|
791
|
5.4 |
MEDIUM
Network
|
-
|
-
|
Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in circle.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized valu…
|
CWE-79
Cross-site Scripting
|
CVE-2026-48215
|
2026-05-22 03:16 |
2026-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
792
|
5.4 |
MEDIUM
Network
|
-
|
-
|
Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in add_nm.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized valu…
|
CWE-79
Cross-site Scripting
|
CVE-2026-48214
|
2026-05-22 03:16 |
2026-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
793
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Missing Authorization vulnerability in VillaTheme HAPPY allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects HAPPY: from n/a through 1.0.10.
|
CWE-862
Missing Authorization
|
CVE-2026-39593
|
2026-05-22 03:16 |
2026-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
794
|
7.8 |
HIGH
Local
|
-
|
-
|
MediaArea MediaInfoLib Channel Splitting heap-based buffer overflow vulnerability
|
CWE-122
Heap-based Buffer Overflow
|
CVE-2026-22554
|
2026-05-22 03:16 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
795
|
9.1 |
CRITICAL
Network
|
scadabr
|
scadabr
|
In ScadaBR version 1.2.0, a Missing Authentication for Critical Function vulnerability could allow an unauthenticated attacker to send a HTTP GET requests to the SCADA system and inject arbitrary sen…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2026-8602
|
2026-05-22 02:19 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
796
|
9.8 |
CRITICAL
Network
|
scadabr
|
scadabr
|
In ScadaBR version 1.2.0, an OS Command Injection vulnerability could allow an attacker to execute commands as root on the SCADA system.
|
CWE-78
OS Command
|
CVE-2026-8603
|
2026-05-22 02:17 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
797
|
8.8 |
HIGH
Network
|
scadabr
|
scadabr
|
In ScadaBR version 1.2.0, a CSRF vulnerability could allow an attacker to trigger any authenticated action through a victim's session by luring any logged-in user to a malicious webpage.
|
CWE-352
Origin Validation Error
|
CVE-2026-8604
|
2026-05-22 02:16 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
798
|
5.4 |
MEDIUM
Network
|
-
|
-
|
Open ISES Tickets before 3.44.2 contains a reflected cross-site scripting vulnerability in add.php that allows authenticated attackers to inject arbitrary JavaScript by passing an unsanitized value t…
|
CWE-79
Cross-site Scripting
|
CVE-2026-48213
|
2026-05-22 02:16 |
2026-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
799
|
9.8 |
CRITICAL
Network
|
scadabr
|
scadabr
|
In ScadaBR version 1.2.0, a Use of Hard-Coded Credentials vulnerability could allow an attacker to access the SCADA system as admin.
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2026-8605
|
2026-05-22 02:16 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
800
|
4.2 |
MEDIUM
Network
|
google
|
chrome
|
Incorrect security UI in Downloads in Google Chrome on Android and Mac prior to 148.0.7778.168 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: M…
|
CWE-451
User Interface (UI) Misrepresentation of Critical Information
|
CVE-2026-8564
|
2026-05-22 02:09 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|