|
61
|
7.1 |
HIGH
Network
|
-
|
-
|
Unauthenticated Cross Site Scripting (XSS) in Blog2Social <= 8.9.2 versions.
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-56044
|
2026-06-27 03:17 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
62
|
8.8 |
HIGH
Network
|
-
|
-
|
Contributor Privilege Escalation in Frisbii Pay <= 1.8.2 versions.
New
|
CWE-862
Missing Authorization
|
CVE-2026-56038
|
2026-06-27 03:17 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
63
|
9.3 |
CRITICAL
Network
|
-
|
-
|
Unauthenticated SQL Injection in 워드프레스 결제 심플페이 <= 5.5.6 versions.
New
|
CWE-89
SQL Injection
|
CVE-2026-56036
|
2026-06-27 03:17 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
64
|
8.1 |
HIGH
Network
|
-
|
-
|
Unauthenticated PHP Object Injection in Uncanny Automator <= 7.3.1.2 versions.
New
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-56031
|
2026-06-27 03:17 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
65
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Unauthenticated Privilege Escalation in Paytium <= 5.0.2 versions.
New
|
CWE-266
Incorrect Privilege Assignment
|
CVE-2026-56030
|
2026-06-27 03:17 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
66
|
7.5 |
HIGH
Network
|
-
|
-
|
Unauthenticated Broken Access Control in Paymob for WooCommerce <= 4.1.2 versions.
New
|
CWE-862
Missing Authorization
|
CVE-2026-56025
|
2026-06-27 03:17 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
67
|
7.1 |
HIGH
Network
|
-
|
-
|
Unauthenticated Cross Site Scripting (XSS) in MapPress Maps for WordPress <= 2.97.3 versions.
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-56011
|
2026-06-27 03:17 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
68
|
7.5 |
HIGH
Network
|
-
|
-
|
Echo is a Go web framework. Prior to 4.15.3 and 5.2.0, Echo's router and static file handler disagree on URL path decoding. The router matches routes using the raw encoded path (preserving %2F as-is)…
New
|
CWE-22
Path Traversal
|
CVE-2026-55677
|
2026-06-27 03:17 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
69
|
6.3 |
MEDIUM
Local
|
-
|
-
|
mise manages dev tools like node, python, cmake, and terraform. From 2026.3.15 until 2026.6.4, mise loads github.credential_command from local project config before any trust decision, then executes …
New
|
CWE-78
OS Command
|
CVE-2026-55448
|
2026-06-27 03:17 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
70
|
8.6 |
HIGH
Local
|
-
|
-
|
mise manages dev tools like node, python, cmake, and terraform. Prior to 2026.6.4, mise's trust feature gates config files (mise.toml, .tool-versions) through trust_check, but task-include files are …
New
|
CWE-78 CWE-94 CWE-732
OS Command Code Injection Incorrect Permission Assignment for Critical Resource
|
CVE-2026-55441
|
2026-06-27 03:17 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|