|
331
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Affiliate Broken Access Control in Affiliates Manager <= 2.9.49 versions.
New
|
CWE-862
Missing Authorization
|
CVE-2026-57654
|
2026-06-27 00:49 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
332
|
8.2 |
HIGH
Network
|
-
|
-
|
Unauthenticated Cross Site Request Forgery (CSRF) in Child Theme Wizard <= 1.4 versions.
New
|
CWE-352
Origin Validation Error
|
CVE-2026-57655
|
2026-06-27 00:49 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
333
|
5.3 |
MEDIUM
Network
|
-
|
-
|
Unauthenticated Broken Access Control in Booking and Rental Manager <= 2.7.1 versions.
New
|
CWE-862
Missing Authorization
|
CVE-2026-57660
|
2026-06-27 00:49 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
334
|
5.4 |
MEDIUM
Network
|
-
|
-
|
Subscriber Broken Access Control in WPComplete <= 2.9.5.5 versions.
New
|
CWE-862
Missing Authorization
|
CVE-2026-57661
|
2026-06-27 00:49 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
335
|
8.5 |
HIGH
Network
|
-
|
-
|
Sales Representative SQL Injection in Groundhogg <= 4.5 versions.
New
|
CWE-89
SQL Injection
|
CVE-2026-57667
|
2026-06-27 00:49 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
336
|
8.0 |
HIGH
Network
|
-
|
-
|
Dell Dell Container Storage Modules, version(s) csi-powerstore v2.16.0, csi-unity v2.16.0, csi-powerflex v2.16.0, csi-powermax v2.16.0, contain(s) an Improper Neutralization of Special Elements used …
New
|
CWE-78
OS Command
|
CVE-2026-40711
|
2026-06-27 00:48 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
337
|
7.5 |
HIGH
Network
|
google
|
chrome
|
Use after free in AdFilter in Google Chrome on Android prior to 149.0.7827.201 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted…
New
|
CWE-416
Use After Free
|
CVE-2026-13283
|
2026-06-27 00:41 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
338
|
6.8 |
MEDIUM
Physics
|
google
|
chrome
|
Use after free in Payments in Google Chrome on Android prior to 149.0.7827.201 allowed a local attacker to potentially exploit heap corruption via physical access to the device. (Chromium security se…
New
|
CWE-416
Use After Free
|
CVE-2026-13282
|
2026-06-27 00:41 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
339
|
8.3 |
HIGH
Network
|
google
|
chrome
|
Integer overflow in Mojo in Google Chrome prior to 149.0.7827.201 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a malicious file. (Chr…
New
|
CWE-472
External Control of Assumed-Immutable Web Parameter
|
CVE-2026-13281
|
2026-06-27 00:41 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
340
|
7.3 |
HIGH
Network
|
-
|
-
|
It is possible to bypass the Kerberos pre-authentication check in Apache Kerby by sending a PA-DATA with an unrecognized or unsupported type. Users are recommended to upgrade to version 2.1.2, which …
New
|
CWE-304
Missing Critical Step in Authentication
|
CVE-2026-57915
|
2026-06-27 00:16 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|