|
1471
|
6.5 |
MEDIUM
Local
|
-
|
-
|
Kdenlive before 26.04.1 allows dangerous proxy parameters when an attacker-controlled project file is used.
Update
|
CWE-829
Inclusion of Functionality from Untrusted Control Sphere
|
CVE-2026-45184
|
2026-05-14 00:46 |
2026-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1472
|
8.1 |
HIGH
Network
|
-
|
-
|
Command injection vulnerability in automagik-genie 2.5.27 MCP Server allows attackers to execute arbitrary commands via the view_task (aka view) in the readTranscriptFromCommit function in dist/mcp/s…
Update
|
CWE-78
OS Command
|
CVE-2026-30635
|
2026-05-14 00:46 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1473
|
8.8 |
HIGH
Network
|
-
|
-
|
EDIMAX BR-6428nS V3 1.15 is vulnerable to Command Injection. An authenticated attacker with access to the network can submit crafted input to the WLAN configuration functionality. Due to insufficient…
Update
|
CWE-77
Command Injection
|
CVE-2026-36734
|
2026-05-14 00:46 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1474
|
7.3 |
HIGH
Network
|
-
|
-
|
An issue in QuickJS-NG v.0.12.1 allows an attacker to execute arbitrary code via the js_mapped_arguments_mark function
Update
|
CWE-94
Code Injection
|
CVE-2026-37630
|
2026-05-14 00:46 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1475
|
3.2 |
LOW
Local
|
-
|
-
|
Sangoma Switchvox before 8.4 places cleartext SIP authentication credentials in a backup file.
Update
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2026-45362
|
2026-05-14 00:46 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1476
|
5.3 |
MEDIUM
Network
|
-
|
-
|
Missing Authorization vulnerability in WPMU DEV Hustle allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects Hustle: through 7.8.10.1.
Update
|
CWE-862
Missing Authorization
|
CVE-2026-25431
|
2026-05-14 00:46 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1477
|
8.8 |
HIGH
Network
|
snorkel
|
snorkel
|
The snorkel library thru v0.10.0 contains an insecure deserialization vulnerability (CWE-502) in the MultitaskClassifier.load() method of the MultitaskClassifier class. The method loads model weight …
Update
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-31224
|
2026-05-14 00:44 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1478
|
7.1 |
HIGH
Network
|
-
|
-
|
The Salesforce module before 1.x-1.0.1 for Backdrop CMS does not properly use a random state parameter to protect the authorization flow against CSRF attacks.
Update
|
CWE-352
Origin Validation Error
|
CVE-2026-45430
|
2026-05-14 00:43 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1479
|
5.4 |
MEDIUM
Network
|
-
|
-
|
A Stored Cross-Site Scripting (XSS) vulnerability was discovered in the File Management module of FluentCMS 1.2.3. The flaw allows an authenticated administrator to upload crafted SVG files containin…
Update
|
CWE-79
Cross-site Scripting
|
CVE-2025-70842
|
2026-05-14 00:43 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1480
|
7.7 |
HIGH
Network
|
-
|
-
|
Xibo is an open source digital signage platform with a web content management system and Windows display player software. Prior to 4.4.1, an authenticated Server-Side Request Forgery (SSRF) vulnerabi…
Update
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-42141
|
2026-05-14 00:43 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|