|
1
|
8.1 |
HIGH
Network
|
microsoft
|
malware_protection_engine
|
Heap-based buffer overflow in Microsoft Defender allows an unauthorized attacker to execute code over a network.
New
|
CWE-122
Heap-based Buffer Overflow
|
CVE-2026-45584
|
2026-05-21 03:56 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2
|
7.8 |
HIGH
Local
|
microsoft
|
windows_admin_center
|
Improper link resolution before file access ('link following') in Azure Portal Windows Admin Center allows an authorized attacker to elevate privileges locally.
New
|
CWE-59
Link Following
|
CVE-2026-42834
|
2026-05-21 03:29 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Missing Authorization vulnerability in Drupal Date iCal allows Forceful Browsing.
This issue affects Date iCal: from 0.0.0 before 4.0.15.
New
|
CWE-862
Missing Authorization
|
CVE-2026-8495
|
2026-05-21 03:16 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4
|
5.4 |
MEDIUM
Network
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Colorbox Inline allows Cross-Site Scripting (XSS).
This issue affects Colorbox Inline: fr…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-8493
|
2026-05-21 03:16 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
5
|
2.7 |
LOW
Network
|
-
|
-
|
Modification of Assumed-Immutable Data (MAID) vulnerability in Drupal Translate Drupal with GTranslate allows Resource Location Spoofing.
This issue affects Translate Drupal with GTranslate: from 0.…
New
|
CWE-471
Modification of Assumed-Immutable Data (MAID)
|
CVE-2026-8492
|
2026-05-21 03:16 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6
|
3.7 |
LOW
Network
|
-
|
-
|
Improper Check for Unusual or Exceptional Conditions vulnerability in Drupal Node View Permissions allows Forceful Browsing.
This issue affects Node View Permissions: from 0.0.0 before 1.7.0, from 2…
New
|
CWE-754
Improper Check for Unusual or Exceptional Conditions
|
CVE-2026-8491
|
2026-05-21 03:16 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7
|
5.8 |
MEDIUM
Network
|
-
|
-
|
The Decent Comments WordPress plugin before 3.0.2 does not restrict access to comment author email addresses and post author email addresses via its REST API endpoint, allowing unauthenticated attack…
New
|
-
|
CVE-2026-7385
|
2026-05-21 03:16 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
8
|
4.0 |
MEDIUM
Local
|
-
|
-
|
Microsoft Defender Denial of Service Vulnerability
New
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2026-45498
|
2026-05-21 03:16 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
9
|
7.8 |
HIGH
Local
|
-
|
-
|
Improper link resolution before file access ('link following') in Microsoft Defender allows an authorized attacker to elevate privileges locally.
New
|
CWE-59
Link Following
|
CVE-2026-41091
|
2026-05-21 03:16 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
10
|
4.8 |
MEDIUM
Network
|
-
|
-
|
CtrlPanel is open-source billing software for hosting providers. Versions 1.1.1 and prior contain a Stored Cross-Site Scripting (XSS) vulnerability exists in the admin role management interface. In a…
New
|
CWE-80 CWE-116
Basic XSS Improper Encoding or Escaping of Output
|
CVE-2026-34246
|
2026-05-21 03:16 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|