|
1151
|
7.5 |
HIGH
Network
|
strapi
|
strapi
|
Strapi is an open source headless content management system. Strapi versions starting in 4.0.0 and prior to 5.37.0 did not sufficiently sanitize query parameters when filtering content via relational…
|
CWE-22 CWE-200 CWE-943
Path Traversal Information Exposure Improper Neutralization of Special Elements in Data Query Logic
|
CVE-2026-27886
|
2026-05-16 12:16 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1152
|
8.8 |
HIGH
Adjacent
|
zyxel
|
wre6505_firmware
|
** UNSUPPORTED WHEN ASSIGNED ** A command injection vulnerability in the CGI program of Zyxel WRE6505 v2 firmware version V1.00(ABDV.3)C0 could allow an adjacent attacker on the LAN to execute operat…
|
CWE-78
OS Command
|
CVE-2026-7256
|
2026-05-16 12:08 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1153
|
4.4 |
MEDIUM
Local
|
zyxel
|
wre6505_firmware
|
** UNSUPPORTED WHEN ASSIGNED ** An insecure storage of sensitive information vulnerability in the configuration file of Zyxel WRE6505 v2 firmware version V1.00(ABDV.3)C0 could allow a local attacker …
|
CWE-922
Insecure Storage of Sensitive Information
|
CVE-2026-7257
|
2026-05-16 12:08 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1154
|
7.5 |
HIGH
Network
|
zyxel
|
nwa1100-n_firmware
|
** UNSUPPORTED WHEN ASSIGNED ** A buffer overflow vulnerability in the formWep(), formWlAc(), formPasswordSetup(), formUpgradeCert(), and formDelcert() functions of the “webs” binary in Zyxel NWA1100…
|
CWE-120
Classic Buffer Overflow
|
CVE-2026-7287
|
2026-05-16 12:08 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1155
|
6.5 |
MEDIUM
Adjacent
|
pengutronix
|
barebox
|
barebox prior to version 2026.04.0 contains an out-of-bounds read vulnerability in DHCP option parsing within the dhcp_message_type() function that fails to verify the options pointer remains within …
|
CWE-125
Out-of-bounds Read
|
CVE-2026-34960
|
2026-05-16 12:07 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1156
|
9.8 |
CRITICAL
Network
|
openclaw
|
openclaw
|
A vulnerability was detected in OpenClaw up to 2026.1.24. The impacted element is the function handleBlueBubblesWebhookRequest of the file extensions/bluebubbles/src/monitor.ts of the component blueb…
|
CWE-287
Improper Authentication
|
CVE-2026-8305
|
2026-05-16 12:06 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1157
|
9.8 |
CRITICAL
Network
|
libexpat_project
|
libexpat
|
`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\r\n\r\nFully mitigating this…
|
CWE-331
Insufficient Entropy
|
CVE-2026-7210
|
2026-05-16 12:05 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1158
|
8.1 |
HIGH
Network
|
bitwarden
|
server
|
Bitwarden Server prior to v2026.4.1 does not require master-password re-authentication when retrieving or rotating an organization's SCIM API key, allowing an authenticated user with SCIM management …
|
CWE-303
Incorrect Implementation of Authentication Algorithm
|
CVE-2026-43640
|
2026-05-16 12:04 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1159
|
9.1 |
CRITICAL
Network
|
bitwarden
|
server
|
Bitwarden Server prior to v2026.4.0 contains a missing authorization vulnerability that allows a provider service user to add an arbitrary organization to their provider via `POST /providers/{provide…
|
CWE-862
Missing Authorization
|
CVE-2026-43639
|
2026-05-16 12:04 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1160
|
5.4 |
MEDIUM
Network
|
bitwarden
|
server
|
Bitwarden Server prior to v2026.4.1 contains a missing authorization vulnerability that allows any authenticated user to write ciphers into an arbitrary organization via `POST /ciphers/import-organiz…
|
CWE-862
Missing Authorization
|
CVE-2026-43638
|
2026-05-16 11:55 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|