|
2261
|
8.5 |
HIGH
Network
|
-
|
-
|
SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to 1.18.0,…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-46372
|
2026-05-30 05:17 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2262
|
5.9 |
MEDIUM
Network
|
-
|
-
|
Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, CreateOrderFromCartAction::execute previously created the Order row before checking and incrementing the discount's total_use counter. Un…
|
CWE-362
Race Condition
|
CVE-2026-47741
|
2026-05-30 05:17 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2263
|
8.1 |
HIGH
Network
|
-
|
-
|
Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, Multiple Filament actions on the admin Order detail and Order shipments table were callable by an authenticated low-privilege user withou…
|
CWE-285 CWE-862
Improper Authorization Missing Authorization
|
CVE-2026-47740
|
2026-05-30 05:17 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2264
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, Sub-form Livewire components used in the product editor (Edit, Inventory, Seo, Shipping, Files) had no authorization on their store() met…
|
CWE-862
Missing Authorization
|
CVE-2026-47742
|
2026-05-30 05:17 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2265
|
9.9 |
CRITICAL
Network
|
-
|
-
|
Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, two distinct authorization defects in the team settings allowed any authenticated panel user to take over the RBAC system. Settings/Team/…
|
CWE-269 CWE-285
Improper Privilege Management Improper Authorization
|
CVE-2026-47744
|
2026-05-30 05:17 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2266
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, the admin tables for PaymentMethods, Currencies and Carriers exposed inline toggles and per-record actions (enable, disable, edit, delete…
|
CWE-862
Missing Authorization
|
CVE-2026-47745
|
2026-05-30 05:17 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2267
|
5.3 |
MEDIUM
Network
|
-
|
-
|
Casdoor versions 2.362.0 and earlier contain a logic flaw in the social‑login binding flow that allows users to bypass configured MFA requirements. The binding‑rule code path in controllers/auth.go c…
|
-
|
CVE-2026-9091
|
2026-05-30 05:16 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2268
|
9.1 |
CRITICAL
Network
|
-
|
-
|
Casdoor versions 2.362.0 and earlier contain a vulnerability that allows an attacker to bypass authentication by supplying an arbitrary signing certificate. The buildSpCertificateStore function extra…
|
-
|
CVE-2026-9090
|
2026-05-30 05:16 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2269
|
7.5 |
HIGH
Network
|
microsoft
|
planetary_computer
|
Deserialization of untrusted data in Microsoft Planetary Computer Pro allows an unauthorized attacker to disclose information over a network.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-41104
|
2026-05-30 04:46 |
2026-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2270
|
5.5 |
MEDIUM
Local
|
pypdf_project
|
pypdf
|
pypdf is a free and open-source pure-python PDF library. Prior to 6.12.1, an attacker who uses this vulnerability can craft a PDF which leads to large memory usage. This requires parsing large XMP me…
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2026-48735
|
2026-05-30 04:38 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|