|
71
|
7.3 |
HIGH
Network
|
-
|
-
|
Unauthenticated Broken Access Control in Newsletters <= 4.13 versions.
New
|
CWE-862
Missing Authorization
|
CVE-2026-54840
|
2026-06-27 03:17 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
72
|
7.5 |
HIGH
Network
|
-
|
-
|
Unauthenticated Sensitive Data Exposure in Trinity Backup – Backup, Migrate, Restore, Clone & Schedule Backups <= 2.0.9 versions.
New
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-54839
|
2026-06-27 03:17 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
73
|
7.5 |
HIGH
Network
|
-
|
-
|
Unauthenticated Broken Access Control in Gutenverse Companion <= 2.5.0 versions.
New
|
CWE-862
Missing Authorization
|
CVE-2026-54832
|
2026-06-27 03:17 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
74
|
9.3 |
CRITICAL
Network
|
-
|
-
|
Unauthenticated SQL Injection in GeoDirectory <= 2.8.162 versions.
New
|
CWE-89
SQL Injection
|
CVE-2026-54831
|
2026-06-27 03:17 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
75
|
9.3 |
CRITICAL
Network
|
-
|
-
|
Unauthenticated SQL Injection in JetBooking <= 4.0.4.1 versions.
New
|
CWE-89
SQL Injection
|
CVE-2026-54820
|
2026-06-27 03:17 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
76
|
5.5 |
MEDIUM
Local
|
-
|
-
|
mise manages dev tools like node, python, cmake, and terraform. Prior to 2026.6.1, the mise HTTP backend builds its install symlink destination from the raw resolved version string for non-latest ver…
New
|
CWE-22
Path Traversal
|
CVE-2026-54557
|
2026-06-27 03:17 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
77
|
7.5 |
HIGH
Network
|
-
|
-
|
Dragonfly is an in-memory data store built for modern application workloads. Prior to 1.39.0, a crafted RESTORE payload triggers an out-of-bounds read in DragonflyDB's listpack collection loaders, cr…
New
|
CWE-125
Out-of-bounds Read
|
CVE-2026-54341
|
2026-06-27 03:17 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
78
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Unauthenticated Broken Access Control in User Registration <= 5.2.2 versions.
New
|
CWE-862
Missing Authorization
|
CVE-2026-52701
|
2026-06-27 03:17 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
79
|
7.5 |
HIGH
Network
|
-
|
-
|
Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.35.11, 1.36.7, 1.37.3, and 1.38.1, Envoy can translate a downstream HTTP/3 request that is complete a…
New
|
CWE-444
HTTP Request Smuggling
|
CVE-2026-48743
|
2026-06-27 03:17 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
80
|
5.9 |
MEDIUM
Network
|
-
|
-
|
Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.34.0 until 1.35.13, 1.36.9, 1.37.5, and 1.38.3, a vulnerability exists in Envoy's TCP StatsD sink (TcpSta…
New
|
CWE-120
Classic Buffer Overflow
|
CVE-2026-48706
|
2026-06-27 03:17 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|