|
51
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Subscriber Sensitive Data Exposure in GetGenie <= 4.4.2 versions.
New
|
CWE-497
Exposure of Sensitive System Information to an Unauthorized Control Sphere
|
CVE-2026-57316
|
2026-06-27 03:17 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
52
|
8.1 |
HIGH
Network
|
-
|
-
|
extract-zip does not validate symlink targets when extracting zip archives. When processing a malicious zip file containing a symlink with a relative path like '../../../../etc/passwd', extract-zip w…
New
|
CWE-22 CWE-61
Path Traversal UNIX Symbolic Link (Symlink) Following
|
CVE-2026-56876
|
2026-06-27 03:17 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
53
|
7.3 |
HIGH
Local
|
-
|
-
|
CANBoat through 6.22, fixed in commit a5a22b7, contains an off-by-one global buffer overflow in the searchForPgn() function in analyzer/pgn.c that allows remote attackers to crash the application. At…
New
|
CWE-193
Off-by-one Error
|
CVE-2026-56790
|
2026-06-27 03:17 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
54
|
7.1 |
HIGH
Network
|
-
|
-
|
Unauthenticated Cross Site Scripting (XSS) in WoodMart <= 8.5.3 versions.
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-56072
|
2026-06-27 03:17 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
55
|
9.3 |
CRITICAL
Network
|
-
|
-
|
Unauthenticated SQL Injection in Advance Product Search <= 1.4.4 versions.
New
|
CWE-89
SQL Injection
|
CVE-2026-56070
|
2026-06-27 03:17 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
56
|
8.5 |
HIGH
Network
|
-
|
-
|
Subscriber SQL Injection in Tourfic <= 2.22.5 versions.
New
|
CWE-89
SQL Injection
|
CVE-2026-56064
|
2026-06-27 03:17 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
57
|
8.3 |
HIGH
Network
|
-
|
-
|
Unauthenticated Broken Access Control in MailChimp Block <= 1.1.15 versions.
New
|
CWE-862
Missing Authorization
|
CVE-2026-56063
|
2026-06-27 03:17 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
58
|
9.9 |
CRITICAL
Network
|
-
|
-
|
Subscriber Arbitrary File Upload in Quform <= 2.23.0 versions.
New
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2026-56058
|
2026-06-27 03:17 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
59
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Subscriber PHP Object Injection in Uncanny Automator Pro <= 7.3.0.6 versions.
New
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-56057
|
2026-06-27 03:17 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
60
|
7.1 |
HIGH
Network
|
-
|
-
|
Unauthenticated Cross Site Scripting (XSS) in Automatic < 3.135.1 versions.
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-56045
|
2026-06-27 03:17 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|