|
551
|
9.9 |
CRITICAL
Network
|
yhirose
|
cpp-httplib
|
cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.44.0, when cpp-httplib's server parses an incoming request, it applies percent-decoding to every header va…
Update
|
CWE-93 CWE-444
CRLF Injection HTTP Request Smuggling
|
CVE-2026-45372
|
2026-06-2 03:34 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
552
|
8.2 |
HIGH
Network
|
-
|
-
|
Espressif Shared GitHub DangerJS is a reusable GitHub Action CI DangerJS workflow for Espressif GitHub projects. Prior to 1.0.1, the action's entrypoint.sh invoked DangerJS from the caller's workspac…
Update
|
CWE-427 CWE-829
Uncontrolled Search Path Element Inclusion of Functionality from Untrusted Control Sphere
|
CVE-2026-44358
|
2026-06-2 03:33 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
553
|
8.7 |
HIGH
Network
|
-
|
-
|
Local Path Provisioner provides a way for the Kubernetes users to utilize the local storage in each node. Prior to 0.0.36, a malicious user with permission to edit the local-path-config ConfigMap in …
Update
|
CWE-269
Improper Privilege Management
|
CVE-2026-44543
|
2026-06-2 03:33 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
554
|
7.4 |
HIGH
Network
|
-
|
-
|
FileRise is a self-hosted web-based file manager with multi-file upload, editing, and batch operations. Prior to 3.12.0, /api/totp_setup.php is callable from a session that has only passed the passwo…
Update
|
CWE-200 CWE-287 CWE-306
Information Exposure Improper Authentication Missing Authentication for Critical Function
|
CVE-2026-44460
|
2026-06-2 03:33 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
555
|
- |
|
-
|
-
|
mapfish-print is a component of MapFish for printing templated cartographic maps. From 3.23.0 to before 3.28.28, 3.30.30, 3.31.22, 3.33.14, and 4.0.3, the attacker can execute arbitrary code in Dyna…
Update
|
CWE-94
Code Injection
|
CVE-2026-44672
|
2026-06-2 03:33 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
556
|
5.9 |
MEDIUM
Network
|
github
|
enterprise_server
|
A Server-Side Request Forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an attacker to cause the server to issue HTTP requests to internal services via the security…
Update
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-8606
|
2026-06-2 03:33 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
557
|
7.5 |
HIGH
Network
|
yhirose
|
cpp-httplib
|
cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.44.0, When the server has called Server::set_trusted_proxies() with a non-empty trusted-proxy list, an att…
Update
|
CWE-476
NULL Pointer Dereference
|
CVE-2026-46527
|
2026-06-2 03:32 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
558
|
- |
|
-
|
-
|
RELATE is a web-based courseware package. Prior to commit d66ba5659b459bf1ba56b7109b5f9ecf197cbefb, RELATE LMS configures its Celery workers to accept and deserialize untrusted 'pickle' data. An atta…
Update
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-47161
|
2026-06-2 03:31 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
559
|
8.2 |
HIGH
Network
|
-
|
-
|
RVF (formerly Remix Validated Form) provides easy form validation and state management for React. From 6.0.0 to before 6.0.4 and 7.0.2, setPath in @rvf/set-get (used by @rvf/core to flatten incoming …
Update
|
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
|
CVE-2026-44483
|
2026-06-2 03:31 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
560
|
7.5 |
HIGH
Network
|
-
|
-
|
Kysely is a type-safe TypeScript SQL query builder. From 0.26.0 to 0.28.16, DefaultQueryCompiler.visitJSONPathLeg does not escape JSON-path metacharacters (., [, ], *, **, ?). When attacker-controlle…
Update
|
CWE-22 CWE-89 CWE-915 CWE-1284
Path Traversal SQL Injection Improperly Controlled Modification of Dynamically-Determined Object Attributes Improper Validation of Specified Quantity in Input
|
CVE-2026-44635
|
2026-06-2 03:31 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|