|
121
|
7.1 |
HIGH
Network
|
-
|
-
|
Exposure of private personal information to an unauthorized actor, Insufficiently Protected Credentials vulnerability in Digital Operations Services Inc. WifiBurada allows Authentication Bypass.
Thi…
New
|
CWE-359 CWE-522
Exposure of Private Personal Information to an Unauthorized Actor Insufficiently Protected Credentials
|
CVE-2025-13477
|
2026-05-22 00:24 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
122
|
7.5 |
HIGH
Network
|
-
|
-
|
Authorization bypass through User-Controlled key vulnerability in PosCube Hardware Software and Consulting Ltd. QR Menu allows Exploitation of Trusted Identifiers.
This issue affects QR Menu: throug…
New
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2025-13479
|
2026-05-22 00:24 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
123
|
5.7 |
MEDIUM
Network
|
-
|
-
|
Insufficient session expiration vulnerability in Turkiye Electricity Transmission Corporation (TEİAŞ) Mobile Application allows Session Hijacking.
This issue affects Mobile Application: from 1.6.2 b…
New
|
CWE-613
Insufficient Session Expiration
|
CVE-2026-1815
|
2026-05-22 00:24 |
2026-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
124
|
6.3 |
MEDIUM
Network
|
-
|
-
|
Improper restriction of excessive authentication attempts vulnerability in Turkiye Electricity Transmission Corporation (TEİAŞ) Mobile Application allows Brute Force.
This issue affects Mobile Appli…
New
|
CWE-307
mproper Restriction of Excessive Authentication Attempts
|
CVE-2026-1816
|
2026-05-22 00:24 |
2026-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
125
|
5.3 |
MEDIUM
Network
|
isc
|
bind
|
An unbounded resend loop vulnerability exists in the BIND 9 resolver state machine during bad-server handling, enabling a remote unauthenticated attacker to cause severe resource exhaustion by sendin…
New
|
CWE-606
Unchecked Input for Loop Condition
|
CVE-2026-5950
|
2026-05-22 00:24 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
126
|
5.9 |
MEDIUM
Network
|
isc
|
bind
|
Undefined behavior may result due to a race condition leading to a use-after-free violation. If BIND receives an incoming DNS message signed with SIG(0), it begins work to validate that signature. …
New
|
CWE-362 CWE-416
Race Condition Use After Free
|
CVE-2026-5947
|
2026-05-22 00:24 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
127
|
9.8 |
CRITICAL
Network
|
isc
|
bind
|
A use-after-free vulnerability exists within the DNS-over-HTTPS implementation.
This issue affects BIND 9 versions 9.20.0 through 9.20.22, 9.21.0 through 9.21.21, and 9.20.9-S1 through 9.20.22-S1.
BI…
New
|
CWE-416
Use After Free
|
CVE-2026-3593
|
2026-05-22 00:24 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
128
|
7.5 |
HIGH
Network
|
isc
|
bind
|
Multiple flaws have been identified in `named` related to the handling of DNS messages whose CLASS is not Internet (`IN`) — for example, `CHAOS` or `HESIOD`, or DNS messages that specify meta-classes…
New
|
CWE-20 CWE-125 CWE-617 CWE-754 CWE-843
Improper Input Validation Out-of-bounds Read Reachable Assertion Improper Check for Unusual or Exceptional Conditions Type Confusion
|
CVE-2026-5946
|
2026-05-22 00:24 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
129
|
7.5 |
HIGH
Network
|
isc
|
bind
|
BIND servers that are configured to use TKEY-based authentication via GSS-API tokens are vulnerable to excessive memory consumption when receiving and processing maliciously-constructed packets. Typ…
New
|
CWE-771
Missing Reference to Active Allocated Resource
|
CVE-2026-3039
|
2026-05-22 00:24 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
130
|
8.6 |
HIGH
Network
|
-
|
-
|
Trilium Notes is a cross-platform, hierarchical note taking application focused on building large personal knowledge bases. In versions 0.102.1 and prior, the Clipper API in Trilium Desktop (v0.101.3…
New
|
CWE-284 CWE-306
Improper Access Control Missing Authentication for Critical Function
|
CVE-2026-39310
|
2026-05-22 00:24 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|