|
781
|
4.3 |
MEDIUM
Network
|
jenkins
|
job_import
|
Jenkins Job Import Plugin 143.v044a_2e819b_27 and earlier does not perform a permission check in an HTTP endpoint, allowing attackers with Overall/Read permission to enumerate credentials IDs of cred…
Update
|
CWE-269
Improper Privilege Management
|
CVE-2026-48926
|
2026-06-2 23:49 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
782
|
2.5 |
LOW
Local
|
mintplexlabs
|
anythingllm
|
AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. Prior to 1.13.0, the AnythingLLM agent filesystem copy tool validates only …
Update
|
CWE-59
Link Following
|
CVE-2026-45403
|
2026-06-2 23:48 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
783
|
- |
|
-
|
-
|
An authentication bypass vulnerability exists in MISP when LDAP mixed authentication is enabled with OTP enforcement. In deployments configured with LdapAuth.mixedAuth=true and Security.require_otp=t…
New
|
CWE-287
Improper Authentication
|
CVE-2026-10611
|
2026-06-2 23:47 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
784
|
- |
|
-
|
-
|
Path traversal in restore handler in Collibra Agent, allows an attacker to write arbitrary files via a crafted ZIP archive. Collibra Agent fails to properly validate and canonicalize file path during…
New
|
-
|
CVE-2026-10621
|
2026-06-2 23:46 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
785
|
- |
|
-
|
-
|
Improper Authentication in REST API in Collibra Agent, allows a remote unauthenticated attacker to access privileged functionality via exposed '/rest/* endpoints.
New
|
-
|
CVE-2026-10622
|
2026-06-2 23:46 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
786
|
7.5 |
HIGH
Network
|
-
|
-
|
Banana Slides through 0.4.0, patched in commit e8bc490, contains a path traversal vulnerability in the generate_image() function within the AI service backend that allows unauthenticated attackers to…
New
|
CWE-22
Path Traversal
|
CVE-2026-49136
|
2026-06-2 23:45 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
787
|
8.2 |
HIGH
Network
|
-
|
-
|
Joomla Component JE Photo Gallery 1.1 contains an SQL injection vulnerability that allows unauthenticated attackers to extract database information by injecting malicious SQL code through the categor…
New
|
CWE-89
SQL Injection
|
CVE-2018-25433
|
2026-06-2 23:45 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
788
|
6.5 |
MEDIUM
Adjacent
|
-
|
-
|
A buffer overflow vulnerability in the UPnP AddPortMapping() command in Zyxel VMG4005-B50B firmware versions through 5.13(ABRL.5.4)C0 could allow an adjacent attacker to trigger a temporary denial-of…
New
|
CWE-120
Classic Buffer Overflow
|
CVE-2026-3870
|
2026-06-2 23:45 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
789
|
6.5 |
MEDIUM
Adjacent
|
-
|
-
|
A buffer overflow vulnerability in the UPnP DeletePortMapping() command in Zyxel VMG4005-B50B firmware versions through 5.13(ABRL.5.4)C0 could allow an adjacent attacker to trigger a temporary denial…
New
|
CWE-120
Classic Buffer Overflow
|
CVE-2026-3871
|
2026-06-2 23:45 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
790
|
- |
|
-
|
-
|
LDAP filter injection vulnerability in Yandex Database prior to 25.3.1.25 allows a remote attacker with valid LDAP credentials to bypass group membership checks resulting in unauthorized access to th…
New
|
CWE-280
Improper Handling of Insufficient Permissions or Privileges
|
CVE-2026-10549
|
2026-06-2 23:45 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|