Aggregator
CVE-2026-48921 | Groovy Libraries Plugin up to 797.v90ea_a_9b_e45a_0 on Jenkins Symbolic Links information disclosure (EUVD-2026-32512)
3 days ago
A vulnerability classified as problematic was found in Groovy Libraries Plugin up to 797.v90ea_a_9b_e45a_0 on Jenkins. This impacts an unknown function of the component Symbolic Links Handler. The manipulation results in information disclosure.
This vulnerability was named CVE-2026-48921. The attack needs to be approached within the local network. There is no available exploit.
vuldb.com
CVE-2026-45719 | budibase up to 3.38.0 Request Body /api/views SCHEMA_MAP code injection (EUVD-2026-32599)
3 days ago
A vulnerability identified as critical has been detected in budibase up to 3.38.0. This affects an unknown function of the file /api/views of the component Request Body Handler. The manipulation of the argument SCHEMA_MAP leads to code injection.
This vulnerability is listed as CVE-2026-45719. The attack may be initiated remotely. There is no available exploit.
You should upgrade the affected component.
vuldb.com
CVE-2026-48152 | budibase up to 3.38.x Placeholder mergeConfigs authorization (EUVD-2026-32588)
3 days ago
A vulnerability classified as critical was found in budibase up to 3.38.x. This affects the function mergeConfigs of the component Placeholder Handler. Executing a manipulation can lead to incorrect authorization.
This vulnerability appears as CVE-2026-48152. The attack may be performed from remote. There is no available exploit.
Upgrading the affected component is advised.
vuldb.com
CVE-2026-42877 | NeoRazorX facturascripts up to 2025.92 Warehouse SalesModalHTML.php cross site scripting (EUVD-2026-32630)
3 days ago
A vulnerability classified as problematic has been found in NeoRazorX facturascripts up to 2025.92. The impacted element is an unknown function in the library Core/Lib/AjaxForms/SalesModalHTML.php of the component Warehouse Module. This manipulation causes cross site scripting.
This vulnerability is registered as CVE-2026-42877. Remote exploitation of the attack is possible. No exploit is available.
vuldb.com
CVE-2026-45104 | MapServer up to 8.6.2 array index (EUVD-2026-32631)
3 days ago
A vulnerability categorized as problematic has been discovered in MapServer up to 8.6.2. Impacted is an unknown function. Executing a manipulation can lead to improper validation of array index.
The identification of this vulnerability is CVE-2026-45104. The attack may be launched remotely. There is no exploit available.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2026-44330 | Free5GC up to 4.2.1 authorization (EUVD-2026-32568)
3 days ago
A vulnerability was found in Free5GC up to 4.2.1 and classified as critical. This affects an unknown function. Such manipulation leads to incorrect authorization.
This vulnerability is referenced as CVE-2026-44330. It is possible to launch the attack remotely. No exploit is available.
It is suggested to upgrade the affected component.
vuldb.com
CVE-2026-44483 | airjp73 rvf up to 6.0.3/7.0.1 prototype pollution (EUVD-2026-32564)
3 days ago
A vulnerability was found in airjp73 rvf up to 6.0.3/7.0.1. It has been rated as critical. This vulnerability affects unknown code. This manipulation causes improperly controlled modification of object prototype attributes.
This vulnerability is tracked as CVE-2026-44483. The attack is possible to be carried out remotely. No exploit exists.
Upgrading the affected component is advised.
vuldb.com
CVE-2026-45102 | oneuptime up to 10.0.97 protection mechanism (EUVD-2026-32632)
3 days ago
A vulnerability classified as critical was found in oneuptime up to 10.0.97. This affects an unknown function. Such manipulation leads to protection mechanism failure.
This vulnerability is documented as CVE-2026-45102. The attack can be executed remotely. There is not any exploit available.
Upgrading the affected component is advised.
vuldb.com
CVE-2026-45108 | himmelblau-idm himmelblau up to 2.3.10/3.1.4 authorization (EUVD-2026-32633)
3 days ago
A vulnerability categorized as problematic has been discovered in himmelblau-idm himmelblau up to 2.3.10/3.1.4. This affects an unknown part. Such manipulation leads to incorrect authorization.
This vulnerability is referenced as CVE-2026-45108. The attack can only be performed from a local environment. No exploit is available.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2026-45046 | safedep gryph up to 0.6.x Logging Level improper removal of sensitive information before storage or transfer (GHSA-f3jg-756w-gm35 / EUVD-2026-32624)
3 days ago
A vulnerability was found in safedep gryph up to 0.6.x. It has been classified as problematic. This affects an unknown part of the component Logging Level Handler. This manipulation causes improper removal of sensitive information before storage or transfer.
