|
301
|
8.8 |
HIGH
Network
|
snorkel
|
snorkel
|
The snorkel library thru v0.10.0 contains an insecure deserialization vulnerability (CWE-502) in the Trainer.load() method of the Trainer class. The method loads model checkpoint files using torch.lo…
Update
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-31222
|
2026-05-16 04:16 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
302
|
8.8 |
HIGH
Network
|
lightningai
|
pytorch_lightning
|
PyTorch-Lightning versions 2.6.0 and earlier contain an insecure deserialization vulnerability (CWE-502) in the checkpoint loading mechanism. The LightningModule.load_from_checkpoint() method, which …
Update
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-31221
|
2026-05-16 04:16 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303
|
9.8 |
CRITICAL
Network
|
-
|
-
|
PySyft (Syft Datasite/Server) versions 0.9.5 and earlier are vulnerable to remote code execution due to insufficient validation and sandboxing of user-submitted code. The system allows low-privileged…
Update
|
CWE-94
Code Injection
|
CVE-2026-31220
|
2026-05-16 04:16 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
304
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Medical Management System a81df1ce700a9662cb136b27af47f4cbde64156b is vulnerable to Insecure Permissions, which allows arbitrary user password reset.
New
|
CWE-284
Improper Access Control
|
CVE-2025-67437
|
2026-05-16 04:16 |
2026-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
305
|
6.4 |
MEDIUM
Network
|
-
|
-
|
Podcast Generator 3.1 contains a persistent cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by submitting unfiltered JavaScript code in the long_des…
New
|
CWE-79
Cross-site Scripting
|
CVE-2021-47968
|
2026-05-16 04:16 |
2026-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
306
|
6.1 |
MEDIUM
Network
|
-
|
-
|
PHP Timeclock 1.04 contains multiple cross-site scripting vulnerabilities that allow unauthenticated attackers to inject arbitrary JavaScript by manipulating URL paths and POST parameters. Attackers …
New
|
CWE-79
Cross-site Scripting
|
CVE-2021-47967
|
2026-05-16 04:16 |
2026-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307
|
8.2 |
HIGH
Network
|
-
|
-
|
PHP Timeclock 1.04 contains time-based and boolean-based blind SQL injection vulnerabilities in the login_userid parameter of login.php that allows unauthenticated attackers to extract database conte…
New
|
CWE-89
SQL Injection
|
CVE-2021-47966
|
2026-05-16 04:16 |
2026-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308
|
9.8 |
CRITICAL
Network
|
-
|
-
|
WordPress Plugin WP Super Edit 2.5.4 and earlier contains an unrestricted file upload vulnerability in the FCKeditor component that allows attackers to upload dangerous file types without validation.…
New
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2021-47965
|
2026-05-16 04:16 |
2026-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309
|
8.8 |
HIGH
Network
|
-
|
-
|
Schlix CMS 2.2.6-6 contains a remote code execution vulnerability that allows authenticated attackers to execute arbitrary PHP code by uploading malicious extension packages through the block manager…
New
|
CWE-94
Code Injection
|
CVE-2021-47964
|
2026-05-16 04:16 |
2026-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310
|
7.2 |
HIGH
Network
|
-
|
-
|
Anote 1.0 contains a persistent cross-site scripting vulnerability that allows attackers to execute arbitrary code by injecting malicious payloads into markdown files stored within the application. A…
New
|
CWE-79
Cross-site Scripting
|
CVE-2021-47963
|
2026-05-16 04:16 |
2026-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|