|
891
|
6.5 |
MEDIUM
Local
|
sandboxie-plus
|
sandboxie
|
Sandboxie is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, a local denial of service vulnerability exists in the Sandboxie kernel driver. An unprivilege…
Update
|
CWE-20
Improper Input Validation
|
CVE-2026-32603
|
2026-05-8 05:02 |
2026-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
892
|
6.1 |
MEDIUM
Network
|
hcltech
|
dfxanalytics
|
HCL DFXAnalytics is affected by an Insecure Security Header configuration vulnerability where the Content-Security-Policy does not define strict directives for object-src and base-uri, which could al…
Update
|
CWE-358 CWE-79
Improperly Implemented Security Check for Standard Cross-site Scripting
|
CVE-2025-31970
|
2026-05-8 04:58 |
2026-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
893
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
counter: rz-mtu3-cnt: do not use struct rz_mtu3_channel's dev member
The counter driver can use HW channels 1 and 2, while the PW…
Update
|
NVD-CWE-noinfo
|
CVE-2026-31740
|
2026-05-8 04:56 |
2026-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
894
|
5.5 |
MEDIUM
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
counter: rz-mtu3-cnt: prevent counter from being toggled multiple times
Runtime PM counter is incremented / decremented each time…
Update
|
NVD-CWE-Other
|
CVE-2026-31741
|
2026-05-8 04:55 |
2026-05-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
895
|
7.2 |
HIGH
Network
|
-
|
-
|
Postorius through 1.3.13 does not escape HTML in the message subject when rendering it in the Held messages pop-up, as exploited in the wild in May 2026.
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-44742
|
2026-05-8 04:53 |
2026-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
896
|
- |
|
-
|
-
|
BentoPDF is a client-side PDF toolkit that is self hostable. Prior to version 2.8.3, a cross-site scripting vulnerability was identified in BentoPD. An attacker may be able to execute arbitrary JavaS…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-41653
|
2026-05-8 04:51 |
2026-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
897
|
5.4 |
MEDIUM
Network
|
-
|
-
|
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.217, a user holding the PERM_EDIT_USERS permission (intended for general user-profile editing) …
New
|
CWE-863
Incorrect Authorization
|
CVE-2026-41903
|
2026-05-8 04:51 |
2026-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
898
|
8.8 |
HIGH
Local
|
sandboxie-plus
|
sandboxie
|
Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, an INI injection vulnerability allows any standard local user to bypass configuration re…
Update
|
CWE-93
CRLF Injection
|
CVE-2026-34458
|
2026-05-8 04:48 |
2026-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
899
|
7.3 |
HIGH
Network
|
-
|
-
|
A vulnerability was found in SourceCodester Pharmacy Sales and Inventory System 1.0. This affects an unknown part of the file /ajax.php?action=save_user. The manipulation of the argument ID results i…
New
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-8083
|
2026-05-8 04:48 |
2026-05-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
900
|
8.8 |
HIGH
Local
|
sandboxie-plus
|
sandboxie
|
Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, the SbieSvc proxy service's GetRawInputDeviceInfoSlave handler contains two vulnerabilit…
Update
|
CWE-121
Stack-based Buffer Overflow
|
CVE-2026-34459
|
2026-05-8 04:48 |
2026-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|