|
431
|
7.4 |
HIGH
Adjacent
|
microsoft
|
windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2012 windows_server_2016 w…
|
Null pointer dereference in Windows TCP/IP allows an unauthorized attacker to deny service over an adjacent network.
Update
|
CWE-476
NULL Pointer Dereference
|
CVE-2026-40414
|
2026-05-16 00:07 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
432
|
8.1 |
HIGH
Network
|
microsoft
|
windows_10_1809 windows_10_21h2 windows_10_22h2 windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2019 windows_server_2022 windows_server_2022_…
|
Use after free in Windows TCP/IP allows an unauthorized attacker to execute code over a network.
Update
|
CWE-416
Use After Free
|
CVE-2026-40415
|
2026-05-16 00:06 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
433
|
3.3 |
LOW
Local
|
microsoft
|
visual_studio_code
|
Improper neutralization of script-related html tags in a web page (basic xss) in Visual Studio Code allows an unauthorized attacker to execute code locally.
Update
|
CWE-77 CWE-80 CWE-79
Command Injection Basic XSS Cross-site Scripting
|
CVE-2026-41611
|
2026-05-16 00:05 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
434
|
9.1 |
CRITICAL
Network
|
okfn
|
ckan
|
CKAN is an open-source DMS (data management system) for powering data hubs and data portals. Prior to 2.10.10 and 2.11.5, a vulnerability in datastore_search_sql allowed attackers to bypass authoriza…
New
|
CWE-863
Incorrect Authorization
|
CVE-2026-42032
|
2026-05-16 00:02 |
2026-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
435
|
9.8 |
CRITICAL
Network
|
okfn
|
ckan
|
CKAN is an open-source DMS (data management system) for powering data hubs and data portals. Prior to 2.10.10 and 2.11.5, a vulnerability in datastore_search_sql allowed attackers to inject SQL in or…
New
|
CWE-89
SQL Injection
|
CVE-2026-42031
|
2026-05-15 23:59 |
2026-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
436
|
6.1 |
MEDIUM
Network
|
okfn
|
ckan
|
CKAN is an open-source DMS (data management system) for powering data hubs and data portals. Prior to 2.10.10 and 2.11.5, Access to the views via tokens or unauthenticated requests marked the endpoin…
New
|
CWE-352
Origin Validation Error
|
CVE-2026-41255
|
2026-05-15 23:58 |
2026-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
437
|
7.4 |
HIGH
Network
|
okfn
|
ckan
|
CKAN is an open-source DMS (data management system) for powering data hubs and data portals. Prior to 2.10.10 and 2.11.5, the configured SMTP server may be spoofed with any certificate (e.g. self-sig…
New
|
CWE-295
Improper Certificate Validation
|
CVE-2026-41132
|
2026-05-15 23:57 |
2026-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
438
|
5.3 |
MEDIUM
Network
|
-
|
-
|
Hedera Guardian through 3.5.1 contains an authentication bypass vulnerability in the GET /api/v1/demo/registered-users endpoint that allows unauthenticated attackers to retrieve sensitive user inform…
New
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2026-45248
|
2026-05-15 23:56 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
439
|
8.6 |
HIGH
Network
|
-
|
-
|
A vulnerability in mlflow/mlflow versions 3.9.0 and earlier allows unauthenticated access to certain FastAPI routes when the server is started with authentication enabled (`--app-name basic-auth`) an…
New
|
CWE-305
Authentication Bypass by Primary Weakness
|
CVE-2026-2652
|
2026-05-15 23:56 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
440
|
- |
|
-
|
-
|
SzafirHost verifies the signature of the downloaded JAR file using class JarInputStream (reading from the beginning of the file), but loads classes using class JarFile/URLClassLoader (reading the Cen…
New
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2026-44088
|
2026-05-15 23:56 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|