|
441
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Copilot said: i18nextify is a JavaScript library that adds
i18nextify is a JavaScript library that adds website internationalization via a script tag, without source code changes. Versions prior to 3…
New
|
CWE-22 CWE-74
Path Traversal Injection
|
CVE-2026-41691
|
2026-05-9 01:05 |
2026-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
442
|
4.7 |
MEDIUM
Network
|
-
|
-
|
i18nextify is a JavaScript library that adds website internationalization via a script tag, without source code changes. Versions prior to 4.0.8 substitute {{key}} interpolation tokens inside src and…
New
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-41692
|
2026-05-9 01:05 |
2026-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
443
|
- |
|
-
|
-
|
SOPlanning 1.52.00 is vulnerable to Cross Site Scripting (XSS) via the groupe_id parameter to process/groupe_save.php.
New
|
-
|
CVE-2024-33724
|
2026-05-9 01:04 |
2026-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
444
|
- |
|
-
|
-
|
Beauty Parlour Management System v1.1 was discovered to contain a SQL injection vulnerability via the aptnumber parameter in the /appointment-detail.php endpoint. This vulnerability allows attackers …
New
|
-
|
CVE-2026-37431
|
2026-05-9 01:03 |
2026-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
445
|
- |
|
-
|
-
|
Heimdall is a cloud native Identity Aware Proxy and Access Control Decision service. Prior to version 0.17.14, Heimdall handles URL-encoded slashes (%2F) in a case-sensitive manner, while percent-enc…
New
|
CWE-178 CWE-436
Improper Handling of Case Sensitivity Interpretation Conflict
|
CVE-2026-42272
|
2026-05-9 01:03 |
2026-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
446
|
- |
|
-
|
-
|
Heimdall is a cloud native Identity Aware Proxy and Access Control Decision service. Prior to version 0.17.14, Heimdall performs host matching in a case-sensitive manner, while HTTP hostnames are cas…
New
|
CWE-178 CWE-436
Improper Handling of Case Sensitivity Interpretation Conflict
|
CVE-2026-42273
|
2026-05-9 01:03 |
2026-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
447
|
- |
|
-
|
-
|
Heimdall is a cloud native Identity Aware Proxy and Access Control Decision service. Prior to version 0.17.14, Heimdall performs rule matching on the raw (non-normalized) request path, while downstre…
New
|
CWE-35 CWE-436
Path Traversal: '.../...//' Interpretation Conflict
|
CVE-2026-42274
|
2026-05-9 01:03 |
2026-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
448
|
7.5 |
HIGH
Network
|
coredns.io
|
coredns
|
CoreDNS is a DNS server that chains plugins. In versions prior to 1.14.3, the DNS-over-QUIC (DoQ) server can be driven into unbounded goroutine and memory growth by a remote client that opens many QU…
Update
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2026-32934
|
2026-05-9 01:03 |
2026-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
449
|
7.5 |
HIGH
Network
|
coredns.io
|
coredns
|
CoreDNS is a DNS server that chains plugins. In versions prior to 1.14.3, the DNS-over-HTTPS (DoH) GET path accepts oversized dns= query parameter values and performs URL query parsing, base64 decodi…
Update
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2026-32936
|
2026-05-9 01:02 |
2026-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
450
|
3.3 |
LOW
Network
|
-
|
-
|
Kimai is an open-source time tracking application. Prior to version 2.54.0, the Team API endpoints use #[IsGranted('edit_team')] instead of #[IsGranted('edit', 'team')], causing Symfony TeamVoter to …
New
|
CWE-862
Missing Authorization
|
CVE-2026-41498
|
2026-05-9 01:02 |
2026-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|