|
2451
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Missing Authorization vulnerability in VillaTheme HAPPY allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects HAPPY: from n/a through 1.0.10.
|
CWE-862
Missing Authorization
|
CVE-2026-39593
|
2026-05-22 03:16 |
2026-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2452
|
7.8 |
HIGH
Local
|
-
|
-
|
MediaArea MediaInfoLib Channel Splitting heap-based buffer overflow vulnerability
|
CWE-122
Heap-based Buffer Overflow
|
CVE-2026-22554
|
2026-05-22 03:16 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2453
|
9.1 |
CRITICAL
Network
|
scadabr
|
scadabr
|
In ScadaBR version 1.2.0, a Missing Authentication for Critical Function vulnerability could allow an unauthenticated attacker to send a HTTP GET requests to the SCADA system and inject arbitrary sen…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2026-8602
|
2026-05-22 02:19 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2454
|
9.8 |
CRITICAL
Network
|
scadabr
|
scadabr
|
In ScadaBR version 1.2.0, an OS Command Injection vulnerability could allow an attacker to execute commands as root on the SCADA system.
|
CWE-78
OS Command
|
CVE-2026-8603
|
2026-05-22 02:17 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2455
|
8.8 |
HIGH
Network
|
scadabr
|
scadabr
|
In ScadaBR version 1.2.0, a CSRF vulnerability could allow an attacker to trigger any authenticated action through a victim's session by luring any logged-in user to a malicious webpage.
|
CWE-352
Origin Validation Error
|
CVE-2026-8604
|
2026-05-22 02:16 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2456
|
5.4 |
MEDIUM
Network
|
-
|
-
|
Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in add.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized value t…
|
CWE-79
Cross-site Scripting
|
CVE-2026-48213
|
2026-05-22 02:16 |
2026-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2457
|
9.8 |
CRITICAL
Network
|
scadabr
|
scadabr
|
In ScadaBR version 1.2.0, a Use of Hard-Coded Credentials vulnerability could allow an attacker to access the SCADA system as admin.
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2026-8605
|
2026-05-22 02:16 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2458
|
4.2 |
MEDIUM
Network
|
google
|
chrome
|
Incorrect security UI in Downloads in Google Chrome on Android and Mac prior to 148.0.7778.168 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: M…
|
CWE-451
User Interface (UI) Misrepresentation of Critical Information
|
CVE-2026-8564
|
2026-05-22 02:09 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2459
|
4.7 |
MEDIUM
Network
|
google
|
chrome
|
Inappropriate implementation in Downloads in Google Chrome on Mac prior to 148.0.7778.168 allowed an attacker who convinced a user to install a malicious extension to perform UI spoofing via a crafte…
|
CWE-451
User Interface (UI) Misrepresentation of Critical Information
|
CVE-2026-8565
|
2026-05-22 02:09 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2460
|
8.3 |
HIGH
Network
|
google
|
chrome
|
Out of bounds write in Codecs in Google Chrome on Mac prior to 148.0.7778.168 allowed a remote attacker to potentially perform a sandbox escape via a crafted video file. (Chromium security severity: …
|
CWE-787
Out-of-bounds Write
|
CVE-2026-8569
|
2026-05-22 02:09 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|