|
1871
|
4.4 |
MEDIUM
Local
|
vmware
|
spring_cloud_config
|
When enabling trace logging in Spring Cloud Config Server sensitive information was placed in plain text in the logs.
Spring Cloud Config 3.1.x: affected from 3.1.0 through 3.1.13 (inclusive); upgrad…
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2026-41004
|
2026-05-13 01:52 |
2026-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1872
|
8.8 |
HIGH
Network
|
nocobase
|
nocobase
|
NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to version 2.0.39, the queryParentSQL() function in the core database package co…
|
CWE-89
SQL Injection
|
CVE-2026-41640
|
2026-05-13 01:51 |
2026-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1873
|
5.3 |
MEDIUM
Network
|
-
|
-
|
Plack::Middleware::Statsd versions before 0.9.0 for Perl may leak user IP addresses.
If the communication channel to the statsd daemon is not secured (for example, by sending UDP packets to a host o…
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2026-45179
|
2026-05-13 01:48 |
2026-05-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1874
|
7.5 |
HIGH
Network
|
-
|
-
|
Catalyst::Plugin::Statsd versions through 0.10.0 for Perl may leak session ids.
If the communication channel to the statsd daemon is not secured (for example, by sending UDP packets to a host on ano…
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2026-45180
|
2026-05-13 01:48 |
2026-05-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1875
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Net::CIDR::Lite versions before 0.24 for Perl does not properly validate IP address and CIDR mask inputs, which may allow IP ACL bypass.
Inputs containing a trailing newline or non-ASCII digit chara…
|
CWE-1289
Improper Validation of Unsafe Equivalence in Input
|
CVE-2026-45190
|
2026-05-13 01:48 |
2026-05-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1876
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Net::CIDR::Lite versions before 0.24 for Perl does not properly consider extraneous zero characters in CIDR mask values, which may allow IP ACL bypass.
Mask forms like "/00" and "/01" pass validatio…
|
CWE-1289
Improper Validation of Unsafe Equivalence in Input
|
CVE-2026-45191
|
2026-05-13 01:48 |
2026-05-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1877
|
7.5 |
HIGH
Network
|
-
|
-
|
XML::LibXML versions through 2.0210 for Perl read out-of-bounds heap memory when parsing XML node names containing truncated UTF-8 byte sequences.
A node name ending in the middle of a multi byte UT…
|
CWE-125
Out-of-bounds Read
|
CVE-2026-8177
|
2026-05-13 01:48 |
2026-05-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1878
|
6.5 |
MEDIUM
Network
|
-
|
-
|
WebDyne::Session versions through 2.075 for Perl generates the session id insecurely.
The session handler generates the session id from an MD5 hash seeded with a call to the built-in rand() function…
|
CWE-338 CWE-340
Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) Generation of Predictable Numbers or Identifiers
|
CVE-2026-5084
|
2026-05-13 01:48 |
2026-05-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1879
|
6.5 |
MEDIUM
Network
|
-
|
-
|
HTTP::Tiny versions before 0.093 for Perl do not validate CRLF in HTTP request lines or control field header values.
The unvalidated inputs are the method and URI in the request line, the URL host t…
|
CWE-113
HTTP Response Splitting
|
CVE-2026-7010
|
2026-05-13 01:48 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1880
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Akilli Commerce Software Technologies Ltd. Co. E-Commerce Website allows SQL Injection.
This iss…
|
CWE-89
SQL Injection
|
CVE-2025-6577
|
2026-05-13 01:47 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|