|
2881
|
7.8 |
HIGH
Local
|
microsoft
|
365_apps office office_long_term_servicing_channel
|
Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally.
|
CWE-416
Use After Free
|
CVE-2026-40419
|
2026-05-20 03:04 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2882
|
8.8 |
HIGH
Local
|
microsoft
|
365_apps office office_long_term_servicing_channel
|
Improper access control in Microsoft Office Click-To-Run allows an authorized attacker to elevate privileges locally.
|
CWE-284
Improper Access Control
|
CVE-2026-40420
|
2026-05-20 03:04 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2883
|
5.3 |
MEDIUM
Local
|
-
|
-
|
An issue was discovered in the Portrait Dell Color Management application before 3.7.0 for Dell monitors. On Windows, a symbolic link vulnerability allows a local low-privileged user to escalate priv…
|
CWE-59
Link Following
|
CVE-2026-34883
|
2026-05-20 03:04 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2884
|
7.3 |
HIGH
Network
|
-
|
-
|
An issue was discovered in ModelScope 1.25.0 allowing attackers to execute arbitrary code via crafted module listed in the configuration file (dey_mini.yaml) under the key ['nnet']['module'].
|
CWE-94
Code Injection
|
CVE-2025-51427
|
2026-05-20 03:04 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2885
|
7.3 |
HIGH
Network
|
-
|
-
|
An issue in gohttp commit 34ea51 allows attackers to execute a directory traversal via supplying a crafted request.
|
CWE-22
Path Traversal
|
CVE-2025-70950
|
2026-05-20 03:04 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2886
|
- |
|
-
|
-
|
A command injection vulnerability exists in Panabit PAP-XM320 up to and including V7.7. The web management interface invokes the backend helper /usr/sbin/pappiw and passes user-controlled parameters …
|
-
|
CVE-2026-36827
|
2026-05-20 03:04 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2887
|
- |
|
-
|
-
|
A command injection vulnerability exists in the /cgi-bin/tools/ajax_cmd endpoint of Panabit PAP-XM320 up to and including v7.7. The CGI component allows authenticated users to execute arbitrary shell…
|
-
|
CVE-2026-36828
|
2026-05-20 03:04 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2888
|
- |
|
-
|
-
|
In the web management interface of Archer AX72 (SG) v1, the network diagnostic feature improperly handles invalid user input, resulting in limited exposure of diagnostic command usage information.
…
|
CWE-209
Information Exposure Through an Error Message
|
CVE-2026-5511
|
2026-05-20 02:59 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2889
|
7.5 |
HIGH
Network
|
-
|
-
|
HestiaCP versions 1.2.0 through 1.9.4 contain an IP spoofing vulnerability that allows unauthenticated remote attackers to bypass authentication security controls by supplying an arbitrary IP address…
|
CWE-348
Use of Less Trusted Source
|
CVE-2026-43634
|
2026-05-20 02:57 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2890
|
7.5 |
HIGH
Network
|
-
|
-
|
Funnel Builder for WooCommerce Checkout prior to 3.15.0.3 contains a missing authorization vulnerability in the public checkout endpoint that allows unauthenticated attackers to invoke internal metho…
|
CWE-862
Missing Authorization
|
CVE-2026-47100
|
2026-05-20 02:57 |
2026-05-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|