|
1131
|
3.1 |
LOW
Network
|
-
|
-
|
Due to improper input handling under certain conditions, SAP NetWeaver Application Server ABAP allows an attacker to inject custom Cascading Style Sheets (CSS) data into a web page served by the appl…
|
CWE-276
Incorrect Default Permissions
|
CVE-2026-27680
|
2026-05-15 23:11 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1132
|
- |
|
-
|
-
|
Timing limitations of the HRNG in RS9116 when power save mode is enabled results in predictable values
|
CWE-332
Insufficient Entropy in PRNG
|
CVE-2026-3290
|
2026-05-15 23:11 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1133
|
5.9 |
MEDIUM
Network
|
-
|
-
|
Stack exhaustion vulnerability in the MongoDB PHP driver can cause application crashes when processing deeply nested BSON documents in unusual circumstances when the source of these BSON documents is…
|
CWE-674
Uncontrolled Recursion
|
CVE-2026-6811
|
2026-05-15 23:11 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1134
|
- |
|
-
|
-
|
Improper input validation in Delphix Continuous Data connectors allows an authenticated user to execute arbitrary operating system commands on the staging or target host.
|
CWE-78
OS Command
|
CVE-2026-8654
|
2026-05-15 23:11 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1135
|
8.8 |
HIGH
Network
|
-
|
-
|
Crabbox prior to v0.12.0 contains an authentication bypass vulnerability that allows non-admin shared-token callers to impersonate other owners or organizations by spoofing identity headers. Attacker…
|
CWE-287
Improper Authentication
|
CVE-2026-8621
|
2026-05-15 23:11 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1136
|
8.1 |
HIGH
Network
|
-
|
-
|
Crabbox prior to v0.12.0 contains a privilege escalation vulnerability that allows users with shared visibility-only access to obtain Code, WebVNC, and Egress agent tickets by sending POST requests t…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-8629
|
2026-05-15 23:11 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1137
|
7.2 |
HIGH
Network
|
-
|
-
|
Missing integrity verification in the Triton inference handler in Amazon SageMaker Python SDK v2 before v2.257.2 and v3 before v3.8.0 might allow a remote authenticated actor to achieve code executio…
|
CWE-354
Improper Validation of Integrity Check Value
|
CVE-2026-8597
|
2026-05-15 23:10 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1138
|
7.2 |
HIGH
Network
|
-
|
-
|
Cleartext storage of sensitive information in the ModelBuilder/Serve component in Amazon SageMaker Python SDK before v2.257.2 and v3 before v3.8.0 might allow a remote authenticated actor to extract …
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2026-8596
|
2026-05-15 23:10 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1139
|
- |
|
-
|
-
|
Improper input validation in the AMD OverDrive (AOD) System Management Mode (SMM) module could allow a privileged attacker to perform an out-of-bounds read, potentially resulting in loss of confident…
|
CWE-1274
Improper Access Control for Volatile Memory Containing Boot Code
|
CVE-2024-36345
|
2026-05-15 23:10 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1140
|
- |
|
-
|
-
|
Improper Input validation in the AMD Secure Processor (ASP) PCI driver may allow a local attacker to create a buffer overflow condition, potentially resulting in a crash or denial of service
|
CWE-120
Classic Buffer Overflow
|
CVE-2025-0045
|
2026-05-15 23:10 |
2026-05-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|