|
4601
|
9.8 |
CRITICAL
Network
|
-
|
-
|
The MoreConvert Pro plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.9.14. This is due to the guest waitlist verification flow not invalidating or r…
|
CWE-287
Improper Authentication
|
CVE-2026-5722
|
2026-05-5 11:16 |
2026-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4602
|
5.4 |
MEDIUM
Network
|
-
|
-
|
@diplodoc/search-extension 1.0.0 through 3.x before 3.0.3 allows stored XSS via the title in a .md file.
|
CWE-79
Cross-site Scripting
|
CVE-2026-40201
|
2026-05-5 11:16 |
2026-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4603
|
7.5 |
HIGH
Network
|
mercurycom
|
mipc252w_firmware
|
A null pointer dereference vulnerability exists in the RTSP service of the MERCURY MIPC252W 1.0.5 Build 230306 Rel.79931n. During the processing of a SETUP request for the path rtsp://<IP>:554/stream…
|
CWE-476
NULL Pointer Dereference
|
CVE-2026-31256
|
2026-05-5 10:30 |
2026-04-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4604
|
5.3 |
MEDIUM
Network
|
-
|
-
|
An issue was discovered in Nix before 2.34.7. Writing to arbitrary files can occur via "nix-prefetch-url --unpack" or "nix store prefetch-file --unpack" directory traversal. The fixed versions are 2.…
|
CWE-36
Absolute Path Traversal
|
CVE-2026-44029
|
2026-05-5 10:16 |
2026-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4605
|
5.4 |
MEDIUM
Network
|
wolterskluwer
|
lex_baza_dokumentow
|
LEX Baza Dokumentów is vulnerable to DOM-based XSS in "em" cookie parameter. The application unsafely
processes the parameter on the client side, allowing an attacker to execute arbitrary
JavaScript …
|
CWE-79
Cross-site Scripting
|
CVE-2026-1493
|
2026-05-5 09:30 |
2026-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4606
|
7.5 |
HIGH
Network
|
jetbrains
|
intellij_idea
|
In JetBrains IntelliJ IDEA before 2024.3.7.1,
2025.1.7.1,
2025.2.6.2,
2025.3.4.1,
2026.1.1 reading arbitrary local files was possible via built-in web server
|
CWE-59
Link Following
|
CVE-2026-41882
|
2026-05-5 09:24 |
2026-04-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4607
|
7.8 |
HIGH
Local
|
ibm
|
turbonomic_prometurbo_agent
|
IBM Turbonomic prometurbo agent 8.16.0 through 8.17.6 IBM Turbonomic Application Resource Management grants excessive cluster‑wide permissions, including unrestricted read access to all secrets. An a…
|
CWE-269 NVD-CWE-noinfo
Improper Privilege Management
|
CVE-2026-6389
|
2026-05-5 09:17 |
2026-05-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4608
|
7.3 |
HIGH
Network
|
-
|
-
|
A security flaw has been discovered in Axle-Bucamp MCP-Docusaurus up to 404bc028e15ec304c9a045528560f4b5f27a17e0. The affected element is the function update_document/continue_document/delete_documen…
|
CWE-22
Path Traversal
|
CVE-2026-7788
|
2026-05-5 09:16 |
2026-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4609
|
7.3 |
HIGH
Network
|
-
|
-
|
A security flaw has been discovered in A-G-U-P-T-A wireshark-mcp edaf604416fbc94a201b4043092d4a1b09a12275/400c3da70074f22f3cce7ccb65304cafc7089c89. This affects the function quick_capture of the file…
|
CWE-77 CWE-78
Command Injection OS Command
|
CVE-2026-7785
|
2026-05-5 09:16 |
2026-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4610
|
7.3 |
HIGH
Network
|
-
|
-
|
A vulnerability has been found in RTGS2017 NagaAgent up to 5.1.0. This issue affects some unknown processing of the file apiserver/routes/extensions.py of the component Skills Endpoint. Such manipula…
|
CWE-22
Path Traversal
|
CVE-2026-7784
|
2026-05-5 09:16 |
2026-05-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|