|
1201
|
8.2 |
HIGH
Network
|
-
|
-
|
code100x contains an authentication bypass vulnerability in the Mobile API that allows unauthenticated attackers to impersonate arbitrary users by supplying a crafted JSON payload in the 'g' HTTP hea…
New
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-8890
|
2026-05-27 05:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1202
|
- |
|
-
|
-
|
Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accid…
New
|
-
|
CVE-2026-8453
|
2026-05-27 05:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1203
|
3.1 |
LOW
Network
|
-
|
-
|
TypeBot is a chatbot builder tool. In versions 3.15.2 and prior, the bot engine's the findResult query does not filter results by typebotId, allowing an authenticated user to load result data (user a…
New
|
CWE-639 CWE-862
Authorization Bypass Through User-Controlled Key Missing Authorization
|
CVE-2026-39967
|
2026-05-27 05:16 |
2026-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1204
|
- |
|
-
|
-
|
A cross-site scripting vulnerability exists in Aterm. Arbitrary scripts may be executed in the web browser of a user accessing the web management interface via adjacent network.
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-6059
|
2026-05-27 05:14 |
2026-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1205
|
- |
|
-
|
-
|
An OS Command Injection vulnerability exists in Aterm. If a malicious third person gains administrator access to the product’s web console, they may be able to execute arbitrary OS commands via adjac…
New
|
CWE-78
OS Command
|
CVE-2026-8652
|
2026-05-27 05:14 |
2026-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1206
|
- |
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
net: skbuff: propagate shared-frag marker through frag-transfer helpers
Two frag-transfer helpers (__pskb_copy_fclone() and skb_s…
New
|
-
|
CVE-2026-43503
|
2026-05-27 05:06 |
2026-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1207
|
8.5 |
HIGH
Network
|
-
|
-
|
A vulnerability in the `GitHubRepository` block of the `prefect-github` integration in Prefect version 3.6.18 allows an attacker to inject arbitrary git command-line options via the `reference` field…
New
|
CWE-88
Argument Injection
|
CVE-2026-3515
|
2026-05-27 05:06 |
2026-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1208
|
7.8 |
HIGH
Local
|
-
|
-
|
A critical remote code execution vulnerability exists in all versions of the HuggingFace transformers library prior to version 5.3.0. The vulnerability allows an attacker to craft a malicious `config…
New
|
CWE-1066
|
CVE-2026-4372
|
2026-05-27 05:06 |
2026-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1209
|
- |
|
-
|
-
|
This vulnerability exists in CP Plus Wi-Fi Camera due to improper protection of sensitive information in runtime memory. An attacker with physical access could exploit this vulnerability by accessing…
New
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2026-9274
|
2026-05-27 05:04 |
2026-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1210
|
5.4 |
MEDIUM
Network
|
-
|
-
|
JupyterHub is software that allows users to create a multi-user server for Jupyter notebooks. In versions 4.1.0 through 5.4.4, XSRF protection (updated in 4.1.0) inappropriately treated requests with…
New
|
CWE-352
Origin Validation Error
|
CVE-2026-40864
|
2026-05-27 05:03 |
2026-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|