|
51
|
9.8 |
CRITICAL
Network
|
hashcat
|
hashcat
|
A heap-based buffer overflow in hex_to_binary in the PKZIP hash parser in hashcat v7.1.2 allows an attacker to cause a denial of service or possibly execute arbitrary code via a crafted PKZIP hash fi…
New
|
CWE-787
Out-of-bounds Write
|
CVE-2026-42484
|
2026-05-2 02:45 |
2026-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
52
|
10.0 |
CRITICAL
Network
|
traefik
|
traefik
|
Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.43, 3.6.14, and 3.7.0-rc.2, there is an authentication bypass vulnerability in Traefik's ForwardAuth middleware when trustFo…
New
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2026-35051
|
2026-05-2 02:45 |
2026-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
53
|
9.8 |
CRITICAL
Network
|
hashcat
|
hashcat
|
A stack-based buffer overflow in mangle_to_hex_lower() and mangle_to_hex_upper() in src/rp_cpu.c in hashcat v7.1.2 allows an attacker to cause a denial of service or possibly execute arbitrary code v…
New
|
CWE-787
Out-of-bounds Write
|
CVE-2026-42482
|
2026-05-2 02:45 |
2026-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
54
|
10.0 |
CRITICAL
Network
|
traefik
|
traefik
|
Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.43, 3.6.14, and 3.7.0-rc.2, there is a high severity authentication bypass vulnerability in Traefik's ForwardAuth and snippe…
New
|
CWE-290 CWE-306
Authentication Bypass by Spoofing Missing Authentication for Critical Function
|
CVE-2026-39858
|
2026-05-2 02:44 |
2026-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
55
|
5.3 |
MEDIUM
Network
|
exim
|
exim
|
In Exim before 4.99.2, when utf8 operators are enabled, there is an out-of-bounds read if large UTF-8 trailing characters are present (malformed UTF-8 header data). Information might be divulged with…
New
|
CWE-125
Out-of-bounds Read
|
CVE-2026-40686
|
2026-05-2 02:44 |
2026-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
56
|
8.2 |
HIGH
Network
|
traefik
|
traefik
|
Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.43, 3.6.14, and 3.7.0-rc.2, there is a high severity authentication bypass vulnerability in Traefik's StripPrefixRegex middl…
New
|
CWE-706
Use of Incorrectly-Resolved Name or Reference
|
CVE-2026-40912
|
2026-05-2 02:42 |
2026-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
57
|
7.1 |
HIGH
Network
|
dell
|
idrac10_firmware
|
Dell iDRAC10, versions 1.20.70.50 and 1.30.05.10, contains an Insufficiently Protected Credentials vulnerability. A race condition vulnerability exists that could allow an authenticated low‑privilege…
New
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2026-35155
|
2026-05-2 02:40 |
2026-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
58
|
6.1 |
MEDIUM
Network
|
wso2
|
identity_server
|
The authentication endpoint accepts user-supplied input without enforcing expected validation constraints, leading to a lack of proper output encoding. This allows for the injection of malicious Java…
New
|
CWE-79
Cross-site Scripting
|
CVE-2025-10503
|
2026-05-2 02:40 |
2026-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
59
|
6.4 |
MEDIUM
Network
|
traefik
|
traefik
|
Traefik is an HTTP reverse proxy and load balancer. Prior to versions 2.11.43, 3.6.14, and 3.7.0-rc.2, there is a potential vulnerability in Traefik's Kubernetes CRD provider cross-namespace isolatio…
New
|
CWE-653 CWE-863
Improper Isolation or Compartmentalization Incorrect Authorization
|
CVE-2026-41174
|
2026-05-2 02:39 |
2026-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
60
|
5.5 |
MEDIUM
Local
|
samsung
|
android
|
Insufficient verification of data authenticity in PackageManagerService prior to SMR Mar-2026 Release 1 allows local attackers to modify the installation restriction of specific application.
New
|
NVD-CWE-noinfo
|
CVE-2026-21023
|
2026-05-2 02:39 |
2026-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|