|
221
|
- |
|
-
|
-
|
Cognee thru v0.4.0 contains a critical remote code execution vulnerability in its notebook cell execution API endpoint. The endpoint is designed to execute arbitrary Python code provided by the user,…
New
|
-
|
CVE-2026-31231
|
2026-05-13 03:16 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222
|
- |
|
-
|
-
|
The Adversarial Robustness Toolbox (ART) thru 1.20.1 contains a command-line argument injection vulnerability in its Kubeflow component (robustness_evaluation_fgsm_pytorch.py). The script uses the un…
New
|
-
|
CVE-2026-31230
|
2026-05-13 03:16 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223
|
- |
|
-
|
-
|
The Adversarial Robustness Toolbox (ART) thru 1.20.1 contains an insecure deserialization vulnerability (CWE-502) in its Kubeflow component's model loading functionality. When loading model weights f…
New
|
-
|
CVE-2026-31229
|
2026-05-13 03:16 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224
|
10.0 |
CRITICAL
Network
|
-
|
-
|
Insufficient ownership checks in `clientarea.php` allow an authenticated client area user to submit requests using another user’s `addonId` without any ownership validation leading to unauthorized ac…
New
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-29204
|
2026-05-13 03:16 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
225
|
8.8 |
HIGH
Network
|
-
|
-
|
Insufficient input validation of the `plugin` parameter of the `create_user` plugin allows arbitrary Perl code execution on behalf of the already authenticated account's system user.
New
|
CWE-94
Code Injection
|
CVE-2026-29202
|
2026-05-13 03:16 |
2026-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
226
|
4.3 |
MEDIUM
Network
|
-
|
-
|
Insufficient input validation of the feature file name in `feature::LOADFEATUREFILE` adminbin call can cause arbitrary file read when a relative file path is passed.
New
|
CWE-23
Relative Path Traversal
|
CVE-2026-29201
|
2026-05-13 03:16 |
2026-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
227
|
5.3 |
MEDIUM
Adjacent
|
-
|
-
|
A use after free issue was addressed with improved memory management. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS T…
New
|
CWE-416
Use After Free
|
CVE-2026-28994
|
2026-05-13 03:16 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
228
|
5.5 |
MEDIUM
Local
|
-
|
-
|
This issue was addressed by adding an additional prompt for user consent. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, mac…
New
|
CWE-284
Improper Access Control
|
CVE-2026-28993
|
2026-05-13 03:16 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
229
|
4.7 |
MEDIUM
Local
|
-
|
-
|
A memory corruption vulnerability was addressed with improved locking. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS …
New
|
CWE-362
Race Condition
|
CVE-2026-28992
|
2026-05-13 03:16 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
230
|
7.5 |
HIGH
Network
|
-
|
-
|
An out-of-bounds read was addressed with improved bounds checking. This issue is fixed in iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. An app may be able to cau…
New
|
CWE-125
Out-of-bounds Read
|
CVE-2026-28991
|
2026-05-13 03:16 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|