|
1181
|
9.8 |
CRITICAL
Network
|
-
|
-
|
IBM Engineering Lifecycle Management 7.0.3, 7.1.0, and 7.2.0 could allow an unauthenticated remote attacker to update server property files that would allow them to gain unauthorized access to the ap…
New
|
CWE-863
Incorrect Authorization
|
CVE-2026-3660
|
2026-05-27 06:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1182
|
5.4 |
MEDIUM
Network
|
snipeitapp
|
snipe-it
|
Snipe-IT is an IT asset/license management system. Prior to 8.4.1, users with component view access could be impacted by an unescaped notes column, resulting in cross-site scripting (XSS). This vulne…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-44831
|
2026-05-27 05:39 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1183
|
8.8 |
HIGH
Network
|
snipeitapp
|
snipe-it
|
Snipe-IT is an IT asset/license management system. Prior to 8.4.1, aAn authenticated user with only users.edit permission can escalate their own privileges to admin by sending a PATCH request to /api…
New
|
CWE-281 CWE-863
Improper Preservation of Permissions Incorrect Authorization
|
CVE-2026-44832
|
2026-05-27 05:38 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1184
|
7.1 |
HIGH
Network
|
snipeitapp
|
snipe-it
|
Snipe-IT is an IT asset/license management system. Prior to 8.4.1, an open redirect vulnerability in Snipe-IT allows attackers to redirect users to malicious sites via unvalidated HTTP Referer header…
New
|
CWE-601
Open Redirect
|
CVE-2026-44833
|
2026-05-27 05:38 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1185
|
4.8 |
MEDIUM
Network
|
powerdns
|
authoritative
|
Incorrect Behaviour of Views with TCP PROXY Requests
Update
|
CWE-284
Improper Access Control
|
CVE-2026-41999
|
2026-05-27 05:32 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1186
|
6.1 |
MEDIUM
Network
|
-
|
-
|
Devise is an authentication solution for Rails based on Warden. In versions 5.0.3 and below, when the Timeoutable module is enabled in Devise, the FailureApp#redirect_url method returns request.refer…
New
|
CWE-601
Open Redirect
|
CVE-2026-40295
|
2026-05-27 05:24 |
2026-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1187
|
8.1 |
HIGH
Local
|
-
|
-
|
Insertion of Sensitive Information into Log File (CWE-532) in some Command Centre Service installers could lead to Service Account credentials exposure.
Mitigating Factor: Only sites that install Co…
New
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2026-25193
|
2026-05-27 05:24 |
2026-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1188
|
6.6 |
MEDIUM
Network
|
-
|
-
|
SQL Injection affecting the Access Manager role.
New
|
CWE-89
SQL Injection
|
CVE-2026-27768
|
2026-05-27 05:24 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1189
|
7.5 |
HIGH
Network
|
-
|
-
|
In GNU SASL before 2.2.3, DIGEST-MD5 has a NULL pointer dereference affecting both clients and servers, via a known token with no accompanying = character. This occurs in lib/digest-md5/getsubopt.c.
New
|
CWE-476
NULL Pointer Dereference
|
CVE-2026-48829
|
2026-05-27 05:19 |
2026-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1190
|
- |
|
-
|
-
|
Wine ships a .desktop file that registers itself as a MIME handler for EXE files and several other Windows executable file types. In some configurations, handling of an EXE file causes that file to b…
New
|
CWE-669
Incorrect Resource Transfer Between Spheres
|
CVE-2026-48831
|
2026-05-27 05:19 |
2026-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|