|
5871
|
7.5 |
HIGH
Network
|
langgenius
|
dify
|
Dify version 1.14.1 and prior contain an authorization bypass vulnerability in the file preview endpoint that allows any authenticated user to read up to 3,000 characters of any uploaded document acr…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-41949
|
2026-05-20 03:50 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
5872
|
7.5 |
HIGH
Network
|
mozilla
|
firefox thunderbird
|
Incorrect boundary conditions in the Audio/Video: Web Codecs component. This vulnerability was fixed in Firefox 151, Firefox ESR 115.36, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2026-8946
|
2026-05-20 03:50 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
5873
|
7.3 |
HIGH
Network
|
mozilla
|
firefox thunderbird
|
Use-after-free in the DOM: Bindings (WebIDL) component. This vulnerability was fixed in Firefox 151, Firefox ESR 115.36, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.
|
CWE-416
Use After Free
|
CVE-2026-8947
|
2026-05-20 03:47 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
5874
|
9.6 |
CRITICAL
Network
|
mozilla
|
firefox thunderbird
|
Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 151, Firefox ESR 115.36, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140…
|
CWE-416
Use After Free
|
CVE-2026-8953
|
2026-05-20 03:45 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
5875
|
7.5 |
HIGH
Network
|
mozilla
|
firefox thunderbird
|
Incorrect boundary conditions, integer overflow in the Audio/Video component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2026-8954
|
2026-05-20 03:42 |
2026-05-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
5876
|
4.3 |
MEDIUM
Network
|
microsoft
|
365_apps office office_long_term_servicing_channel word
|
External control of file name or path in Microsoft Office Word allows an unauthorized attacker to disclose information over a network.
|
CWE-73
External Control of File Name or Path
|
CVE-2026-40421
|
2026-05-20 03:38 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
5877
|
7.8 |
HIGH
Local
|
microsoft
|
office office_long_term_servicing_channel
|
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
|
CWE-122
Heap-based Buffer Overflow
|
CVE-2026-42831
|
2026-05-20 03:38 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
5878
|
5.5 |
MEDIUM
Local
|
microsoft
|
excel office office_long_term_servicing_channel word
|
Improper access control in Microsoft Office allows an unauthorized attacker to perform spoofing locally.
|
CWE-284 NVD-CWE-noinfo
Improper Access Control
|
CVE-2026-42832
|
2026-05-20 03:38 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
5879
|
7.5 |
HIGH
Network
|
h2o
|
h2o
|
A vulnerability was identified in h2oai h2o-3 up to 7402. Affected by this issue is the function importFiles of the file h2o-core/src/main/java/water/persist/PersistNFS.java of the component ImportFi…
|
CWE-200 CWE-284 NVD-CWE-noinfo
Information Exposure Improper Access Control
|
CVE-2026-8750
|
2026-05-20 03:22 |
2026-05-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
5880
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Audiobookshelf is a self-hosted audiobook and podcast server. Prior to 2.32.2, the GET /api/libraries/:id/download endpoint validates that the requesting user has access to the library specified in t…
|
CWE-863
Incorrect Authorization
|
CVE-2026-42883
|
2026-05-20 03:19 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|