|
21
|
9.1 |
CRITICAL
Network
|
-
|
-
|
An issue was discovered in Gambio 4.9.2.0 (patched in 2024-02 v1.0.0 for GX4 v4.0.0.0 to v4.9.2.0). The password reset function can be bypassed to set arbitrary passwords for arbitrary accounts if th…
New
|
CWE-640
Weak Password Recovery Mechanism for Forgotten Password
|
CVE-2026-34408
|
2026-05-7 03:16 |
2026-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
22
|
- |
|
-
|
-
|
In versions 3.0.0a1 through 3.2.0 of Mistune, there is a ReDoS (Regular Expression Denial of Service) vulnerability in `LINK_TITLE_RE` that allows an attacker who can supply Markdown for parsing to c…
New
|
CWE-1333
Inefficient Regular Expression Complexity
|
CVE-2026-33079
|
2026-05-7 03:16 |
2026-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
23
|
- |
|
-
|
-
|
### Summary
A SQL injection vulnerability exists in Rucio versions 1.30.0 and later before 35.8.5, 38.5.5, 39.4.2, and 40.1.1, in `FilterEngine.create_postgres_query()`. This allows any authenticate…
New
|
CWE-89
SQL Injection
|
CVE-2026-29090
|
2026-05-7 03:16 |
2026-05-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
24
|
7.5 |
HIGH
Network
|
-
|
-
|
An issue was discovered in MM in Samsung Mobile Processor, Wearable Processor, and Modem Exynos 980, 990, 850, 2100, 1280, 2200, 1330, 1380, 1480, 2400, 1580, 2500, W920, W930, W1000, Modem 5123, Mod…
New
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2025-66369
|
2026-05-7 03:16 |
2026-05-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
25
|
8.1 |
HIGH
Network
|
dlink
|
m60_firmware
|
A vulnerability was determined in D-Link M60 up to 1.20B02. Affected by this issue is some unknown functionality of the file /usr/bin/httpd. This manipulation causes weak password recovery. The attac…
Update
|
CWE-640
Weak Password Recovery Mechanism for Forgotten Password
|
CVE-2026-7554
|
2026-05-7 03:10 |
2026-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
26
|
7.5 |
HIGH
Network
|
apache
|
opennlp
|
OOM Denial of Service via Unbounded Array Allocation in Apache OpenNLP AbstractModelReader
Versions Affected:
before 2.5.9
before 3.0.0-M3
Description:
The AbstractModelReader methods getOut…
New
|
CWE-789
Memory Allocation with Excessive Size Value
|
CVE-2026-42440
|
2026-05-7 03:09 |
2026-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
27
|
7.5 |
HIGH
Network
|
n8n
|
n8n
|
n8n is an open source workflow automation platform. Prior to versions 1.123.33 and 2.17.5, the dynamic-node-parameters endpoints did not verify whether the authenticated caller was authorized to use …
New
|
CWE-862
Missing Authorization
|
CVE-2026-42226
|
2026-05-7 03:09 |
2026-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
28
|
6.5 |
MEDIUM
Network
|
n8n
|
n8n
|
n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, an authenticated user with a valid API key scoped to variable:list could read variables from projec…
New
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-42227
|
2026-05-7 03:08 |
2026-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
29
|
6.5 |
MEDIUM
Network
|
n8n
|
n8n
|
n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, the /chat WebSocket endpoint used by the Chat Trigger node's Hosted Chat feature did not verify tha…
New
|
CWE-862
Missing Authorization
|
CVE-2026-42228
|
2026-05-7 03:08 |
2026-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
30
|
9.8 |
CRITICAL
Network
|
n8n
|
n8n
|
n8n is an open source workflow automation platform. Prior to versions 1.123.32, 2.17.4, and 2.18.1, a flaw in the Oracle Database node's select operation allowed user-controlled input passed into the…
New
|
CWE-89
SQL Injection
|
CVE-2026-42233
|
2026-05-7 03:07 |
2026-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|