|
11
|
3.1 |
LOW
Network
|
-
|
-
|
A flaw has been found in AIDC-AI ComfyUI-Copilot up to 2.0.28. This issue affects some unknown processing of the file backend/controller/conversation_api.py of the component Workflow Checkpoint Resto…
New
|
CWE-99
Resource Injection
|
CVE-2026-13493
|
2026-06-28 22:16 |
2026-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
12
|
3.7 |
LOW
Network
|
-
|
-
|
A vulnerability was detected in 78 xiaozhi-esp32 up to 2.2.6. This vulnerability affects the function Application::GetInstance of the file main/protocols/mqtt_protocol.cc of the component MQTT Goodby…
New
|
CWE-404
Improper Resource Shutdown or Release
|
CVE-2026-13491
|
2026-06-28 21:17 |
2026-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
13
|
3.7 |
LOW
Network
|
-
|
-
|
A security vulnerability has been detected in glpi-project glpi 11.0.5/11.0.6/11.0.7. This affects the function Document::canViewFile of the file front/document.send.php of the component Document Han…
New
|
CWE-285 CWE-639
Improper Authorization Authorization Bypass Through User-Controlled Key
|
CVE-2026-13490
|
2026-06-28 21:17 |
2026-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
14
|
3.1 |
LOW
Network
|
-
|
-
|
A weakness has been identified in 78 xiaozhi-esp32 up to 2.2.6. Affected by this issue is the function ParseMessage of the file main/mcp_server.cc of the component MCP Response Handler. This manipula…
New
|
CWE-662
Improper Synchronization
|
CVE-2026-13489
|
2026-06-28 21:17 |
2026-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
15
|
7.3 |
HIGH
Network
|
-
|
-
|
A security flaw has been discovered in SourceCodester Class and Exam Timetabling System 1.0/7.php. Affected by this vulnerability is an unknown functionality of the file /preview7.php. The manipulati…
New
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-13488
|
2026-06-28 20:16 |
2026-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
16
|
7.3 |
HIGH
Network
|
-
|
-
|
A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. Affected is an unknown function of the file /archive.php. The manipulation of the argument sy leads to sql inje…
New
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-13487
|
2026-06-28 20:16 |
2026-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
17
|
7.3 |
HIGH
Network
|
-
|
-
|
A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0/6.php. This impacts an unknown function of the file /preview6.php. Executing a manipulation of the argument cour…
New
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-13486
|
2026-06-28 19:16 |
2026-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
18
|
7.3 |
HIGH
Network
|
-
|
-
|
A vulnerability was found in SourceCodester Class and Exam Timetabling System 1.0. This affects an unknown function of the file /preview.php. Performing a manipulation of the argument course_year_sec…
New
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-13485
|
2026-06-28 19:16 |
2026-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
19
|
5.0 |
MEDIUM
Network
|
-
|
-
|
A vulnerability has been found in MLflow up to 4666cffc7912ea606d592fc38d6a75e2935f65e7. The impacted element is an unknown function of the component Experiment-scoped Label Schema CRUD API. Such man…
New
|
CWE-862 CWE-863
Missing Authorization Incorrect Authorization
|
CVE-2026-13484
|
2026-06-28 18:16 |
2026-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
20
|
8.8 |
HIGH
Local
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
vfio/pci: Clean up DMABUFs before disabling function
On device shutdown, make vfio_pci_core_close_device() call
vfio_pci_dma_buf_…
New
|
-
|
CVE-2026-53322
|
2026-06-28 17:16 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|