|
1551
|
5.4 |
MEDIUM
Network
|
concretecms
|
concrete_cms
|
Concrete CMS 9.5.0 and below is vulnerable to Reflected XSS in Legacy Pagination via HTML attribute injection. Concrete\Core\Legacy\Pagination builds pagination links by raw-interpolating its $URL fi…
Update
|
CWE-83
Improper Neutralization of Script in Attributes in a Web Page
|
CVE-2026-8245
|
2026-05-27 02:19 |
2026-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1552
|
4.3 |
MEDIUM
Network
|
concretecms
|
concrete_cms
|
Concrete CMS below 9.5.0 and below is vulnerable to password change without reauthorization and session-hardening bypass. The user-profile edit controller passes the entire raw POST array to UserInfo…
Update
|
CWE-269 CWE-620 CWE-915
Improper Privilege Management Unverified Password Change Improperly Controlled Modification of Dynamically-Determined Object Attributes
|
CVE-2026-8327
|
2026-05-27 02:18 |
2026-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1553
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was determined in haojing8312 WorkClaw up to 0.6.4. This affects the function is_dangerous of the file apps/runtime/src-tauri/src/agent/tools/bash.rs of the component Blacklist Handle…
New
|
CWE-77 CWE-78
Command Injection OS Command
|
CVE-2026-9565
|
2026-05-27 02:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1554
|
2.4 |
LOW
Network
|
-
|
-
|
A vulnerability was found in SourceCodester/oretnom23 Hospitals Patient Records Management System 1.0. The impacted element is an unknown function of the file /admin/?page=patients/view_patient. Perf…
New
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-9564
|
2026-05-27 02:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1555
|
6.2 |
MEDIUM
Local
|
-
|
-
|
IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service via the optional module mod_fastcgi module.
New
|
CWE-617
Reachable Assertion
|
CVE-2026-8852
|
2026-05-27 02:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1556
|
7.5 |
HIGH
Network
|
-
|
-
|
IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service via the optional module mod_ibm_upload.
New
|
CWE-476
NULL Pointer Dereference
|
CVE-2026-8850
|
2026-05-27 02:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1557
|
- |
|
-
|
-
|
Lack of input filtering leads to an XSS vector in the HTML filter code.
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-48905
|
2026-05-27 02:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1558
|
- |
|
-
|
-
|
An improper access check allows privelege escalation through the com_users group editing webservice endpoint.
New
|
CWE-284
Improper Access Control
|
CVE-2026-48904
|
2026-05-27 02:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1559
|
- |
|
-
|
-
|
Inadequate content filtering within the checkAttribute methods leads to XSS vulnerabilities in various components.
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-48903
|
2026-05-27 02:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1560
|
- |
|
-
|
-
|
An improper access check allowed low privileged users to edit the task types of existing scheduler tasks.
New
|
CWE-284
Improper Access Control
|
CVE-2026-48900
|
2026-05-27 02:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|