Sandbox escape due to incorrect boundary conditions in the Widget: Win32 component. This vulnerability was fixed in Firefox 151 and Firefox ESR 140.11.
CVSSv3.1 9.6 (CRITICAL)
CWECWE 20CWECWE 693CWECWE 119TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-05-19
2026-05-19 14:16Z
HIGH
CVE-2026-8958 — Information: disclosure, sandbox escape in the Security: Process Sandboxing component.
Information disclosure, sandbox escape in the Security: Process Sandboxing component. This vulnerability was fixed in Firefox 151 and Firefox ESR 140.11.
CVSSv3.1 8.6 (HIGH)
Privilege escalation in the Enterprise Policies component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.
CVSSv3.1 8.8 (HIGH)
CWECWE 269VNDMozillaTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-19
2026-05-19 14:16Z
CRIT
CVE-2026-8956 — Integer: overflow in the Networking: JAR component.
Privilege escalation in the DOM: Workers component. This vulnerability was fixed in Firefox 151, Firefox ESR 140.11, Thunderbird 151, and Thunderbird 140.11.
CVSSv3.1 8.8 (HIGH)
CWECWE 269VNDMozillaTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-19
2026-05-19 14:16Z
CRIT
CVE-2026-8953 — Sandbox: escape due to use-after-free in the Disability Access APIs component.
Sandbox escape due to use-after-free in the Disability Access APIs component. This vulnerability was fixed in Firefox 151, Firefox ESR 115.36, and Firefox ESR 140.11.
CVSSv3.1 9.6 (CRITICAL)
CWECWE 416TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-05-19
2026-05-19 14:16Z
HIGH
CVE-2026-8952 — Mozilla Firefox: Privilege escalation in the Application Update component.
Same-origin policy bypass in the Networking: HTTP component. This vulnerability was fixed in Firefox 151 and Firefox ESR 140.11.
CVSSv3.1 9.3 (CRITICAL)
CWECWE 346TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-05-19
2026-05-19 14:16Z
CRIT
CVE-2026-8948 — Same: Same-origin policy bypass in the DOM: Networking component.
Camel-CXF and Camel-Knative Message Header Injection via Missing Inbound Filtering
The CXF and Knative HeaderFilterStrategy implementations (CxfRsHeaderFilterStrategy in camel-cxf-rest, CxfHeaderFilterStrategy in camel-cxf-transport, and KnativeHttpHeaderFilterStrategy in camel-knative-http) only filter outbound Camel-internal headers via setOutFilterStartsWith, while not configuring inbound filtering via setInFilterStartsWith. As a result, an unauthenticated attacker can in
CVSSv3.1 9.8 (CRITICAL)
CWECWE 178VNDCamelTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-19
2026-05-19 14:16Z
CRIT
CVE-2026-43633 — HestiaCP: versions 1.9.0 through 1.9.4 contain a deserialization vulnerability in the web terminal component
HestiaCP versions 1.9.0 through 1.9.4 contain a deserialization vulnerability in the web terminal component caused by a session format mismatch between PHP and Node.js that allows unauthenticated remote attackers to achieve root-level code execution. Attackers can inject crafted data into HTTP headers that are processed by the PHP session handler but incorrectly deserialized by the Node.js web terminal component as trusted session values, resulting in arbitrary command execut
CVSSv3.1 10.0 (CRITICAL)
CWECWE 502VNDHestiacpTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-05-19
2026-05-19 14:16Z
HIGH
CVE-2026-42097 — Sparxsystems Pro_cloud_server: Sparx Pro Cloud Server requires authentication based on requested URL.
Sparx Pro Cloud Server requires authentication based on requested URL. An attacker can omit the "model" query parameter and send the model name only in the binary blob in POST request allowing SQL query execution without authentication.
The vendor was notified early about this vulnerability, but didn't respond with the details of vulnerability or vulnerable version range. Only version 6.1 (build 167) and below were tested and confirmed as vulnerable, other versions were not
CVSSv3.1 8.8 (HIGH)
CWECWE 639VNDSparxsystemsVNDSparxTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-19
2026-05-19 14:16Z
HIGH
CVE-2026-42096 — Sparxsystems Pro_cloud_server: Sparx Pro Cloud Server is vulnerable to Broken Access Control within communication with the
Sparx Pro Cloud Server is vulnerable to Broken Access Control within communication with the database. Due to lack of permission checks, any low privileged user can run arbitrary SQL queries within database user context.
