|
1911
|
8.8 |
HIGH
Network
|
-
|
-
|
A potential vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow a remote authenticated user on the local network to execute arbitrary commands on the device.
|
CWE-78
OS Command
|
CVE-2026-6281
|
2026-05-14 01:27 |
2026-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1912
|
8.1 |
HIGH
Network
|
-
|
-
|
A potential improper file path validation vulnerability was reported in some Lenovo Personal Cloud Storage devices that could allow a remote authenticated user to move or access files belonging to ot…
|
CWE-22
Path Traversal
|
CVE-2026-6282
|
2026-05-14 01:27 |
2026-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1913
|
4.8 |
MEDIUM
Network
|
-
|
-
|
aria2c accepts a server certificate with incorrect Extended Key Usage (EKU). If the attackers compromise a certificate (with the associated private key) issued for a different purpose, they may be ab…
|
CWE-295
Improper Certificate Validation
|
CVE-2026-8367
|
2026-05-14 01:27 |
2026-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1914
|
- |
|
-
|
-
|
Rejected reason: This CVE ID has been rejected or withdrawn.
|
-
|
CVE-2026-8449
|
2026-05-14 01:17 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1915
|
4.3 |
MEDIUM
Network
|
-
|
-
|
Missing authorization in the PAM module in Devolutions Server allows an authenticated user with a PAM license but no additional permissions to obtain OTP secret keys and recovery codes via crafted re…
|
CWE-862
Missing Authorization
|
CVE-2026-8407
|
2026-05-14 01:17 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1916
|
7.2 |
HIGH
Network
|
-
|
-
|
Successful exploitation of the SQL injection vulnerability could allow a remote authenticated attacker to
execute arbitrary commands via a specific interface,
potentially enabling the attacker to acc…
|
CWE-89
SQL Injection
|
CVE-2026-6888
|
2026-05-14 01:17 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1917
|
4.3 |
MEDIUM
Network
|
-
|
-
|
Improper access control in the notification management endpoints in Devolutions Server allows an unauthenticated attacker to modify or delete arbitrary user notification records via missing session v…
|
CWE-862
Missing Authorization
|
CVE-2026-5146
|
2026-05-14 01:17 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1918
|
8.1 |
HIGH
Network
|
-
|
-
|
ChurchCRM is an open-source church management system. Prior to 7.3.2, top-level cross-site GET navigation from an attacker-controlled page to FundRaiserDelete.php, PropertyTypeDelete.php, or NoteDele…
|
CWE-352 CWE-650
Origin Validation Error Trusting HTTP Permission Methods on the Server Side
|
CVE-2026-44548
|
2026-05-14 01:16 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1919
|
9.6 |
CRITICAL
Network
|
-
|
-
|
ChurchCRM is an open-source church management system. From 7.2.0 to 7.2.2, The fix for CVE-2026-4058 is incomplete. The hardening commit was merged and then silently stripped from src/api/routes/publ…
|
CWE-287 CWE-304
Improper Authentication Missing Critical Step in Authentication
|
CVE-2026-44547
|
2026-05-14 01:16 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1920
|
- |
|
-
|
-
|
Flowsint is an open-source OSINT graph exploration tool designed for cybersecurity investigation, transparency, and verification. Prior to 1.2.3, Broken Access Control allows reading of sketch logs f…
|
CWE-284
Improper Access Control
|
CVE-2026-44352
|
2026-05-14 01:16 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|