|
1291
|
7.5 |
HIGH
Network
|
apple
|
ipados iphone_os macos tvos visionos watchos
|
A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26…
New
|
CWE-121
Stack-based Buffer Overflow
|
CVE-2026-28846
|
2026-05-13 22:46 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1292
|
6.1 |
MEDIUM
Network
|
th30d4y
|
w4nn4d13\/ip
|
In th30d4y/IP from version 1.0.1 to before version 2.0.1, a DOM-Based Cross-Site Scripting (XSS) vulnerability was identified in an IP Reputation Checker application. Unsanitized user input was direc…
Update
|
CWE-79 CWE-80
Cross-site Scripting Basic XSS
|
CVE-2026-41575
|
2026-05-13 06:11 |
2026-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1293
|
8.1 |
HIGH
Network
|
inducer
|
relate
|
RELATE is a web-based courseware package. Prior to commit 2f68e16, there is a timing attack vulnerability in course/auth.py — check_sign_in_key(). This issue has been patched via commit 2f68e16.
Update
|
CWE-208 CWE-203
Information Exposure Through Timing Discrepancy Information Exposure Through Discrepancy
|
CVE-2026-41588
|
2026-05-13 06:09 |
2026-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1294
|
7.5 |
HIGH
Network
|
fohrloop
|
dash-uploader
|
An issue in fohrloop dash-uploader v.0.1.0 through v.0.7.0a2 allows a remote attacker to execute arbitrary code via the dash_uploader/httprequesthandler.py, dash_uploader/upload.py in the Upload func…
Update
|
NVD-CWE-noinfo CWE-400 CWE-670
Uncontrolled Resource Consumption Always-Incorrect Control Flow Implementation
|
CVE-2026-38361
|
2026-05-13 05:55 |
2026-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1295
|
7.2 |
HIGH
Network
|
dolibarr
|
dolibarr_erp\/crm
|
Dolibarr is an enterprise resource planning (ERP) and customer relationship management (CRM) software package. Versions 22.0.2 and earlier contains an authenticated remote code execution vulnerabilit…
Update
|
CWE-74
Injection
|
CVE-2025-67486
|
2026-05-13 05:54 |
2026-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1296
|
9.9 |
CRITICAL
Network
|
pfsense
|
pfsense
|
Netgate pfSense CE 2.8.0 allows code execution in the XMLRPC API via pfsense.exec_php. NOTE: the Supplier disputes this because the API call is only available to admins and they are intentionally all…
Update
|
CWE-284 CWE-915
Improper Access Control Improperly Controlled Modification of Dynamically-Determined Object Attributes
|
CVE-2025-69691
|
2026-05-13 05:39 |
2026-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1297
|
7.5 |
HIGH
Network
|
vmware
|
spring_cloud_config
|
When using Google Secrets Manager as a backend for the Spring Cloud Config server a client can craft a request to the config server potentially exposing secrets from unintended GCP projects.
Spring C…
Update
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-40981
|
2026-05-13 05:34 |
2026-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1298
|
6.1 |
MEDIUM
Network
|
naturalintelligence
|
fast-xml-parser
|
fast-xml-parser allows users to process XML from JS object without C/C++ based libraries or callbacks. Prior to version 5.7.0, XMLBuilder does not escape the "-->" sequence in comment content or the …
Update
|
CWE-91
Blind XPath Injection
|
CVE-2026-41650
|
2026-05-13 05:30 |
2026-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1299
|
9.8 |
CRITICAL
Network
|
snipeitapp
|
snipe-it
|
Insecure Permissions vulnerability in grokability snipe-it v.8.4.0 and before and fixed after 2026-03-10 commit 676a9958 allows a remote attacker to execute arbitrary code via the app/Http/Controller…
Update
|
CWE-284
Improper Access Control
|
CVE-2026-37709
|
2026-05-13 05:29 |
2026-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1300
|
6.3 |
MEDIUM
Network
|
router-for-me
|
cliproxyapi
|
A vulnerability has been found in router-for-me CLIProxyAPI 6.9.29. Affected by this issue is some unknown functionality of the file internal/api/handlers/management/api_tools.go of the component API…
Update
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-8081
|
2026-05-13 05:27 |
2026-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|