|
251
|
7.7 |
HIGH
Network
|
-
|
-
|
Active debug code exists in the ARN resolver of amazon-mq rabbitmq-aws before version 0.2.1. A debug ARN scheme (arn:aws-debug:file) accepted by the PUT /api/aws/arn/validate validation endpoint migh…
New
|
CWE-489
Exposure of Data Element to Wrong Session
|
CVE-2026-9133
|
2026-05-22 00:24 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252
|
8.7 |
HIGH
Network
|
-
|
-
|
authentik is an open-source identity provider. Versions 2025.12.4 and prior, and versions 2026.2.0-rc1 through 2026.2.2 were vulnerable to Authentication Bypass through SAML NameID XML Comment Inject…
New
|
CWE-91 CWE-287 CWE-436
Blind XPath Injection Improper Authentication Interpretation Conflict
|
CVE-2026-40165
|
2026-05-22 00:24 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253
|
- |
|
-
|
-
|
A missing authentication vulnerability exists in the Altium 365 SearchService. A legacy SOAP endpoint exposes search index operations without requiring authentication, session tokens, or any form of …
New
|
CWE-306 CWE-639
Missing Authentication for Critical Function Authorization Bypass Through User-Controlled Key
|
CVE-2026-9152
|
2026-05-22 00:24 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
254
|
8.4 |
HIGH
Local
|
-
|
-
|
Improper input validation, Unrestricted upload of file with dangerous type vulnerability in Gmission Web Fax allows Remote Code Inclusion.
This issue affects Web Fax: from 3.0 before 3.1.
New
|
CWE-20 CWE-434
Improper Input Validation Unrestricted Upload of File with Dangerous Type
|
CVE-2026-9157
|
2026-05-22 00:24 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255
|
- |
|
-
|
-
|
(Externally Controlled Reference to a Resource in Another Sphere), (Authorization Bypass Through User-Controlled Key) vulnerability in Apache Camel K. Authorized users in a Kubernetes namespace can c…
New
|
CWE-610 CWE-639
Externally Controlled Reference to a Resource in Another Sphere Authorization Bypass Through User-Controlled Key
|
CVE-2026-45760
|
2026-05-22 00:24 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256
|
5.3 |
MEDIUM
Network
|
isc
|
bind
|
BIND resolvers are vulnerable to an amplified resource consumption/exhaustion attack. If a victim resolver makes a query to a specially crafted zone, the resolver will consume disproportionate resou…
New
|
CWE-408
Incorrect Behavior Order: Early Amplification
|
CVE-2026-3592
|
2026-05-22 00:24 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257
|
8.8 |
HIGH
Network
|
-
|
-
|
An SQL injection vulnerability in the MySQL CNID backend in Netatalk 3.1.0 through 4.4.2 allows a remote authenticated attacker to obtain unauthorized access to data, modify data, or cause a denial o…
New
|
CWE-89
SQL Injection
|
CVE-2026-44047
|
2026-05-22 00:20 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
258
|
8.8 |
HIGH
Network
|
-
|
-
|
A stack-based buffer overflow via UCS-2 type confusion in convert_charset() in Netatalk 2.0.4 through 4.4.2 allows a remote authenticated attacker to execute arbitrary code or cause a denial of servi…
New
|
CWE-121
Stack-based Buffer Overflow
|
CVE-2026-44048
|
2026-05-22 00:20 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
259
|
7.5 |
HIGH
Network
|
-
|
-
|
An out-of-bounds write due to improper null termination in convert_charset() in Netatalk 2.0.4 through 4.4.2 allows a remote authenticated attacker to execute arbitrary code or cause a denial of serv…
New
|
CWE-787
Out-of-bounds Write
|
CVE-2026-44049
|
2026-05-22 00:20 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
260
|
9.9 |
CRITICAL
Network
|
-
|
-
|
A heap-based buffer overflow in the CNID daemon comm_rcv() function in Netatalk 2.0.0 through 4.4.2 allows a remote authenticated attacker to execute arbitrary code with escalated privileges or cause…
New
|
CWE-122
Heap-based Buffer Overflow
|
CVE-2026-44050
|
2026-05-22 00:20 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|