|
881
|
7.5 |
HIGH
Network
|
-
|
-
|
In tinyMQTT commit 6226ade15bd4f97be2d196352e64dd10937c1962 (2024-02-18), the broker mishandles protocol violations during CONNECT packet parsing. When receiving a CONNECT packet with a zero-length C…
New
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2025-56352
|
2026-05-19 03:17 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
882
|
8.6 |
HIGH
Network
|
lfprojects
|
mlflow
|
A vulnerability in mlflow/mlflow versions 3.9.0 and earlier allows unauthenticated access to certain FastAPI routes when the server is started with authentication enabled (`--app-name basic-auth`) an…
Update
|
CWE-305
Authentication Bypass by Primary Weakness
|
CVE-2026-2652
|
2026-05-19 03:16 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
883
|
7.0 |
HIGH
Local
|
vmware
|
fusion
|
VMware Fusion contains a TOCTOU (Time-of-check Time-of-use) vulnerability that occurs during an operation performed by a SETUID binary. A malicious actor with local non-administrative user privileges…
Update
|
CWE-367
Time-of-check Time-of-use (TOCTOU) Race Condition
|
CVE-2026-41702
|
2026-05-19 03:15 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
884
|
5.3 |
MEDIUM
Local
|
tonyc
|
imager\
|
Imager::File::GIF versions through 1.002 for Perl allow a heap out of bounds (OOB) write on crafted multi-frame GIF files.
Imager::File::GIF's i_readgif_multi_low allocates a single per-row buffer G…
Update
|
CWE-787
Out-of-bounds Write
|
CVE-2026-8454
|
2026-05-19 03:12 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
885
|
7.1 |
HIGH
Local
|
netty
|
netty
|
Netty is an asynchronous, event-driven network application framework. Prior to 4.2.13.Final and 4.1.133.Final, the Netty Redis codec encoder (RedisEncoder) writes user-controlled string content direc…
Update
|
CWE-93
CRLF Injection
|
CVE-2026-42586
|
2026-05-19 03:02 |
2026-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
886
|
8.8 |
HIGH
Network
|
-
|
-
|
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Basamak Information Technology Consulting and Organization Trade Ltd. Co. DernekWeb allows Stored…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-7498
|
2026-05-19 02:51 |
2026-05-18 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
887
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A security vulnerability has been detected in kalcaddle Kodbox up to 1.64. This issue affects the function parseVideoInfo of the file /workspace/source-code/plugins/fileThumb/lib/VideoResize.class.ph…
Update
|
CWE-74 CWE-77
Injection Command Injection
|
CVE-2026-8753
|
2026-05-19 02:51 |
2026-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
888
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was detected in AstrBotDevs AstrBot up to 4.23.5. Impacted is the function post_file of the file astrbot/dashboard/routes/chat.py of the component File Upload Handler. The manipulatio…
Update
|
CWE-22
Path Traversal
|
CVE-2026-8754
|
2026-05-19 02:51 |
2026-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
889
|
7.3 |
HIGH
Network
|
-
|
-
|
A vulnerability was determined in Metasoft 美特软件 MetaCRM up to 6.4.0 Beta06. This impacts an unknown function of the file /common/jsp/upload3.jsp. Executing a manipulation of the argument File can lea…
Update
|
CWE-284 CWE-434
Improper Access Control Unrestricted Upload of File with Dangerous Type
|
CVE-2026-8758
|
2026-05-19 02:51 |
2026-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
890
|
- |
|
-
|
-
|
Mathesar is a web application that makes working with PostgreSQL databases both simple and powerful. From 0.2.0 to before 0.10.0, explorations.get, explorations.replace, and explorations.delete opera…
Update
|
CWE-639 CWE-862
Authorization Bypass Through User-Controlled Key Missing Authorization
|
CVE-2026-44718
|
2026-05-19 02:50 |
2026-05-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|