The vendor was notified early about this vulnerability, but didn't respond with the details of vulnerability or vulnerable version range. Only version 6.1 (build 167) and below were tested and confirmed as vulnerable, other versions were not tested and might
CVSSv3.1 8.8 (HIGH)
CWECWE 863VNDSparxsystemsVNDSparxTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-19
2026-05-19 13:16Z
CRIT
CVE-2026-4883 — Piotnet: The Piotnet Forms plugin for WordPress is vulnerable to arbitrary file upload due to
The Piotnet Forms plugin for WordPress is vulnerable to arbitrary file upload due to missing file type validation in the 'piotnetforms_ajax_form_builder' function in all versions up to, and including, 2.1.40. The plugin uses an incomplete extension blacklist that only blocks php, phpt, php5, php7, and exe extensions, while allowing dangerous extensions such as .phar or .phtml to be uploaded. This makes it possible for unauthenticated attackers to upload arbitrary files on the
CVSSv3.1 9.8 (CRITICAL)
CWECWE 434VNDPiotnetTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-19
2026-05-19 12:16Z
HIGH
CVE-2026-7504 — By crafting a malicious request, an attacker could bypass validation to redirect users to
A flaw was found in Keycloak's URL validation logic during redirect operations. By crafting a malicious request, an attacker could bypass validation to redirect users to unauthorized URLs, potentially leading to the exposure of sensitive information within the domain or facilitating further attacks. This vulnerability specifically affects Keycloak clients configured with a wildcard (*) in the "Valid Redirect URIs" field and requires user interaction to be successfully exploit
CVSSv3.1 8.1 (HIGH)
CWECWE 601TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-05-19
2026-05-19 12:16Z
CRIT
CVE-2026-43493 — Linux: In the Linux kernel, the following vulnerability has been resolved: crypto: pcrypt - Fix
In the Linux kernel, the following vulnerability has been resolved:
crypto: pcrypt - Fix handling of MAY_BACKLOG requests
MAY_BACKLOG requests can return EBUSY. Handle them by checking
for that value and filtering out EINPROGRESS notifications.
CVSSv3.1 9.8 (CRITICAL)
TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-19
2026-05-19 10:16Z
HIGH
CVE-2026-46586 — Apache Ofbiz: Improper Control of Generation of Code ('Code Injection'), Improper Neutralization of Directives in Dynamically
Improper Control of Generation of Code ('Code Injection'), Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') vulnerability in Apache OFBiz.
This issue affects Apache OFBiz: before 24.09.06.
Users are recommended to upgrade to version 24.09.06, which fixes the issue.
CVSSv3.1 8.8 (HIGH)
CWECWE 94CWECWE 95VNDApacheTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-19
2026-05-19 10:16Z
HIGH
CVE-2026-45434 — Authentication: Improper Authentication vulnerability in Apache OFBiz via Password-Change Logic Flaw Leading to Remote Code
Improper Authentication vulnerability in Apache OFBiz via Password-Change Logic Flaw Leading to Remote Code Execution
This issue affects Apache OFBiz: before 24.09.06.
Users are recommended to upgrade to version 24.09.06, which fixes the issue.
CVSSv3.1 8.8 (HIGH)
CWECWE 287TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-05-19
2026-05-19 10:16Z
CRIT
CVE-2026-41919 — Neutralization: Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in
Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Apache OFBiz.
This issue affects Apache OFBiz: before 24.09.06.
Users are recommended to upgrade to version 24.09.06, which fixes the issue.
CVSSv3.1 9.1 (CRITICAL)
CWECWE 90TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-05-19
2026-05-19 10:16Z
CRIT
CVE-2026-31986 — Use: of Hard-coded Cryptographic Key vulnerability in Apache OFBiz.
Use of Hard-coded Cryptographic Key vulnerability in Apache OFBiz.
This issue affects Apache OFBiz: before 24.09.06.
Users are recommended to upgrade to version 24.09.06, which fixes the issue.
CVSSv3.1 9.1 (CRITICAL)
CWECWE 321TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-05-19
2026-05-19 10:16Z
CRIT
CVE-2026-2611 — MLflow: This vulnerability allows a remote attacker to exploit cross-origin requests from a malicious webpage
In MLflow version 3.9.0, the MLflow Assistant feature introduced improper origin validation in its /ajax-api endpoints. This vulnerability allows a remote attacker to exploit cross-origin requests from a malicious webpage to interact with the MLflow Assistant running on a victim's local machine. By bypassing the loopback-only restriction, the attacker can modify the Assistant's configuration to enable full access, which in turn allows the execution of arbitrary commands via t
CVSSv3.1 9.6 (CRITICAL)
CWECWE 346VNDMlflowTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-05-19
2026-05-19 08:16Z
CRIT
CVE-2026-4885 — Piotnet: The Piotnet Addons for Elementor Pro plugin for WordPress is vulnerable to arbitrary file
The Piotnet Addons for Elementor Pro plugin for WordPress is vulnerable to arbitrary file upload due to missing file type validation in the 'pafe_ajax_form_builder' function in all versions up to, and including, 7.1.70. The plugin uses an incomplete extension blacklist that only blocks php, phpt, php5, php7, and exe extensions, while allowing dangerous extensions such as .phar or .phtml to be uploaded. This makes it possible for unauthenticated attackers to upload arbitrary f
CVSSv3.1 9.8 (CRITICAL)
CWECWE 434VNDPiotnetTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-05-19
2026-05-19 07:52Z
HIGH
offensive-claude — Offensive security toolkit for Claude Code covering red team, exploit dev, AD attacks, EDR bypass, mobile pentest
offensive-claude is a comprehensive Claude Code configuration toolkit designed for offensive security practitioners, featuring 25 specialized skills, 6 agents, and 47 vulnerability reference files covering the full red-team lifecycle including exploit development, AD attacks, EDR bypass, mobile penetration testing, and cloud security. The toolkit integrates with MCP servers (IDA Pro, JADX, web search) and provides structured guidance on recon, vulnerability analysis, reverse engineering, malware analysis, and advanced red-team operations.