|
521
|
7.1 |
HIGH
Local
|
saitoha
|
libsixel
|
libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. From to 1.8.7-r1, a signed integer overflow in the SIXEL parser's image-buffer doubling loop can lead to an out-of-boun…
New
|
CWE-190 CWE-787
Integer Overflow or Wraparound Out-of-bounds Write
|
CVE-2026-44637
|
2026-05-16 02:55 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
522
|
2.5 |
LOW
Local
|
saitoha
|
libsixel
|
libsixel is a SIXEL encoder/decoder implementation derived from kmiya's sixel. From to 1.8.7-r1, a wrong NULL check after an allocation call in sixel_decode_raw and sixel_decode causes a NULL pointe…
New
|
CWE-476 CWE-690
NULL Pointer Dereference Unchecked Return Value to NULL Pointer Dereference
|
CVE-2026-44638
|
2026-05-16 02:54 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
523
|
5.4 |
MEDIUM
Network
|
lfprojects
|
mcp_registry
|
The MCP Registry provides MCP clients with a list of MCP servers, like an app store for MCP servers. Prior to 1.7.7, the public catalogue UI served at GET / (file internal/api/handlers/v0/ui_index.ht…
New
|
CWE-79 CWE-116
Cross-site Scripting Improper Encoding or Escaping of Output
|
CVE-2026-44429
|
2026-05-16 02:52 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
524
|
7.2 |
HIGH
Network
|
misp
|
misp
|
MISP is an open source threat intelligence and sharing platform. Prior to 2.5.37, an improper access control vulnerability in the authentication key reset functionality allowed an authenticated organ…
Update
|
CWE-863
Incorrect Authorization
|
CVE-2026-44380
|
2026-05-16 02:42 |
2026-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
525
|
5.3 |
MEDIUM
Network
|
misp
|
misp
|
MISP is an open source threat intelligence and sharing platform. Prior to 2.5.37, a SQL injection vulnerability existed in the handling of user-controlled ordering parameters in the event and shadow …
Update
|
CWE-89
SQL Injection
|
CVE-2026-44381
|
2026-05-16 02:37 |
2026-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
526
|
8.1 |
HIGH
Network
|
fit2cloud
|
sqlbot
|
SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. Prior to 1.8.0, SQLBot contains a Cross-Workspace IDOR (Insecure Direct Object Reference) and Authorization Bypass …
Update
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-42463
|
2026-05-16 02:34 |
2026-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
527
|
9.1 |
CRITICAL
Network
|
opnsense
|
opnsense
|
OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.7, the XMLRPC method opnsense.restore_config_section fails to sanitize user supplied input leading to Remote Code Execution. T…
Update
|
CWE-88
Argument Injection
|
CVE-2026-44193
|
2026-05-16 02:30 |
2026-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
528
|
4.7 |
MEDIUM
Network
|
lfprojects
|
mcp_registry
|
The MCP Registry provides MCP clients with a list of MCP servers, like an app store for MCP servers. Prior to 1.7.6, the client-side and server-side GitHub OIDC flow is bound only to a global audienc…
New
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-44428
|
2026-05-16 02:23 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
529
|
9.1 |
CRITICAL
Network
|
opnsense
|
opnsense
|
OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.8, an authenticated Remote Code Execution (RCE) vulnerability in the OPNsense core allows a user with user-management privileg…
Update
|
CWE-78
OS Command
|
CVE-2026-44194
|
2026-05-16 02:19 |
2026-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
530
|
7.4 |
HIGH
Network
|
-
|
-
|
Microsoft APM is an open-source, community-driven dependency manager for AI agents. From 0.5.4 to 0.12.4, two primitive integrators in apm-cli enumerate package files with bare Path.glob() / Path.rgl…
New
|
CWE-59 CWE-200
Link Following Information Exposure
|
CVE-2026-45539
|
2026-05-16 02:16 |
2026-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|