|
891
|
5.9 |
MEDIUM
Network
|
-
|
-
|
OpenTelemetry.Resources.Azure is the .NET resource detector for Azure environments. In versions 1.15.0-beta.1 and earlier, the AzureVmMetaDataRequestor class makes HTTP requests to the Azure VM insta…
New
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2026-41483
|
2026-05-8 00:04 |
2026-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
892
|
5.3 |
MEDIUM
Adjacent
|
-
|
-
|
OpenTelemetry.Exporter.OneCollector is a .NET exporter that sends telemetry to a OneCollector back-end over HTTP. In versions 1.15.0 and earlier, when a request to the configured back-end or collecto…
New
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2026-41484
|
2026-05-8 00:04 |
2026-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
893
|
- |
|
-
|
-
|
xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) `DOMParser` and `XMLSerializer` module. In @xmldom/xmldom prior to versions 0.9.10 and 0.8.13 and xmldom version 0.6.0 and prior,…
New
|
CWE-91
Blind XPath Injection
|
CVE-2026-41674
|
2026-05-8 00:02 |
2026-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
894
|
9.8 |
CRITICAL
Network
|
-
|
-
|
vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.0, VM2 suffers from a sandbox breakout vulnerability. This allows attackers to write code which can escape from the VM2 sandbox and…
Update
|
CWE-94 CWE-693
Code Injection Protection Mechanism Failure
|
CVE-2026-24118
|
2026-05-8 00:00 |
2026-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
895
|
9.8 |
CRITICAL
Network
|
-
|
-
|
vm2 is an open source vm/sandbox for Node.js. Prior to version 3.10.5, the fix for CVE-2023-37466 is insufficient and can be circumvented allowing attackers to write code which can escape from the VM…
Update
|
CWE-94 CWE-693
Code Injection Protection Mechanism Failure
|
CVE-2026-24120
|
2026-05-8 00:00 |
2026-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
896
|
9.8 |
CRITICAL
Network
|
-
|
-
|
vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.0, VM2 suffers from a sandbox breakout vulnerability through the inspect function. This allows attackers to write code which can es…
Update
|
CWE-94 CWE-693
Code Injection Protection Mechanism Failure
|
CVE-2026-24781
|
2026-05-8 00:00 |
2026-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
897
|
9.8 |
CRITICAL
Network
|
-
|
-
|
vm2 is an open source vm/sandbox for Node.js. In version 3.10.4, vm2 is vulnerable to full sandbox escape with arbitrary code execution. Attacker code inside VM.run() obtains host process object and …
Update
|
CWE-693
Protection Mechanism Failure
|
CVE-2026-26956
|
2026-05-8 00:00 |
2026-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
898
|
8.8 |
HIGH
Network
|
hcltech
|
bigfix_service_management
|
HCL BigFix Service Management (SM) is affected by use of a vulnerable WSGI Server was identified. Deploying an outdated or insecure WSGI server may expose the application to known security weaknesses…
New
|
CWE-200
Information Exposure
|
CVE-2025-52613
|
2026-05-7 23:59 |
2026-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
899
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Incus is a system container and virtual machine manager. Prior to version 7.0.0, a missing error handling could lead an authenticated Incus user to cause a daemon crash through the import of a trunca…
New
|
CWE-476
NULL Pointer Dereference
|
CVE-2026-41647
|
2026-05-7 23:59 |
2026-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
900
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Incus is a system container and virtual machine manager. Prior to version 7.0.0, backup.GetInfo() trusts the inline backup/index.yaml config when present and only falls back to parsing the legacy bac…
New
|
CWE-476
NULL Pointer Dereference
|
CVE-2026-41684
|
2026-05-7 23:59 |
2026-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|