|
1141
|
4.3 |
MEDIUM
Network
|
jenkins
|
azure_ad
|
Jenkins Microsoft Entra ID (previously Azure AD) Plugin 666.v6060de32f87d and earlier does not restrict the redirect URL after login, allowing attackers to perform phishing attacks.
|
CWE-601
Open Redirect
|
CVE-2026-42525
|
2026-05-5 23:25 |
2026-04-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1142
|
8.8 |
HIGH
Network
|
agilonhealth
|
minerva
|
An authorization vulnerability in MphRx's Minerva V3.6.0, specifically in the '/minerva/moUser/update' endpoint, could allow an authenticated user with user modification privileges to escalate their …
|
CWE-285
Improper Authorization
|
CVE-2026-5781
|
2026-05-5 23:24 |
2026-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1143
|
8.1 |
HIGH
Network
|
agilonhealth
|
minerva
|
An insecure direct object reference (IDOR) vulnerability in MphRx's Minerva V3.6.0, specifically in the endpoint '/minerva/moUser/show/'. If this vulnerability is successfully exploited, an authentic…
|
CWE-284
Improper Access Control
|
CVE-2026-5780
|
2026-05-5 23:22 |
2026-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1144
|
5.5 |
MEDIUM
Local
|
canonical
|
pdfunite
|
PDFunite 0.41.0 contains a buffer overflow vulnerability that allows local attackers to crash the application by processing malformed PDF files during merge operations. Attackers can trigger a segmen…
|
CWE-120
Classic Buffer Overflow
|
CVE-2018-25306
|
2026-05-5 23:22 |
2026-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1145
|
8.8 |
HIGH
Network
|
agilonhealth
|
minerva
|
An insecure direct object reference (IDOR) vulnerability in MphRx's Minerva V3.6.0, specifically in the '/minerva/user/updateUserProfile' endpoint. This allows an authenticated user to modify the inf…
|
CWE-284
Improper Access Control
|
CVE-2026-5779
|
2026-05-5 23:20 |
2026-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1146
|
9.8 |
CRITICAL
Network
|
-
|
-
|
A security vulnerability has been detected in EFM ipTIME NAS1dual 1.5.24. This issue affects the function get_csrf_whites of the file /cgi/advanced/misc_main.cgi. Such manipulation leads to stack-bas…
|
CWE-119 CWE-121
Incorrect Access of Indexable Resource ('Range Error') Stack-based Buffer Overflow
|
CVE-2026-7834
|
2026-05-5 23:16 |
2026-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1147
|
- |
|
-
|
-
|
In Eclipse Open9J versions 0.21 to 0.58, a pre-authentication remote attacker can crash JITServer by sending a 32-byte crafted TCP message.
|
CWE-125
Out-of-bounds Read
|
CVE-2026-6918
|
2026-05-5 23:16 |
2026-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1148
|
7.5 |
HIGH
Network
|
-
|
-
|
The WeePie Cookie Allow plugin for WordPress is vulnerable to SQL Injection via the 'consent' parameter in all versions up to, and including, 3.4.11 due to insufficient escaping on the user supplied …
|
CWE-89
SQL Injection
|
CVE-2026-4304
|
2026-05-5 23:16 |
2026-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1149
|
4.4 |
MEDIUM
Local
|
mercurycom
|
mipc252w_firmware
|
A handling issue in the RTSP service of the Mercury MIPC252W 1.0.5 Build 230306 Rel.79931n allows an authenticated attacker to trigger session termination by repeatedly sending SETUP requests for the…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2026-35901
|
2026-05-5 22:41 |
2026-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1150
|
6.2 |
MEDIUM
Local
|
mercurycom
|
mipc252w_firmware
|
The RTSP service of MERCURY IP camera MIPC252W 1.0.5 Build 230306 has an issue handling failed Digest authentication attempts. By repeatedly sending RTSP requests with invalid authentication paramete…
|
CWE-307
mproper Restriction of Excessive Authentication Attempts
|
CVE-2026-35902
|
2026-05-5 22:40 |
2026-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|