|
431
|
6.1 |
MEDIUM
Network
|
-
|
-
|
HCL Digital Experience Compose is affected by a reflected cross-site scripting (XSS) vulnerability in the search center. An attacker could execute arbitrary JavaScript in the victim's browser.
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-21825
|
2026-06-6 01:05 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
432
|
6.1 |
MEDIUM
Network
|
-
|
-
|
HCL Digital Experience and HCL Digital Experience Compose could be susceptible to Host header injection. An attacker can manipulate the Host header and cause the application to behave in unexpected …
New
|
CWE-601
Open Redirect
|
CVE-2026-21826
|
2026-06-6 01:05 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
433
|
- |
|
-
|
-
|
HCL Digital Experience is affected by an OS command injection vulnerability in the Digital Asset Management API. An attacker may execute arbitrary operating system commands, typically inheriting the…
New
|
CWE-78
OS Command
|
CVE-2026-21837
|
2026-06-6 01:05 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
434
|
- |
|
-
|
-
|
A vulnerability in the JCE editor extension for Joomla allows the creation of new editor profiles for unauthenticated users, ultimately resulting in PHP code upload and execution.
New
|
CWE-284
Improper Access Control
|
CVE-2026-48907
|
2026-06-6 01:05 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
435
|
6.3 |
MEDIUM
Network
|
-
|
-
|
Cross Site Scripting (XSS) vulnerability in the "Task in Progress / Recent" page in Arket Globe Document Intelligence 5.0.0.559 due to improper sanitization of user input in text fields when creating…
New
|
CWE-79
Cross-site Scripting
|
CVE-2025-65640
|
2026-06-6 01:04 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
436
|
5.3 |
MEDIUM
Network
|
-
|
-
|
HelloTalk through 3.4.1 stores full-precision GPS coordinates even when the user had intended to share only a country or city. Furthermore, these coordinates are placed into a database on the client …
New
|
CWE-359
Exposure of Private Personal Information to an Unauthorized Actor
|
CVE-2020-25900
|
2026-06-6 01:04 |
2026-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
437
|
- |
|
-
|
-
|
Multiple reflected Cross-Site Scripting (XSS) vulnerabilities in damasac thaipalliative_lte through version 3.0 allow remote attackers to inject arbitrary web script or HTML via the idFormMain parame…
New
|
-
|
CVE-2026-38579
|
2026-06-6 01:04 |
2026-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
438
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A security vulnerability has been detected in tittuvarghese CollegeManagementSystem 3e476335cfbfb9a049e09f474c7ec885f69a9df3/a38852979f7e27ae67b610dce5979500ef8ebe01. The impacted element is an unkno…
New
|
CWE-284 CWE-434
Improper Access Control Unrestricted Upload of File with Dangerous Type
|
CVE-2026-11333
|
2026-06-6 01:04 |
2026-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
439
|
7.3 |
HIGH
Network
|
-
|
-
|
A vulnerability was detected in tittuvarghese CollegeManagementSystem 3e476335cfbfb9a049e09f474c7ec885f69a9df3/a38852979f7e27ae67b610dce5979500ef8ebe01. This affects an unknown function of the file d…
New
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-11334
|
2026-06-6 01:04 |
2026-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
440
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A flaw has been found in tittuvarghese CollegeManagementSystem 3e476335cfbfb9a049e09f474c7ec885f69a9df3/a38852979f7e27ae67b610dce5979500ef8ebe01. This impacts the function session_start of the file /…
New
|
CWE-384
Session Fixation
|
CVE-2026-11335
|
2026-06-6 01:04 |
2026-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|