|
161
|
5.5 |
MEDIUM
Local
|
-
|
-
|
UDS protocol dissector infinite loop in Wireshark 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
New
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2026-7375
|
2026-05-1 00:13 |
2026-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
162
|
5.5 |
MEDIUM
Local
|
-
|
-
|
Crash in sharkd 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
New
|
CWE-476
NULL Pointer Dereference
|
CVE-2026-7376
|
2026-05-1 00:13 |
2026-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
163
|
5.5 |
MEDIUM
Local
|
-
|
-
|
Crash in sharkd 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
New
|
CWE-122
Heap-based Buffer Overflow
|
CVE-2026-7378
|
2026-05-1 00:13 |
2026-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
164
|
5.5 |
MEDIUM
Local
|
-
|
-
|
Memory leak in sharkd 4.6.0 to 4.6.4 and 4.4.0 to 4.4.14 allows denial of service
New
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2026-7379
|
2026-05-1 00:13 |
2026-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
165
|
7.3 |
HIGH
Network
|
-
|
-
|
The BOOTP file field is written to the lease file without escaping embedded double-quotes, allowing injection of arbitrary dhclient.conf directives. When the lease file is subsequently re-parsed by …
New
|
CWE-149
Improper Neutralization of Quoting Syntax
|
CVE-2026-42511
|
2026-05-1 00:13 |
2026-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
166
|
7.4 |
HIGH
Network
|
-
|
-
|
In JetBrains IntelliJ IDEA before 2024.3.7.1,
2025.1.7.1,
2025.2.6.2,
2025.3.4.1,
2026.1.1 reading arbitrary local files was possible via built-in web server
New
|
CWE-59
Link Following
|
CVE-2026-41882
|
2026-05-1 00:13 |
2026-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
167
|
6.5 |
MEDIUM
Network
|
-
|
-
|
A WebFlux server application that processes multipart requests creates temp files for parts larger than 10 K. Under some circumstances, temp files may remain not deleted after the request is fully pr…
New
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2026-22740
|
2026-05-1 00:11 |
2026-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
168
|
3.1 |
LOW
Network
|
-
|
-
|
Spring MVC and WebFlux applications are vulnerable to cache poisoning when resolving static resources.
More precisely, an application can be vulnerable when all the following are true:
* the ap…
New
|
CWE-524
Use of Cache Containing Sensitive Information
|
CVE-2026-22741
|
2026-05-1 00:11 |
2026-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
169
|
5.3 |
MEDIUM
Network
|
-
|
-
|
Spring MVC and WebFlux applications are vulnerable to Denial of Service attacks when resolving static resources.
More precisely, an application can be vulnerable when all the following are true:
…
New
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2026-22745
|
2026-05-1 00:11 |
2026-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
170
|
4.3 |
MEDIUM
Network
|
-
|
-
|
A missing permission check in Jenkins Script Security Plugin 1399.ve6a_66547f6e1 and earlier allows attackers with Overall/Read permission to enumerate pending and approved Script Security classpaths.
New
|
CWE-862
Missing Authorization
|
CVE-2026-42519
|
2026-05-1 00:11 |
2026-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|