|
681
|
9.1 |
CRITICAL
Network
|
-
|
-
|
sealed-env is a cross-stack, zero-trust secret management library for Node.js and Java/Spring Boot. In sealed-env enterprise mode, versions 0.1.0-alpha.1 through 0.1.0-alpha.3 embedded the operator's…
New
|
CWE-200 CWE-522
Information Exposure Insufficiently Protected Credentials
|
CVE-2026-45091
|
2026-05-12 23:17 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
682
|
6.8 |
MEDIUM
Network
|
-
|
-
|
WeGIA is a web manager for charitable institutions. In versions prior to 3.7.3, a Stored Cross-Site Scripting (XSS) vulnerability allows an authenticated user to inject malicious JavaScript into the …
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-45026
|
2026-05-12 23:17 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
683
|
5.8 |
MEDIUM
Network
|
-
|
-
|
Outline is a service that allows for collaborative documentation. Prior to 1.7.1, the Slack integration callback for GET /auth/slack.post accepts an unsigned, session-independent OAuth state value. A…
New
|
CWE-352
Origin Validation Error
|
CVE-2026-44695
|
2026-05-12 23:17 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
684
|
- |
|
-
|
-
|
Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 8.6.76 and 9.9.0-alpha.2, a race condition in the MFA SMS one-time password (OTP) logi…
New
|
CWE-362
Race Condition
|
CVE-2026-43930
|
2026-05-12 23:17 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
685
|
- |
|
-
|
-
|
pam_authnft is a PAM session module binding nftables firewall rules to authenticated sessions via cgroupv2 inodes. Prior to 0.2.0-alpha, a heap buffer over-read in peer_lookup_tcp (src/peer_lookup.c:…
New
|
CWE-125 CWE-191
Out-of-bounds Read Integer Underflow (Wrap or Wraparound)
|
CVE-2026-43916
|
2026-05-12 23:17 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
686
|
7.3 |
HIGH
Network
|
-
|
-
|
Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.35.4, there is a security vulnerability in Vaultwarden that allows bypassing the login brute-force protection if email 2fa is …
New
|
CWE-307
mproper Restriction of Excessive Authentication Attempts
|
CVE-2026-43914
|
2026-05-12 23:17 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
687
|
8.7 |
HIGH
Network
|
-
|
-
|
Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.35.5, Vaultwarden does not enforce that a groups_users.users_organizations_uuid entry belongs to the same organization as grou…
New
|
CWE-285
Improper Authorization
|
CVE-2026-43912
|
2026-05-12 23:17 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
688
|
0.0 |
NONE
Network
|
-
|
-
|
WeGIA is a web manager for charitable institutions. In versions prior to 3.6.10, when attempting to upload a file with malicious content to funcionario/docdependente_upload.php, the application respo…
New
|
CWE-200
Information Exposure
|
CVE-2026-42873
|
2026-05-12 23:17 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
689
|
10.0 |
CRITICAL
Network
|
-
|
-
|
SOCFortress CoPilot focuses on providing a single pane of glass for all your security operations needs. Prior to 0.1.57, SOCFortress CoPilot ships a hardcoded JWT signing secret as a fallback value i…
New
|
CWE-287 CWE-522 CWE-798
Improper Authentication Insufficiently Protected Credentials Use of Hard-coded Credentials
|
CVE-2026-42869
|
2026-05-12 23:17 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
690
|
8.3 |
HIGH
Network
|
-
|
-
|
pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, the set_config_value() API method (@permission(Perms.SETTINGS)) in src/pyload/core/api/__init__.py gates …
New
|
CWE-441 CWE-863 CWE-918
Confused Deputy Incorrect Authorization Server-Side Request Forgery (SSRF)
|
CVE-2026-42313
|
2026-05-12 23:17 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|