|
481
|
6.8 |
MEDIUM
Network
|
-
|
-
|
EspoCRM is an open source customer relationship management application. Versions 9.3.3 and below allow authenticated users to upload SVG attachments through normal attachment-capable fields and later…
|
CWE-79
Cross-site Scripting
|
CVE-2026-33741
|
2026-05-20 23:16 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
482
|
6.5 |
MEDIUM
Network
|
-
|
-
|
libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and prior, when decoding a HEIF grid image with strict_decoding=false (the default), a corrupted tile silently fails to …
|
CWE-200 CWE-908
Information Exposure Use of Uninitialized Resource
|
CVE-2026-32814
|
2026-05-20 23:16 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
483
|
9.1 |
CRITICAL
Network
|
-
|
-
|
API endpoints in LalanaChami Pharmacy Management System (commit 5c3d028) lack authentication middleware. Unauthenticated remote attackers can exploit this to dump all user records (including bcrypt p…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2026-31071
|
2026-05-20 23:16 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
484
|
9.8 |
CRITICAL
Network
|
-
|
-
|
The LalanaChami Pharmacy Management System (commit 5c3d028) allows unauthenticated remote attackers to escalate privileges by self-assigning an administrative role during registration. The /api/user/…
|
CWE-269
Improper Privilege Management
|
CVE-2026-31070
|
2026-05-20 23:16 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
485
|
8.8 |
HIGH
Network
|
-
|
-
|
BillaBear (all versions prior to Jan 2026) contains a SQL Injection vulnerability in the EventRepository. User-controlled input from metric filter names and aggregation properties is directly interpo…
|
CWE-89
SQL Injection
|
CVE-2026-31069
|
2026-05-20 23:16 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
486
|
9.8 |
CRITICAL
Network
|
-
|
-
|
scalar/astro v0.1.13 was discovered to contain a Server-Side Request Forgery (SSRF) in the scalar_url query parameter of the Scalar Proxy endpoint. This vulnerability allows unauthenticated attackers…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-30118
|
2026-05-20 23:16 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
487
|
9.8 |
CRITICAL
Network
|
-
|
-
|
scalar/astro v0.1.13 was discovered to contain an arbitrary file upload vulnerability in the the scalar_url query parameter of the Scalar Proxy endpoint. This vulnerability allows attackers to execut…
|
CWE-94
Code Injection
|
CVE-2026-30117
|
2026-05-20 23:16 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
488
|
4.6 |
MEDIUM
Physics
|
-
|
-
|
Ledger Nano X, Flex, and Stax devices contain a denial of service vulnerability in the MCU firmware update process due to missing validation of the reset_handler parameter during firmware flashing. A…
|
CWE-1284
Improper Validation of Specified Quantity in Input
|
CVE-2025-15645
|
2026-05-20 23:16 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
489
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Ledger Live with vulnerable versions of ledgerhq/hw-app-eth prior to 6.34.7 contains an integer parsing vulnerability that allows attackers to manipulate EIP-712 typed data messages by exploiting inc…
|
CWE-704
Incorrect Type Conversion or Cast
|
CVE-2023-7345
|
2026-05-20 23:16 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
490
|
- |
|
-
|
-
|
Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.1 and prior contain a Stored XSS vulnerability. When cloning an issue originating from a Project other than the current on…
|
CWE-79
Cross-site Scripting
|
CVE-2026-34463
|
2026-05-20 23:06 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|