|
1251
|
9.8 |
CRITICAL
Network
|
apache
|
tomcat
|
DEPRECATED: Authentication Bypass Issues vulnerability in digest authentication in Apache Tomcat.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, fr…
|
CWE-592
DEPRECATED: Authentication Bypass Issues
|
CVE-2026-43512
|
2026-05-16 00:54 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1252
|
7.5 |
HIGH
Network
|
espressif
|
arduino-esp32
|
arduino-esp32 is an Arduino core for the ESP32, ESP32-S2, ESP32-S3, ESP32-C3, ESP32-C6 and ESP32-H2 microcontrollers. Prior to 3.3.8, the WebServer Digest authentication implementation in arduino-esp…
|
CWE-287 NVD-CWE-noinfo
Improper Authentication
|
CVE-2026-42855
|
2026-05-16 00:54 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1253
|
7.5 |
HIGH
Network
|
apache
|
tomcat
|
Improper Handling of Case Sensitivity vulnerability in LockOutRealm in Apache Tomcat.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21, from 10.1.0-M1 through 10.1.54, from 9.0.0.M1 …
|
CWE-178
Improper Handling of Case Sensitivity
|
CVE-2026-43513
|
2026-05-16 00:53 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1254
|
9.1 |
CRITICAL
Network
|
apache
|
tomcat
|
Improper Authorization vulnerability when multiple method constraints define an HTTP method for the same extension in Apache Tomcat.
This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.21,…
|
CWE-285
Improper Authorization
|
CVE-2026-43515
|
2026-05-16 00:52 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1255
|
8.8 |
HIGH
Network
|
arubanetworks
|
arubaos sd-wan
|
Command injection vulnerabilities exist in the web-based management interface of AOS-8 and AOS-10 Operating Systems. Successful exploitation of these vulnerabilities could allow an authenticated remo…
|
CWE-77
Command Injection
|
CVE-2026-44866
|
2026-05-16 00:49 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1256
|
5.9 |
MEDIUM
Network
|
vercel
|
next.js
|
Next.js is a React framework for building full-stack web applications. From 12.2.0 to before 15.5.16 and 16.2.5, an external client could send a x-nextjs-data header on a normal request to a path han…
|
CWE-349
Acceptance of Extraneous Untrusted Data With Trusted Data
|
CVE-2026-44572
|
2026-05-16 00:46 |
2026-05-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1257
|
7.8 |
HIGH
Local
|
microsoft
|
windows_10_21h2 windows_10_22h2 windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2022 windows_server_2022_23h2 windows_server_2025
|
External control of file name or path in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
|
CWE-73
External Control of File Name or Path
|
CVE-2026-41088
|
2026-05-16 00:45 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1258
|
9.8 |
CRITICAL
Network
|
microsoft
|
windows_server_2012 windows_server_2016 windows_server_2019 windows_server_2022 windows_server_2022_23h2 windows_server_2025
|
Stack-based buffer overflow in Windows Netlogon allows an unauthorized attacker to execute code over a network.
|
CWE-121
Stack-based Buffer Overflow
|
CVE-2026-41089
|
2026-05-16 00:42 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1259
|
7.8 |
HIGH
Local
|
microsoft
|
windows_server_2012 windows_server_2016 windows_server_2019 windows_server_2022 windows_server_2022_23h2 windows_server_2025
|
Use after free in Data Deduplication allows an authorized attacker to elevate privileges locally.
|
CWE-416
Use After Free
|
CVE-2026-41095
|
2026-05-16 00:40 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1260
|
9.8 |
CRITICAL
Network
|
microsoft
|
windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2022_23h2 windows_server_2025
|
Heap-based buffer overflow in Microsoft Windows DNS allows an unauthorized attacker to execute code over a network.
|
CWE-122
Heap-based Buffer Overflow
|
CVE-2026-41096
|
2026-05-16 00:38 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|