|
531
|
6.2 |
MEDIUM
Local
|
-
|
-
|
go-ipld-prime is an implementation of the InterPlanetary Linked Data (IPLD) spec interfaces, a batteries-included codec implementations of IPLD for CBOR and JSON, and tooling for basic operations on …
New
|
CWE-674
Uncontrolled Recursion
|
CVE-2026-42328
|
2026-05-28 03:16 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
532
|
7.8 |
HIGH
Local
|
-
|
-
|
Command injection in Raynet rvia version 12.6.4392.49-amd64.deb allows adversaries to execute arbitrary Java code via a crafted path that matches the improperly terminated search criteria of rvia's J…
New
|
CWE-77
Command Injection
|
CVE-2026-38945
|
2026-05-28 03:16 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
533
|
4.3 |
MEDIUM
Network
|
-
|
-
|
PbootCMS v.3.2.11 contains a code injection vulnerability in its site configuration functionality
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-36239
|
2026-05-28 03:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
534
|
5.2 |
MEDIUM
Adjacent
|
-
|
-
|
SailingLab AppLock (aka com.alpha.applock) 4.3.8 for Android allows a local attacker to trigger arbitrary JavaScript execution via BrowserMainActivity, which accepts VIEW intents with javascript: URI…
New
|
CWE-79
Cross-site Scripting
|
CVE-2025-68709
|
2026-05-28 03:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
535
|
- |
|
-
|
-
|
Northern.tech Mender Client 5 before 5.0.4 allows a Cryptographic signature verification bypass.
New
|
-
|
CVE-2025-67903
|
2026-05-28 03:16 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
536
|
9.8 |
CRITICAL
Network
|
ibm
|
websphere_application_server
|
IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty 8.5, 9.0 IBM WebSphere Application Server and WebSphere Application Server Liberty are vulnerable to remote code executi…
New
|
CWE-94
Code Injection
|
CVE-2026-8633
|
2026-05-28 03:12 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
537
|
7.8 |
HIGH
Local
|
openvpn
|
connect
|
Privilege escalation via background service of OpenVPN Connect 3.5.1 through 3.8.1 on macOS allows attackers to execute arbitrary commands with elevated privileges via local IPC channel
New
|
CWE-78 CWE-267 CWE-270 CWE-648
OS Command Privilege Defined With Unsafe Actions Privilege Context Switching Error Incorrect Use of Privileged APIs
|
CVE-2026-9560
|
2026-05-28 03:08 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
538
|
4.3 |
MEDIUM
Network
|
-
|
-
|
Missing Authorization vulnerability in Mamunur Rashid The Post Grid allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects The Post Grid: from n/a through 7.9.2.
New
|
CWE-862
Missing Authorization
|
CVE-2026-49054
|
2026-05-28 02:44 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
539
|
9.1 |
CRITICAL
Network
|
-
|
-
|
HTTP::Daemon versions before 6.17 for Perl allow OS command injection via send_file().
send_file() opens its string argument with Perl's 2-arg open(). The 2-arg form interprets magic prefixes: '| cm…
New
|
CWE-73 CWE-78
External Control of File Name or Path OS Command
|
CVE-2026-8450
|
2026-05-28 02:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
540
|
4.8 |
MEDIUM
Adjacent
|
-
|
-
|
IBM WebSphere Application Server - Liberty 19.0.0.7 through 26.0.0.5 and IBM WebSphere Application Server 9.0, and 8.5 and WebSphere Application Server Liberty are vulnerable to a denial of service, …
New
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2026-4410
|
2026-05-28 02:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|