|
2201
|
7.5 |
HIGH
Network
|
-
|
-
|
An issue in Zhoros SuperBin v1.0.0 allows attackers to execute a directory traversal via supplying files with names containing traversal characters.
|
CWE-22
Path Traversal
|
CVE-2026-50877
|
2026-06-17 00:50 |
2026-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2202
|
9.8 |
CRITICAL
Network
|
-
|
-
|
An issue in the sendmail transport integration component of YouTransfer v1.0.6 allows attackers to execute arbitrary code via supplying a crafted request.
|
CWE-94
Code Injection
|
CVE-2026-50880
|
2026-06-17 00:50 |
2026-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2203
|
- |
|
-
|
-
|
Incorrect access control in the impworks Bonsai v6.0 allows authenticated attackers with Editor privileges to escalate privileges to Administrator and execute unauthorized account, password, and conf…
|
-
|
CVE-2026-50881
|
2026-06-17 00:50 |
2026-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2204
|
7.5 |
HIGH
Network
|
-
|
-
|
An issue in the /api/v0/pastes endpoint of anna-is-cute paste v0.1.1 allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2026-50882
|
2026-06-17 00:50 |
2026-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2205
|
9.6 |
CRITICAL
Network
|
-
|
-
|
An HTML injection vulnerability in the /src/highlight.rs component of matze wastebin v3.4.1 allows attackers to execute arbitrary scripts via a crafted payload.
|
CWE-79
Cross-site Scripting
|
CVE-2026-50883
|
2026-06-17 00:50 |
2026-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2206
|
7.5 |
HIGH
Network
|
-
|
-
|
Incorrect access control in the share-based read endpoints of Sismics Docs (Teedy) v1.11 allow unauthorized attackers to access sensitive endpoints via a crafted request.
|
CWE-284
Improper Access Control
|
CVE-2026-50885
|
2026-06-17 00:50 |
2026-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2207
|
9.1 |
CRITICAL
Network
|
-
|
-
|
Incorrect access control in the webhook management component of Project Firefly III v6.5.9 allows attackers to scan internal resources via a crafted POST request.
|
CWE-284
Improper Access Control
|
CVE-2026-50886
|
2026-06-17 00:50 |
2026-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2208
|
9.1 |
CRITICAL
Network
|
-
|
-
|
A Server-Side Request Forgery (SSRF) in the automatic short URL title resolution component of shlink v5.0.1 allows attackers to scan internal resources via supplying a crafted longUrl.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-50887
|
2026-06-17 00:50 |
2026-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2209
|
- |
|
-
|
-
|
Incorrect access control in the "Let's Encrypt" certificate download endpoint of Nginx Proxy Manager v2.14.0 allows authenticated attackers to obtain the TLS private key material via a crafted GET re…
|
-
|
CVE-2026-50892
|
2026-06-17 00:49 |
2026-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2210
|
7.5 |
HIGH
Network
|
-
|
-
|
Wasmtime is a runtime for WebAssembly. In versions prior to 24.0.9, 36.0.10, and 44.0.2, when a filesystem preopen is given DirPerms::all() and FilePerms::READ without FilePerms::WRITE, this access c…
|
CWE-284
Improper Access Control
|
CVE-2026-47261
|
2026-06-17 00:49 |
2026-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|