|
1231
|
8.8 |
HIGH
Network
|
artica
|
pandora_fms
|
Cross-Site Request Forgery vulnerability allows an attacker to perform unauthorized actions via crafted web page. This issue affects Pandora FMS: from 777 through 800
New
|
CWE-352
Origin Validation Error
|
CVE-2026-30807
|
2026-05-13 23:38 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1232
|
6.5 |
MEDIUM
Network
|
apple
|
macos
|
This issue was addressed through improved state management. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5. An app may be able to access private information.
New
|
CWE-200 CWE-284
Information Exposure Improper Access Control
|
CVE-2026-28922
|
2026-05-13 23:37 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1233
|
8.8 |
HIGH
Network
|
artica
|
pandora_fms
|
Server-Side Request Forgery vulnerability allows Privilege Escalation via API Checker extension. This issue affects Pandora FMS: from 777 through 800
New
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-30810
|
2026-05-13 23:37 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1234
|
7.1 |
HIGH
Network
|
apple
|
ipados iphone_os macos
|
The issue was addressed with improved checks. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, macOS Sequoia 15.7.7, macOS Tahoe 26.5. Processing a maliciously crafted file may lead to a denial-o…
New
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2026-28941
|
2026-05-13 23:37 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1235
|
3.3 |
LOW
Local
|
apple
|
ipados iphone_os visionos
|
An issue with app access to camera metadata was addressed with improved logic. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, visionOS 26.5. An app may be able to capt…
New
|
CWE-284
Improper Access Control
|
CVE-2026-28957
|
2026-05-13 23:36 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1236
|
7.5 |
HIGH
Network
|
apple
|
ipados iphone_os macos tvos visionos watchos
|
A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26…
New
|
CWE-120
Classic Buffer Overflow
|
CVE-2026-28959
|
2026-05-13 23:36 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1237
|
4.6 |
MEDIUM
Physics
|
apple
|
ipados iphone_os
|
A privacy issue was addressed by removing the vulnerable code. This issue is fixed in iOS 26.5 and iPadOS 26.5. An attacker with physical access may be able to use Visual Intelligence to access sensi…
New
|
CWE-359
Exposure of Private Personal Information to an Unauthorized Actor
|
CVE-2026-28963
|
2026-05-13 23:35 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1238
|
8.1 |
HIGH
Network
|
artica
|
pandora_fms
|
Session Fixation vulnerability allows Session Hijacking via crafted session ID. This issue affects Pandora FMS: from 777 through 800
New
|
CWE-384
Session Fixation
|
CVE-2026-30808
|
2026-05-13 23:35 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1239
|
7.5 |
HIGH
Network
|
apple
|
macos
|
An information leakage was addressed with additional validation. This issue is fixed in macOS Tahoe 26.5. An app may be able to gain root privileges.
New
|
CWE-200 CWE-269
Information Exposure Improper Privilege Management
|
CVE-2026-28976
|
2026-05-13 23:35 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1240
|
8.8 |
HIGH
Local
|
apple
|
macos
|
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5. A malicious app may be able to break out of its san…
New
|
CWE-284
Improper Access Control
|
CVE-2026-28978
|
2026-05-13 23:34 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|