|
611
|
7.5 |
HIGH
Network
|
jetbrains
|
youtrack
|
In JetBrains YouTrack before 2026.2.16593 improper authorisation in the app configurations endpoint allowed modifying project settings
Update
|
CWE-862
Missing Authorization
|
CVE-2026-57923
|
2026-06-28 04:32 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
612
|
5.3 |
MEDIUM
Network
|
jetbrains
|
youtrack
|
In JetBrains YouTrack before 2026.2.16593 default role configuration exposed excessive user profile details
Update
|
CWE-276
Incorrect Default Permissions
|
CVE-2026-57924
|
2026-06-28 04:31 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
613
|
5.3 |
MEDIUM
Network
|
jetbrains
|
youtrack
|
In JetBrains YouTrack before 2026.2.16593 improper access control allowed reading saved queries and tags
Update
|
CWE-862
Missing Authorization
|
CVE-2026-57925
|
2026-06-28 04:29 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
614
|
7.5 |
HIGH
Network
|
jenkins
|
script_security
|
Jenkins Script Security Plugin 1402.v94c9ce464861 and earlier does not reject Groovy AST transformation annotations carrying an extensions member, allowing attackers able to run sandboxed Groovy scri…
Update
|
CWE-93 CWE-693
CRLF Injection Protection Mechanism Failure
|
CVE-2026-57281
|
2026-06-28 04:27 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
615
|
6.5 |
MEDIUM
Network
|
gnu
|
sed
|
Arbitrary File Read vulnerability in Rapid7 InsightConnect Sed Plugin on Linux allows authenticated attackers to read arbitrary files via the expression parameter due to insufficient input validation.
Update
|
CWE-22 CWE-200
Path Traversal Information Exposure
|
CVE-2026-9153
|
2026-06-28 04:26 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
616
|
6.5 |
MEDIUM
Network
|
gnu
|
sed
|
Arbitrary File Write vulnerability in Rapid7 InsightConnect Sed Plugin on Linux allows authenticated attackers to write attacker-controlled content to arbitrary file paths via the expression paramete…
Update
|
CWE-22
Path Traversal
|
CVE-2026-9154
|
2026-06-28 04:25 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
617
|
8.8 |
HIGH
Network
|
gnu
|
sed
|
OS Command Injection vulnerability in Rapid7 InsightConnect Sed Plugin on Linux allows authenticated attackers to execute arbitrary OS commands via the expression parameter due to insufficient input …
Update
|
CWE-78
OS Command
|
CVE-2026-9155
|
2026-06-28 04:24 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
618
|
7.2 |
HIGH
Network
|
aten
|
unizon
|
ATEN Unizon doCryptoHugeFileToFile Improper Verification of Cryptographic Signature Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affect…
Update
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2026-9779
|
2026-06-28 04:02 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
619
|
7.2 |
HIGH
Network
|
aten
|
unizon
|
ATEN Unizon ImportDeviceList Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of ATEN Unizon. Au…
Update
|
CWE-22
Path Traversal
|
CVE-2026-9778
|
2026-06-28 04:01 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
620
|
7.2 |
HIGH
Network
|
aten
|
unizon
|
ATEN Unizon restoreDB Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of ATEN Unizon. Authentic…
Update
|
CWE-22
Path Traversal
|
CVE-2026-9777
|
2026-06-28 04:01 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|