This vulnerability is handled as CVE-2026-45046. It is possible to launch the attack on the local host. There is not any exploit available.
Upgrading the affected component is recommended.
vuldb.com
CVE-2026-44888 | leiweibau Pi.Alert prior 2026-05-07 Installation SaveConfigFile code injection (EUVD-2026-32634)
3 days ago
A vulnerability identified as critical has been detected in leiweibau Pi.Alert. This vulnerability affects the function SaveConfigFile of the component Installation Handler. Performing a manipulation results in code injection.
This vulnerability is identified as CVE-2026-44888. The attack can be initiated remotely. There is not any exploit available.
You should upgrade the affected component.
vuldb.com
谷歌员工被控在Polymarket进行内幕交易
3 days ago
谷歌员工被控在Polymarket进行内幕交易美国检方称,一名谷歌软件工程师涉嫌通过在预测平台Polymarket上非法交易合约赚取了120万美元。这些合约允许用户押注“2025年搜索量最高的人物”会
Claude Code更新到最新版后无法使用DS系列模型 与A社调整扩展思考模式有关
3 days ago
CVE-2026-4795 | Zyxel GS1200-10v3 HTTP Request authorization (EUVD-2026-31779 / CNNVD-202605-5381)
3 days 1 hour ago
A vulnerability classified as problematic has been found in Zyxel GS1200-5v3, GS1200-8v3, GS1200-5HPv3, GS1200-8HPv3 and GS1200-10v3. Affected is an unknown function of the component HTTP Request Handler. Performing a manipulation results in missing authorization.
This vulnerability is known as CVE-2026-4795. Access to the local network is required for this attack. No exploit is available.
vuldb.com
CVE-2026-42496 | BINGOS Archive::Tar up to 3.07 on Perl File Extraction _make_special_file link following (EUVD-2026-31774 / Nessus ID 316868)
3 days 1 hour ago
A vulnerability classified as critical was found in BINGOS Archive::Tar up to 3.07 on Perl. Affected by this vulnerability is the function _make_special_file of the component File Extraction Handler. Executing a manipulation can lead to link following.
This vulnerability is handled as CVE-2026-42496. The attack can be executed remotely. There is not any exploit available.
Upgrading the affected component is advised.
vuldb.com
CVE-2026-42497 | BINGOS Archive::Tar up to 3.07 on Perl _make_special_file link following (EUVD-2026-31777 / CNNVD-202605-5382)
3 days 1 hour ago
A vulnerability, which was classified as critical, has been found in BINGOS Archive::Tar up to 3.07 on Perl. Affected by this issue is the function _make_special_file. The manipulation leads to link following.
This vulnerability is uniquely identified as CVE-2026-42497. The attack is possible to be carried out remotely. No exploit exists.
It is advisable to upgrade the affected component.
vuldb.com
CVE-2026-45548 | budibase up to 3.34.7 extract.ts processUrlFile server-side request forgery (EUVD-2026-32604)
3 days 1 hour ago
A vulnerability was found in budibase up to 3.34.7. It has been classified as critical. This issue affects the function processUrlFile of the file packages/server/src/automations/steps/ai/extract.ts. This manipulation causes server-side request forgery.
The identification of this vulnerability is CVE-2026-45548. It is possible to initiate the attack remotely. There is no exploit available.
Upgrading the affected component is recommended.
vuldb.com
CVE-2026-44887 | leiweibau Pi.Alert prior 2026-05-07 exec code injection (EUVD-2026-32635)
3 days 1 hour ago
A vulnerability was found in leiweibau Pi.Alert. It has been declared as critical. Affected by this vulnerability is the function exec. The manipulation results in code injection.
This vulnerability was named CVE-2026-44887. The attack may be performed from remote. There is no available exploit.
It is recommended to upgrade the affected component.
vuldb.com
CVE-2026-44681 | Authlib up to 1.6.11/1.7.0 redirect (EUVD-2026-32637)
3 days 1 hour ago
A vulnerability was found in Authlib up to 1.6.11/1.7.0. It has been classified as problematic. Affected is an unknown function. The manipulation leads to open redirect.
This vulnerability is uniquely identified as CVE-2026-44681. The attack is possible to be carried out remotely. No exploit exists.
Upgrading the affected component is recommended.
vuldb.com