|
1501
|
7.5 |
HIGH
Network
|
arubanetworks
|
arubaos sd-wan
|
Vulnerabilities exist in a protocol-handling component of AOS-8 and AOS-10 Operating Systems. An unauthenticated attacker could exploit these vulnerabilities by sending specially crafted network mess…
|
CWE-20
Improper Input Validation
|
CVE-2026-23825
|
2026-05-15 21:44 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1502
|
5.4 |
MEDIUM
Network
|
arubanetworks
|
arubaos sd-wan
|
A session management vulnerability in AOS-8 allows previously authenticated users to retain network access after their accounts are administratively disabled. Existing sessions are not invalidated wh…
|
CWE-613
Insufficient Session Expiration
|
CVE-2026-44873
|
2026-05-15 21:44 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1503
|
4.9 |
MEDIUM
Network
|
arubanetworks
|
arubaos
|
A vulnerability exists in the web-based management interface of an AOS-10 Gateway that could allow an authenticated remote attacker to access sensitive files on the underlying operating system. Succe…
|
CWE-284
Improper Access Control
|
CVE-2026-44874
|
2026-05-15 21:44 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1504
|
7.2 |
HIGH
Network
|
arubanetworks
|
arubaos sd-wan
|
Command injection vulnerabilities exist in the web-based management interface of AOS-8 and AOS-10 Operating Systems. Successful exploitation of these vulnerabilities could allow an authenticated remo…
|
CWE-77
Command Injection
|
CVE-2026-44865
|
2026-05-15 21:44 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1505
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Reserved. Details will be published at disclosure.
|
CWE-20
Improper Input Validation
|
CVE-2026-45392
|
2026-05-15 21:17 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1506
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Reserved. Details will be published at disclosure.
|
CWE-20
Improper Input Validation
|
CVE-2026-45391
|
2026-05-15 21:17 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1507
|
9.6 |
CRITICAL
Network
|
-
|
-
|
Due to improper Spring Security configuration, SAP Commerce Cloud allows an unauthenticated user to perform malicious input injection, resulting in arbitrary server-side code execution, leading to hi…
|
CWE-459
Incomplete Cleanup
|
CVE-2026-34263
|
2026-05-15 21:17 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1508
|
- |
|
-
|
-
|
Fleet is open source device management software. Prior to version 4.82.0, a vulnerability in Fleet's Windows MDM enrollment flow allows authentication tokens from any Azure AD tenant to be accepted. …
|
CWE-290
Authentication Bypass by Spoofing
|
CVE-2026-24899
|
2026-05-15 06:24 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1509
|
8.3 |
HIGH
Network
|
-
|
-
|
SiYuan is an open-source personal knowledge management system. From 2.1.12 to before 3.7.0. SiYuan's Bazaar marketplace renders package author metadata from the public bazaar stage feed into HTML wit…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-44586
|
2026-05-15 06:22 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1510
|
4.3 |
MEDIUM
Network
|
-
|
-
|
SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, POST /api/tag/getTag is registered with model.CheckAuth only, omitting both model.CheckAdminRole and model.CheckReadonly…
|
CWE-285 CWE-862
Improper Authorization Missing Authorization
|
CVE-2026-45147
|
2026-05-15 06:22 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|