
CVE-2026-35417
|
2026-05-15 00:54 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
880
|
5.5 |
MEDIUM
Local
|
m2team
|
nanazip
|
NanaZip is an open source file archive. From 5.0.1252.0 to before 6.0.1698.0, an uncontrolled recursion vulnerability exists in the UFS/UFS2 filesystem image parser in NanaZip. The function GetAllPat…
New
|
CWE-674
Uncontrolled Recursion
|
CVE-2026-42445
|
2026-05-15 00:54 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|