|
2971
|
8.8 |
HIGH
Network
|
-
|
-
|
Budibase is an open-source low-code platform. Prior to 3.38.1, Budibase exposes a REST API for datasource management. The route PUT /api/datasources/:datasourceId is registered in the authorizedRoute…
|
CWE-862
Missing Authorization
|
CVE-2026-45717
|
2026-05-28 03:16 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2972
|
8.8 |
HIGH
Network
|
-
|
-
|
Budibase is an open-source low-code platform. Prior to 3.38.1, the POST /api/global/users/onboard endpoint is protected by workspaceBuilderOrAdmin middleware, allowing any user with builder permissio…
|
CWE-269
Improper Privilege Management
|
CVE-2026-45716
|
2026-05-28 03:16 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2973
|
7.7 |
HIGH
Network
|
-
|
-
|
Budibase is an open-source low-code platform. Prior to 3.34.8, the processUrlFile function in packages/server/src/automations/steps/ai/extract.ts uses fetch(fileUrl) directly without the IP blacklist…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-45548
|
2026-05-28 03:16 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2974
|
8.2 |
HIGH
Network
|
-
|
-
|
Dalfox is a powerful open-source XSS scanner and utility focused on automation. Prior to 2.13.0, when dalfox is run in REST API server mode, the output, output-all, and debug fields in model.Options …
|
CWE-73 CWE-306 CWE-434
External Control of File Name or Path Missing Authentication for Critical Function Unrestricted Upload of File with Dangerous Type
|
CVE-2026-45089
|
2026-05-28 03:16 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2975
|
7.5 |
HIGH
Network
|
-
|
-
|
Dalfox is a powerful open-source XSS scanner and utility focused on automation. Prior to 2.13.0, when dalfox is run in REST API server mode, the custom-payload-file field in model.Options is JSON-tag…
|
CWE-73 CWE-306 CWE-552
External Control of File Name or Path Missing Authentication for Critical Function Files or Directories Accessible to External Parties
|
CVE-2026-45088
|
2026-05-28 03:16 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2976
|
9.3 |
CRITICAL
Network
|
-
|
-
|
Lumiverse is a full-featured AI chat application. Prior to 0.9.7, the component override system transpiles user-supplied TSX via Sucrase and evaluates it with new Function, shadowing dangerous global…
|
CWE-693
Protection Mechanism Failure
|
CVE-2026-44451
|
2026-05-28 03:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2977
|
4.3 |
MEDIUM
Network
|
-
|
-
|
PbootCMS v.3.2.11 contains a code injection vulnerability in its site configuration functionality
|
CWE-79
Cross-site Scripting
|
CVE-2026-36239
|
2026-05-28 03:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2978
|
5.2 |
MEDIUM
Adjacent
|
-
|
-
|
SailingLab AppLock (aka com.alpha.applock) 4.3.8 for Android allows a local attacker to trigger arbitrary JavaScript execution via BrowserMainActivity, which accepts VIEW intents with javascript: URI…
|
CWE-79
Cross-site Scripting
|
CVE-2025-68709
|
2026-05-28 03:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2979
|
9.8 |
CRITICAL
Network
|
ibm
|
websphere_application_server
|
IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty 8.5, 9.0 IBM WebSphere Application Server and WebSphere Application Server Liberty are vulnerable to remote code executi…
|
CWE-94
Code Injection
|
CVE-2026-8633
|
2026-05-28 03:12 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2980
|
7.8 |
HIGH
Local
|
openvpn
|
connect
|
Privilege escalation via background service of OpenVPN Connect 3.5.1 through 3.8.1 on macOS allows attackers to execute arbitrary commands with elevated privileges via local IPC channel
|
CWE-78 CWE-267 CWE-270 CWE-648
OS Command Privilege Defined With Unsafe Actions Privilege Context Switching Error Incorrect Use of Privileged APIs
|
CVE-2026-9560
|
2026-05-28 03:08 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|