|
1771
|
6.5 |
MEDIUM
Network
|
apache
|
apache-airflow-providers-opensearch
|
The OpenSearch logging provider, when configured with a `host` URL that embeds credentials (for example `https://user:password@server.example.com:9200`), wrote the full host URL — including the embed…
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2026-43826
|
2026-05-13 23:05 |
2026-05-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1772
|
7.5 |
HIGH
Network
|
apple
|
ipados iphone_os
|
A resource exhaustion issue was addressed with improved input validation. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.4 and iPadOS 26.4. A remote attacker may be able to cause a denia…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2026-28872
|
2026-05-13 23:03 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1773
|
7.5 |
HIGH
Network
|
apple
|
ipados iphone_os macos visionos
|
This issue was addressed through improved state management. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5,…
|
CWE-359
Exposure of Private Personal Information to an Unauthorized Actor
|
CVE-2026-28906
|
2026-05-13 23:03 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1774
|
3.3 |
LOW
Local
|
apple
|
macos
|
This issue was addressed with improved permissions checking. This issue is fixed in macOS Tahoe 26.4. A malicious app may be able to access arbitrary files.
|
CWE-284
Improper Access Control
|
CVE-2026-28910
|
2026-05-13 23:02 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1775
|
5.4 |
MEDIUM
Network
|
apple
|
ipados iphone_os macos
|
An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5. An app may …
|
CWE-787
Out-of-bounds Write
|
CVE-2026-28819
|
2026-05-13 23:00 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1776
|
6.5 |
MEDIUM
Network
|
apple
|
ipados iphone_os macos tvos visionos watchos
|
An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Parsing a malicio…
|
CWE-125 CWE-787
Out-of-bounds Read Out-of-bounds Write
|
CVE-2026-28918
|
2026-05-13 22:57 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1777
|
9.8 |
CRITICAL
Network
|
gnu redhat
|
gnutls hardened_images openshift_container_platform enterprise_linux
|
A flaw was found in gnutls. Servers configured with RSA-PSK (Rivest–Shamir–Adleman – Pre-Shared Key) wrongfully matched usernames containing a NUL character with truncated usernames. A remote attacke…
|
CWE-626
Null Byte Interaction Error (Poison Null Byte)
|
CVE-2026-42010
|
2026-05-13 22:54 |
2026-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1778
|
7.5 |
HIGH
Network
|
apple
|
ipados iphone_os macos tvos visionos watchos
|
A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26…
|
CWE-121
Stack-based Buffer Overflow
|
CVE-2026-28846
|
2026-05-13 22:46 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1779
|
6.1 |
MEDIUM
Network
|
th30d4y
|
w4nn4d13\/ip
|
In th30d4y/IP from version 1.0.1 to before version 2.0.1, a DOM-Based Cross-Site Scripting (XSS) vulnerability was identified in an IP Reputation Checker application. Unsanitized user input was direc…
|
CWE-79 CWE-80
Cross-site Scripting Basic XSS
|
CVE-2026-41575
|
2026-05-13 06:11 |
2026-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1780
|
8.1 |
HIGH
Network
|
inducer
|
relate
|
RELATE is a web-based courseware package. Prior to commit 2f68e16, there is a timing attack vulnerability in course/auth.py — check_sign_in_key(). This issue has been patched via commit 2f68e16.
|
CWE-208 CWE-203
Information Exposure Through Timing Discrepancy Information Exposure Through Discrepancy
|
CVE-2026-41588
|
2026-05-13 06:09 |
2026-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|