|
2511
|
6.1 |
MEDIUM
Network
|
-
|
-
|
Mattermost Mobile Apps versions <=2.37 11.4 2.0.37 11.0.4 11.1.3 11.3.2 10.11.11.0 fail to properly validate the SSO authentication callback origin which allows an attacker controlling a malicious Ma…
|
CWE-352
Origin Validation Error
|
CVE-2026-22880
|
2026-05-22 00:26 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2512
|
8.0 |
HIGH
Network
|
-
|
-
|
Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to check integration URL for path traversal which allows an malicious authenticated user to call an…
|
CWE-22
Path Traversal
|
CVE-2026-4858
|
2026-05-22 00:26 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2513
|
8.4 |
HIGH
Network
|
-
|
-
|
Zohocorp ManageEngine ADSelfService Plus version before 6525, DataSecurity Plus before 6264 and RecoveryManager Plus before 6313 are vulnerable to Authenticated Remote code execution in the agent mac…
|
CWE-77
Command Injection
|
CVE-2026-2740
|
2026-05-22 00:26 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2514
|
7.1 |
HIGH
Network
|
-
|
-
|
Exposure of private personal information to an unauthorized actor, Insufficiently Protected Credentials vulnerability in Digital Operations Services Inc. WifiBurada allows Authentication Bypass.
Thi…
|
CWE-359 CWE-522
Exposure of Private Personal Information to an Unauthorized Actor Insufficiently Protected Credentials
|
CVE-2025-13477
|
2026-05-22 00:24 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2515
|
7.5 |
HIGH
Network
|
-
|
-
|
Authorization bypass through User-Controlled key vulnerability in PosCube Hardware Software and Consulting Ltd. QR Menu allows Exploitation of Trusted Identifiers.
This issue affects QR Menu: throug…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2025-13479
|
2026-05-22 00:24 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2516
|
5.7 |
MEDIUM
Network
|
-
|
-
|
Insufficient session expiration vulnerability in Turkiye Electricity Transmission Corporation (TEİAŞ) Mobile Application allows Session Hijacking.
This issue affects Mobile Application: from 1.6.2 b…
|
CWE-613
Insufficient Session Expiration
|
CVE-2026-1815
|
2026-05-22 00:24 |
2026-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2517
|
6.3 |
MEDIUM
Network
|
-
|
-
|
Improper restriction of excessive authentication attempts vulnerability in Turkiye Electricity Transmission Corporation (TEİAŞ) Mobile Application allows Brute Force.
This issue affects Mobile Appli…
|
CWE-307
mproper Restriction of Excessive Authentication Attempts
|
CVE-2026-1816
|
2026-05-22 00:24 |
2026-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2518
|
5.3 |
MEDIUM
Network
|
isc
|
bind
|
An unbounded resend loop vulnerability exists in the BIND 9 resolver state machine during bad-server handling, enabling a remote unauthenticated attacker to cause severe resource exhaustion by sendin…
|
CWE-606
Unchecked Input for Loop Condition
|
CVE-2026-5950
|
2026-05-22 00:24 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2519
|
5.9 |
MEDIUM
Network
|
isc
|
bind
|
Undefined behavior may result due to a race condition leading to a use-after-free violation. If BIND receives an incoming DNS message signed with SIG(0), it begins work to validate that signature. …
|
CWE-362 CWE-416
Race Condition Use After Free
|
CVE-2026-5947
|
2026-05-22 00:24 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2520
|
9.8 |
CRITICAL
Network
|
isc
|
bind
|
A use-after-free vulnerability exists within the DNS-over-HTTPS implementation.
This issue affects BIND 9 versions 9.20.0 through 9.20.22, 9.21.0 through 9.21.21, and 9.20.9-S1 through 9.20.22-S1.
BI…
|
CWE-416
Use After Free
|
CVE-2026-3593
|
2026-05-22 00:24 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|