|
781
|
4.3 |
MEDIUM
Network
|
-
|
-
|
In JetBrains TeamCity before 2025.11.2 exposure of sensitive data via default agent parameters
New
|
CWE-526
Cleartext Storage of Sensitive Information in an Environment Variable
|
CVE-2026-49377
|
2026-05-30 05:11 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
782
|
4.3 |
MEDIUM
Network
|
-
|
-
|
In JetBrains TeamCity before 2026.1 credentials parameters were exposed via parameter autocompletion
New
|
CWE-862
Missing Authorization
|
CVE-2026-49378
|
2026-05-30 05:11 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
783
|
6.5 |
MEDIUM
Network
|
-
|
-
|
In JetBrains TeamCity before 2026.1 credentials could be exposed in thread names
New
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2026-49379
|
2026-05-30 05:11 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
784
|
3.1 |
LOW
Network
|
-
|
-
|
In JetBrains TeamCity before 2026.1 open redirect in the SAML plugin was possible
New
|
CWE-601
Open Redirect
|
CVE-2026-49380
|
2026-05-30 05:11 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
785
|
3.4 |
LOW
Network
|
-
|
-
|
In JetBrains TeamCity before 2026.1 stored XSS on the SAML login page was possible
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-49381
|
2026-05-30 05:11 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
786
|
9.8 |
CRITICAL
Network
|
deltaww
|
diaview
|
There is a mitigation bypass / (incomplete fix) for CVE-2025-62582 (Unauthenticated Remote Database Access)
An unauthenticated remote attacker can access configured databases in a DIAView project.
Update
|
CWE-321
Use of Hard-coded Cryptographic Key
|
CVE-2026-9642
|
2026-05-30 04:53 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
787
|
7.5 |
HIGH
Network
|
microsoft
|
planetary_computer
|
Deserialization of untrusted data in Microsoft Planetary Computer Pro allows an unauthorized attacker to disclose information over a network.
Update
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-41104
|
2026-05-30 04:46 |
2026-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
788
|
5.5 |
MEDIUM
Local
|
pypdf_project
|
pypdf
|
pypdf is a free and open-source pure-python PDF library. Prior to 6.12.1, an attacker who uses this vulnerability can craft a PDF which leads to large memory usage. This requires parsing large XMP me…
Update
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2026-48735
|
2026-05-30 04:38 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
789
|
3.3 |
LOW
Local
|
pypdf_project
|
pypdf
|
pypdf is a free and open-source pure-python PDF library. Prior to 6.12.0, an attacker who uses this vulnerability can craft a PDF which leads to long runtimes. This requires cross-reference streams w…
Update
|
CWE-834
Excessive Iteration
|
CVE-2026-48156
|
2026-05-30 04:38 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
790
|
5.5 |
MEDIUM
Local
|
pypdf_project
|
pypdf
|
pypdf is a free and open-source pure-python PDF library. Prior to 6.12.0, an attacker who uses this vulnerability can craft a PDF which leads to large memory usage. This requires extracting text in l…
Update
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2026-48155
|
2026-05-30 04:38 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|