|
261
|
7.5 |
HIGH
Network
|
-
|
-
|
Prometheus is an open-source monitoring system and time series database. Prior to versions 3.5.3 and 3.11.3, the client_secret field in the Azure AD remote write OAuth configuration (storage/remote/a…
New
|
CWE-200 CWE-312
Information Exposure Cleartext Storage of Sensitive Information
|
CVE-2026-42151
|
2026-05-5 04:16 |
2026-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
262
|
- |
|
-
|
-
|
Claude SDK for TypeScript provides access to the Claude API from server-side TypeScript or JavaScript applications. From version 0.79.0 to before version 0.91.1, the BetaLocalFilesystemMemoryTool in …
New
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2026-41686
|
2026-05-5 04:16 |
2026-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
263
|
7.5 |
HIGH
Network
|
-
|
-
|
Conditional Fields for Contact Form 7 WordPress plugin through version 2.6.7 contains an uncontrolled resource consumption vulnerability in the Wpcf7cfMailParser class where the hide_hidden_mail_fiel…
New
|
CWE-1284
Improper Validation of Specified Quantity in Input
|
CVE-2026-25863
|
2026-05-5 04:16 |
2026-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264
|
5.5 |
MEDIUM
Local
|
absolute
|
secure_access
|
CVE-2026-40951 is a memory corruption vulnerability on Secure Access
Windows clients prior to 14.50. Attackers with local control of the
Windows client can send malformed data to an API and trigger…
Update
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2026-40951
|
2026-05-5 03:54 |
2026-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265
|
9.8 |
CRITICAL
Network
|
tenda
|
w308r_firmware
|
Tenda W308R v2 V5.07.48 contains a cookie session weakness vulnerability that allows unauthenticated attackers to modify DNS settings by exploiting insufficient session validation. Attackers can send…
Update
|
CWE-290
Authentication Bypass by Spoofing
|
CVE-2018-25316
|
2026-05-5 03:42 |
2026-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266
|
9.8 |
CRITICAL
Network
|
tenda
|
fh303_firmware a300_firmware
|
Tenda FH303/A300 firmware V5.07.68_EN contains a session weakness vulnerability that allows unauthenticated attackers to modify DNS settings by exploiting insufficient cookie validation. Attackers ca…
Update
|
CWE-290
Authentication Bypass by Spoofing
|
CVE-2018-25318
|
2026-05-5 03:40 |
2026-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267
|
5.0 |
MEDIUM
Network
|
cloudfoundry
|
cf-deployment routing_release
|
Route Services can be leveraged to send app traffic to network destinations outside of an app's configured egress rules. As a result, a malicious developer with access to Cloudfoundry could configure…
Update
|
CWE-923
Improper Restriction of Communication Channel to Intended Endpoints
|
CVE-2026-22726
|
2026-05-5 03:30 |
2026-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268
|
7.5 |
HIGH
Network
|
openstack
|
ironic_python_agent
|
An issue was discovered in OpenStack ironic-python-agent 1.0.0 through 11.5.0. Ironic Python Agent (IPA) sometimes executes grub-install from within a chroot of the deployed partition image, leading …
Update
|
CWE-829
Inclusion of Functionality from Untrusted Control Sphere
|
CVE-2026-43003
|
2026-05-5 03:28 |
2026-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269
|
9.8 |
CRITICAL
Network
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
ip6_tunnel: clear skb2->cb[] in ip4ip6_err()
Oskar Kjos reported the following problem.
ip4ip6_err() calls icmp_send() on a clon…
Update
|
CWE-787
Out-of-bounds Write
|
CVE-2026-43037
|
2026-05-5 03:26 |
2026-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270
|
8.5 |
HIGH
Network
|
openstack
|
keystone
|
An issue was discovered in OpenStack Keystone 13 through 29. POST /v3/credentials did not validate that the caller-supplied project_id for an EC2-type credential matched the project of the authentica…
Update
|
CWE-863
Incorrect Authorization
|
CVE-2026-43001
|
2026-05-5 03:25 |
2026-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|