|
461
|
2.4 |
LOW
Physics
|
-
|
-
|
SailingLab AppLock (aka com.alpha.applock) 4.3.8 for Android allows a local attacker with physical access to bypass the PIN lock. The lock is implemented as an overlay rather than by using Android's …
New
|
CWE-288
Authentication Bypass Using an Alternate Path or Channel
|
CVE-2025-68708
|
2026-05-28 06:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
462
|
6.5 |
MEDIUM
Network
|
gitlab
|
gitlab
|
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.1 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.0.1 that under certain conditions could have allowed an authen…
New
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2026-1402
|
2026-05-28 05:53 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
463
|
4.3 |
MEDIUM
Network
|
gitlab
|
gitlab
|
GitLab has remediated an issue in GitLab EE affecting all versions from 11.5 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.0.1 that under certain conditions could have allowed an authentic…
New
|
CWE-862
Missing Authorization
|
CVE-2026-2601
|
2026-05-28 05:53 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
464
|
8.2 |
HIGH
Network
|
gitlab
|
gitlab
|
GitLab has remediated an issue in GitLab EE affecting all versions from 18.8 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.0.1 that, under certain conditions, could have allowed an authent…
New
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-4868
|
2026-05-28 05:47 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
465
|
4.3 |
MEDIUM
Network
|
gitlab
|
gitlab
|
GitLab has remediated an issue in GitLab EE affecting all versions from 18.7 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.0.1 that when foundational flows were enabled at the group level,…
New
|
CWE-862
Missing Authorization
|
CVE-2026-5296
|
2026-05-28 05:46 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
466
|
5.3 |
MEDIUM
Network
|
gitlab
|
gitlab
|
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.2 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.0.1 that under certain conditions could have allowed an unauth…
New
|
CWE-863
Incorrect Authorization
|
CVE-2026-6713
|
2026-05-28 05:46 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
467
|
4.3 |
MEDIUM
Network
|
gitlab
|
gitlab
|
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.7 before 18.10.7, 18.11 before 18.11.4, and 19.0 before 19.0.1 that under certain conditions could have allowed an authen…
New
|
CWE-706
Use of Incorrectly-Resolved Name or Reference
|
CVE-2026-8716
|
2026-05-28 05:45 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
468
|
5.5 |
MEDIUM
Local
|
-
|
-
|
ROHC protocol dissector crash in Wireshark 4.6.0 to 4.6.5 and 4.4.0 to 4.4.15 allows denial of service
New
|
CWE-476
NULL Pointer Dereference
|
CVE-2026-9759
|
2026-05-28 05:16 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
469
|
7.1 |
HIGH
Network
|
-
|
-
|
LangSmith Client SDKs provide SDK's for interacting with the LangSmith platform. Prior to LangSmith SDK Python 0.8.0 and JS/TS 0.6.0, the LangSmith SDK's prompt pull methods (pull_prompt / pull_promp…
New
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-45134
|
2026-05-28 05:16 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
470
|
8.4 |
HIGH
Network
|
-
|
-
|
Himmelblau is an interoperability suite for Microsoft Azure Entra ID and Intune. From 2.0.0 to before 3.1.5 and 2.3.11, Himmelblau contained an authentication bypass vulnerability in the Device Autho…
New
|
CWE-863
Incorrect Authorization
|
CVE-2026-45108
|
2026-05-28 05:16 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|