|
911
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Incorrect Privilege Assignment vulnerability in Sergey AIWU allows Privilege Escalation.
This issue affects AIWU: from n/a through 1.4.17.
New
|
CWE-266
Incorrect Privilege Assignment
|
CVE-2026-48879
|
2026-06-2 01:41 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
912
|
- |
|
-
|
-
|
Sereal::Decoder versions before 5.005 for Perl allow heap out-of-bounds read via crafted input.
In Perl/Decoder/srl_decoder.c, srl_read_object() and srl_read_hash() process a COPY tag, a back-refere…
New
|
CWE-125
Out-of-bounds Read
|
CVE-2026-8796
|
2026-06-2 01:37 |
2026-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
913
|
- |
|
-
|
-
|
SOPlanning does not enforce authorization for backup functionalities. An unauthenticated attacker can directly query backup-related endpoints and retrieve backup archives containing user databases wi…
New
|
CWE-862
Missing Authorization
|
CVE-2026-40543
|
2026-06-2 01:37 |
2026-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
914
|
- |
|
-
|
-
|
SOPlanning is vulnerable to Stored Cross-Site Scripting (XSS) via /process/upload_backup endpoint. An authenticated attacker with access to the backup functionality can upload a crafted ZIP archive c…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-40544
|
2026-06-2 01:37 |
2026-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
915
|
- |
|
-
|
-
|
SOPlanning is vulnerable to Reflected XSS via the taches parameter. An attacker can craft a malicious URL which, when opened by authenticated victim, results in arbitrary JavaScript execution in the …
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-40545
|
2026-06-2 01:37 |
2026-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
916
|
- |
|
-
|
-
|
SOPlanning is vulnerable to SQL Injection across multiple endpoints and parameters. Attacker with low privileges can inject arbitrary SQL commands, potentially gaining full control over the database.…
New
|
CWE-89
SQL Injection
|
CVE-2026-40546
|
2026-06-2 01:37 |
2026-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
917
|
- |
|
-
|
-
|
SOPlanning is vulnerable to Path Traversal in backup endpoints. Authenticated remote attacker is able to exploit a vulnerable endpoint and construct payloads that allow reading and executing files p…
New
|
CWE-22
Path Traversal
|
CVE-2026-40547
|
2026-06-2 01:37 |
2026-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
918
|
- |
|
-
|
-
|
SOPlanning does not verify uploaded file extension. An authenticated attacker with access to the backup functionality can upload a crafted ZIP archive containing a legitimate user.csv file alongside …
New
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2026-40548
|
2026-06-2 01:37 |
2026-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
919
|
- |
|
-
|
-
|
SOPlanning is vulnerable to Cross‑Site Request Forgery (CSRF) in groupe_save create, modify and delete endpoints. An attacker can craft a malicious website that, when visited by an authenticated user…
New
|
CWE-352
Origin Validation Error
|
CVE-2026-40549
|
2026-06-2 01:37 |
2026-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
920
|
- |
|
-
|
-
|
Use of hard-coded credentials in KS-SOMED allowed an unauthorized attacker access to FTP server that hosted the application's update packages. The attacker with these credentials could upload a malic…
New
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2026-42251
|
2026-06-2 01:37 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|