|
1651
|
4.3 |
MEDIUM
Network
|
-
|
-
|
Missing Authorization vulnerability in bPlugins Tiktok Feed allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects Tiktok Feed: from n/a through 1.0.24.
|
CWE-862
Missing Authorization
|
CVE-2026-24520
|
2026-05-27 05:19 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1652
|
5.3 |
MEDIUM
Network
|
-
|
-
|
Missing Authorization vulnerability in Magepeople inc. Taxi Booking Manager for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects Taxi Booking M…
|
CWE-862
Missing Authorization
|
CVE-2026-25426
|
2026-05-27 05:19 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1653
|
4.3 |
MEDIUM
Network
|
-
|
-
|
Missing Authorization vulnerability in Magepeople inc. WpBookingly allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects WpBookingly: from n/a through 1.2.9.
|
CWE-862
Missing Authorization
|
CVE-2026-25444
|
2026-05-27 05:19 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1654
|
6.3 |
MEDIUM
Network
|
-
|
-
|
Missing Authorization vulnerability in Magepeople inc. WpTravelly allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects WpTravelly: from n/a through 2.1.5.
|
CWE-862
Missing Authorization
|
CVE-2026-27331
|
2026-05-27 05:19 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1655
|
7.3 |
HIGH
Network
|
-
|
-
|
A flaw has been found in itsourcecode Student Transcript Processing System 1.0. This vulnerability affects unknown code of the file /admin/modules/student/trans.php. Executing a manipulation of the a…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-9574
|
2026-05-27 05:19 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1656
|
7.3 |
HIGH
Network
|
-
|
-
|
A vulnerability has been found in itsourcecode Student Transcript Processing System 1.0. This issue affects some unknown processing of the file /admin/modules/class/index.php?view=view. The manipulat…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-9575
|
2026-05-27 05:19 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1657
|
9.8 |
CRITICAL
Network
|
litespeedtech
|
litespeed_cpanel_plugin litespeed_whm_plugin
|
LiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalation (possibly to root), as exploited in the wild in May 2026. Detection is best done via a command line of grep -rE "cpanel_jsona…
|
CWE-266
Incorrect Privilege Assignment
|
CVE-2026-48172
|
2026-05-27 05:19 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1658
|
7.5 |
HIGH
Network
|
-
|
-
|
D-Link DIR601 2.02NA contains a credential disclosure vulnerability that allows unauthenticated attackers to retrieve sensitive configuration data by manipulating the table_name parameter in POST req…
|
CWE-497
Exposure of Sensitive System Information to an Unauthorized Control Sphere
|
CVE-2018-25358
|
2026-05-27 05:16 |
2026-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1659
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Spring AI's support for Anthropic's Skills API used LLM-influenced filenames unsanitized in Path.resolve before writing files to disk. This could allow a malicious user to write files outside the int…
|
CWE-22
Path Traversal
|
CVE-2026-41863
|
2026-05-27 05:16 |
2026-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1660
|
8.2 |
HIGH
Network
|
-
|
-
|
code100x contains an authentication bypass vulnerability in the Mobile API that allows unauthenticated attackers to impersonate arbitrary users by supplying a crafted JSON payload in the 'g' HTTP hea…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-8890
|
2026-05-27 05:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|