|
121
|
- |
|
-
|
-
|
JS8Call through 2.3.1 and JS8Call-improved before 3.0 have a stack-based buffer overflow via a radio transmission of @APRSIS GRID followed by a long Maidenhead locator. This occurs in grid2deg in APR…
New
|
CWE-121
Stack-based Buffer Overflow
|
CVE-2026-42996
|
2026-05-2 00:37 |
2026-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
122
|
5.4 |
MEDIUM
Network
|
-
|
-
|
@diplodoc/search-extension 1.0.0 through 3.x before 3.0.3 allows stored XSS via the title in a .md file.
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-40201
|
2026-05-2 00:37 |
2026-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
123
|
- |
|
-
|
-
|
An issue in open5gs v.2.7.3 allows a remote attacker to cause a denial of service via a crafted PDU Session Modification Request
New
|
-
|
CVE-2025-46115
|
2026-05-2 00:34 |
2026-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
124
|
4.8 |
MEDIUM
Network
|
-
|
-
|
In Exim before 4.99.2, when the SPA authentication driver is used with an adversarial SPA resource, there can be an out-of-bounds write that crashes the connection instance, or erroneous data process…
New
|
CWE-909
Missing Initialization of Resource
|
CVE-2026-40687
|
2026-05-2 00:33 |
2026-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
125
|
- |
|
-
|
-
|
Bitwarden CLI 2026.4.0 from 2026-04-22T21:57Z to 2026-04-22T23:30Z, when obtained from npm, had embedded malicious code. This is related to a Checkmarx supply chain incident.
New
|
CWE-78
OS Command
|
CVE-2026-42994
|
2026-05-2 00:33 |
2026-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
126
|
7.9 |
HIGH
Network
|
-
|
-
|
An issue was discovered in OpenStack Keystone 13 through 29. POST /v3/credentials did not validate that the caller-supplied project_id for an EC2-type credential matched the project of the authentica…
New
|
CWE-863
Incorrect Authorization
|
CVE-2026-43001
|
2026-05-2 00:33 |
2026-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
127
|
8.0 |
HIGH
Adjacent
|
-
|
-
|
An issue was discovered in OpenStack ironic-python-agent 1.0.0 through 11.5.0. Ironic Python Agent (IPA) sometimes executes grub-install from within a chroot of the deployed partition image, leading …
New
|
CWE-829
Inclusion of Functionality from Untrusted Control Sphere
|
CVE-2026-43003
|
2026-05-2 00:33 |
2026-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
128
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. In version 4.9.0, the endpoint POST /user/invited does not validate any …
New
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2026-35514
|
2026-05-2 00:31 |
2026-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
129
|
7.5 |
HIGH
Network
|
-
|
-
|
Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. In version 4.9.0, Chartbrew exposes public chart retrieval and export ro…
New
|
CWE-284
Improper Access Control
|
CVE-2026-40595
|
2026-05-2 00:31 |
2026-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
130
|
8.1 |
HIGH
Network
|
-
|
-
|
Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. In version 4.9.0, Chartbrew allows authenticated users with access to on…
New
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-40600
|
2026-05-2 00:31 |
2026-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|