|
1621
|
4.3 |
MEDIUM
Network
|
-
|
-
|
AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. Prior to version 1.12.1, GET /api/workspace/:slug/tts/:chatId in AnythingLL…
|
CWE-200 CWE-639
Information Exposure Authorization Bypass Through User-Controlled Key
|
CVE-2026-42456
|
2026-05-14 01:58 |
2026-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1622
|
- |
|
-
|
-
|
The Claude Desktop app gives you Claude Code with a graphical interface built for running multiple sessions side by side. Prior to 1.3834.0, the CoworkVMService component in Claude Desktop for Window…
|
CWE-59 CWE-269
Link Following Improper Privilege Management
|
CVE-2026-44470
|
2026-05-14 01:58 |
2026-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1623
|
5.5 |
MEDIUM
Local
|
-
|
-
|
Vercel’s AI Cloud is a unified platform for building modern applications. From 50.16.0 to 52.0.0, hen the Vercel CLI runs in non-interactive mode (--non-interactive or auto-detected AI agent), comma…
|
CWE-200 CWE-532
Information Exposure Inclusion of Sensitive Information in Log Files
|
CVE-2026-44479
|
2026-05-14 01:58 |
2026-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1624
|
- |
|
-
|
-
|
The Claude Desktop app gives you Claude Code with a graphical interface built for running multiple sessions side by side. From 1.2581.0 to before 1.4304.0, Claude Desktop's SSH remote development fea…
|
CWE-297 CWE-322
Improper Validation of Certificate with Host Mismatch Key Exchange without Entity Authentication
|
CVE-2026-44467
|
2026-05-14 01:58 |
2026-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1625
|
9.1 |
CRITICAL
Network
|
-
|
-
|
auth provides authentication via oauth2, direct and email. From versions 1.18.0 to before 1.25.2 and 2.0.0 to before 2.1.2, the Patreon OAuth provider maps every authenticated Patreon account to the …
|
CWE-287
Improper Authentication
|
CVE-2026-42560
|
2026-05-14 01:58 |
2026-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1626
|
8.8 |
HIGH
Network
|
-
|
-
|
OWASP BLT is a QA testing and vulnerability disclosure platform that encompasses websites, apps, git repositories, and more. Prior to 2.1.2, .github/workflows/pre-commit-fix.yaml uses pull_request_ta…
|
CWE-94 CWE-95
Code Injection Eval Injection
|
CVE-2026-42603
|
2026-05-14 01:58 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1627
|
- |
|
-
|
-
|
Neat VNC is a VNC server library. Prior to 0.9.6, a pre-authentication stack buffer overflow exists in neatvnc in the RSA-AES security type handler. An unauthenticated remote attacker who can reach t…
|
CWE-120
Classic Buffer Overflow
|
CVE-2026-42859
|
2026-05-14 01:58 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1628
|
6.1 |
MEDIUM
Network
|
-
|
-
|
fast-xml-builder builds XML from JSON. In 1.1.5, the fix for CVE-2026-41650 in fast-xml-parser sanitizes -- sequences in XML comment content using .replace(/--/g, '- -'). This skip the values contain…
|
CWE-91
Blind XPath Injection
|
CVE-2026-44664
|
2026-05-14 01:58 |
2026-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1629
|
- |
|
-
|
-
|
New API is a large language mode (LLM) gateway and artificial intelligence (AI) asset management system. In versions 0.11.9-alpha.1 and prior, the SSRF protection introduced in v0.9.0.5 (CVE-2025-591…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-42339
|
2026-05-14 01:53 |
2026-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1630
|
6.5 |
MEDIUM
Network
|
-
|
-
|
kafka-sink-azure-kusto Kafka Connect plugin is the official Microsoft sink for Azure Data Explorer (Kusto). Prior to 5.2.3, kafka-sink-azure-kusto did not sanitize user-controlled values inside the k…
|
CWE-943
Improper Neutralization of Special Elements in Data Query Logic
|
CVE-2026-42316
|
2026-05-14 01:53 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|