|
2981
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Mobatek MobaXterm 12.1 contains a structured exception handling (SEH) based buffer overflow vulnerability in the username field of session files that allows remote attackers to execute arbitrary code…
|
CWE-120
Classic Buffer Overflow
|
CVE-2019-25741
|
2026-06-5 00:00 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2982
|
8.2 |
HIGH
Network
|
-
|
-
|
WordPress Plugin Google Review Slider 6.1 contains a time-based blind SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through th…
|
CWE-89
SQL Injection
|
CVE-2019-25745
|
2026-06-5 00:00 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2983
|
7.3 |
HIGH
Network
|
-
|
-
|
A vulnerability was detected in SourceCodester Pizzafy E-Commerce System 1.0. Affected by this vulnerability is the function Login of the file /admin/admin_class_novo.php of the component Administrat…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-10704
|
2026-06-4 23:58 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2984
|
7.3 |
HIGH
Network
|
-
|
-
|
A vulnerability was identified in DedeCMS 5.7.88. The impacted element is the function dede_htmlspecialchars of the file /plus/flink.php. The manipulation of the argument msg leads to sql injection. …
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-10607
|
2026-06-4 23:56 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2985
|
7.3 |
HIGH
Network
|
-
|
-
|
A security flaw has been discovered in DedeCMS 5.7.88. This affects the function RemoveXSS of the file /plus/carbuyaction.php. The manipulation of the argument postname/des results in sql injection. …
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-10608
|
2026-06-4 23:56 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2986
|
4.3 |
MEDIUM
Network
|
-
|
-
|
A weakness has been identified in nextlevelbuilder GoClaw up to 3.11.3. The impacted element is the function TeamTasksTool.executeComplete of the file internal/tools/team_tasks_lifecycle.go of the co…
|
CWE-862 CWE-863
Missing Authorization Incorrect Authorization
|
CVE-2026-10616
|
2026-06-4 23:56 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2987
|
7.3 |
HIGH
Network
|
-
|
-
|
A security vulnerability has been detected in nextlevelbuilder GoClaw up to 3.11.3. This affects the function resolveAuth of the file internal/http/auth.go of the component Webhook Verification Handl…
|
CWE-287 CWE-306
Improper Authentication Missing Authentication for Critical Function
|
CVE-2026-10617
|
2026-06-4 23:56 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2988
|
4.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability has been found in ahujasid blender-mcp up to 7636d13bded82eca58eb93c3f4cd8708dfdfbe8b. Impacted is the function Open of the file src/blender_mcp/server.py. The manipulation of the arg…
|
CWE-74 CWE-707
Injection Improper Enforcement of Message or Data Structure
|
CVE-2026-10661
|
2026-06-4 23:56 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2989
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was found in ahujasid blender-mcp up to 7636d13bded82eca58eb93c3f4cd8708dfdfbe8b. The affected element is the function requests.get of the file src/blender_mcp/server.py of the compon…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-10662
|
2026-06-4 23:56 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2990
|
5.5 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was determined in ahujasid blender-mcp up to 7636d13bded82eca58eb93c3f4cd8708dfdfbe8b. The impacted element is the function execute_blender_code of the file /src/blender_mcp/server.py…
|
CWE-74 CWE-94
Injection Code Injection
|
CVE-2026-10688
|
2026-06-4 23:56 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|