|
801
|
- |
|
-
|
-
|
SailingLab AppLock (aka com.alpha.applock) 4.3.8 for Android allows a local attacker with physical access to bypass the PIN lock. The lock is implemented as an overlay rather than by using Android's …
New
|
-
|
CVE-2025-68708
|
2026-05-27 06:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
802
|
5.4 |
MEDIUM
Network
|
snipeitapp
|
snipe-it
|
Snipe-IT is an IT asset/license management system. Prior to 8.4.1, users with component view access could be impacted by an unescaped notes column, resulting in cross-site scripting (XSS). This vulne…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-44831
|
2026-05-27 05:39 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
803
|
8.8 |
HIGH
Network
|
snipeitapp
|
snipe-it
|
Snipe-IT is an IT asset/license management system. Prior to 8.4.1, aAn authenticated user with only users.edit permission can escalate their own privileges to admin by sending a PATCH request to /api…
New
|
CWE-281 CWE-863
Improper Preservation of Permissions Incorrect Authorization
|
CVE-2026-44832
|
2026-05-27 05:38 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
804
|
7.1 |
HIGH
Network
|
snipeitapp
|
snipe-it
|
Snipe-IT is an IT asset/license management system. Prior to 8.4.1, an open redirect vulnerability in Snipe-IT allows attackers to redirect users to malicious sites via unvalidated HTTP Referer header…
New
|
CWE-601
Open Redirect
|
CVE-2026-44833
|
2026-05-27 05:38 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
805
|
4.8 |
MEDIUM
Network
|
powerdns
|
authoritative
|
Incorrect Behaviour of Views with TCP PROXY Requests
Update
|
CWE-284
Improper Access Control
|
CVE-2026-41999
|
2026-05-27 05:32 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
806
|
6.1 |
MEDIUM
Network
|
-
|
-
|
Devise is an authentication solution for Rails based on Warden. In versions 5.0.3 and below, when the Timeoutable module is enabled in Devise, the FailureApp#redirect_url method returns request.refer…
New
|
CWE-601
Open Redirect
|
CVE-2026-40295
|
2026-05-27 05:24 |
2026-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
807
|
8.1 |
HIGH
Local
|
-
|
-
|
Insertion of Sensitive Information into Log File (CWE-532) in some Command Centre Service installers could lead to Service Account credentials exposure.
Mitigating Factor: Only sites that install Co…
New
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2026-25193
|
2026-05-27 05:24 |
2026-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
808
|
6.6 |
MEDIUM
Network
|
-
|
-
|
SQL Injection affecting the Access Manager role.
New
|
CWE-89
SQL Injection
|
CVE-2026-27768
|
2026-05-27 05:24 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
809
|
7.5 |
HIGH
Network
|
-
|
-
|
In GNU SASL before 2.2.3, DIGEST-MD5 has a NULL pointer dereference affecting both clients and servers, via a known token with no accompanying = character. This occurs in lib/digest-md5/getsubopt.c.
New
|
CWE-476
NULL Pointer Dereference
|
CVE-2026-48829
|
2026-05-27 05:19 |
2026-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
810
|
- |
|
-
|
-
|
Wine ships a .desktop file that registers itself as a MIME handler for EXE files and several other Windows executable file types. In some configurations, handling of an EXE file causes that file to b…
New
|
CWE-669
Incorrect Resource Transfer Between Spheres
|
CVE-2026-48831
|
2026-05-27 05:19 |
2026-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|