|
201
|
7.5 |
HIGH
Network
|
envoyproxy
|
envoy
|
Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.34.0 until 1.35.13, 1.36.9, 1.37.5, and 1.38.3, a vulnerability exists in Envoy's TCP StatsD sink (TcpSta…
New
|
CWE-120
Classic Buffer Overflow
|
CVE-2026-48706
|
2026-06-30 03:34 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
202
|
7.5 |
HIGH
Network
|
envoyproxy
|
envoy
|
Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.35.11, 1.36.7, 1.37.3, and 1.38.1, Envoy can translate a downstream HTTP/3 request that is complete a…
New
|
CWE-444
HTTP Request Smuggling
|
CVE-2026-48743
|
2026-06-30 03:27 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
203
|
5.9 |
MEDIUM
Network
|
envoyproxy
|
envoy
|
Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.36.0 until 1.36.9, 1.37.5, and 1.38.3, a Use-After-Free (UAF) vulnerability leading to a sudden segmentat…
New
|
CWE-416
Use After Free
|
CVE-2026-47205
|
2026-06-30 03:21 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
204
|
7.5 |
HIGH
Network
|
envoyproxy
|
envoy
|
Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.37.0 until 1.37.5 and 1.38.3, when the %REQUESTED_SERVER_NAME(X:Y)% is used in log format and host relate…
New
|
CWE-476
NULL Pointer Dereference
|
CVE-2026-47220
|
2026-06-30 03:21 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
205
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Hi.Events through 1.9.0 public check-in list endpoints use short_id as sole access control, allowing unauthenticated access to retrieve full attendee lists including emails and personal information. …
New
|
CWE-359
Exposure of Private Personal Information to an Unauthorized Actor
|
CVE-2026-57960
|
2026-06-30 03:16 |
2026-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
206
|
5.9 |
MEDIUM
Network
|
-
|
-
|
Hi.Events through 1.9.0 contains a promo code validation vulnerability where reservation validates usage count before asynchronous UpdateEventStatisticsJob increments it, allowing attackers to redeem…
New
|
CWE-367
Time-of-check Time-of-use (TOCTOU) Race Condition
|
CVE-2026-57959
|
2026-06-30 03:16 |
2026-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
207
|
6.1 |
MEDIUM
Network
|
-
|
-
|
Mixpost through 2.6.0 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to execute arbitrary JavaScript in authenticated users' browsers by crafting malici…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-57958
|
2026-06-30 03:16 |
2026-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208
|
4.7 |
MEDIUM
Network
|
-
|
-
|
Papermark through 0.22.0 contains a cross-origin resource sharing (CORS) misconfiguration vulnerability that allows unauthenticated remote attackers to perform credentialed cross-origin requests by e…
New
|
CWE-942
Permissive Cross-domain Policy with Untrusted Domains
|
CVE-2026-57957
|
2026-06-30 03:16 |
2026-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209
|
6.4 |
MEDIUM
Network
|
-
|
-
|
SigNoz through 0.130.1 contains a broken access control vulnerability that allows authenticated users to access other organizations' alert rules by supplying a target rule UUID, as the alert rule sto…
New
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-57956
|
2026-06-30 03:16 |
2026-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210
|
8.5 |
HIGH
Network
|
-
|
-
|
SigNoz through 0.130.1 contains a SQL injection vulnerability that allows authenticated attackers to execute arbitrary ClickHouse queries by injecting URL-encoded quotes into the rule ID path paramet…
New
|
CWE-89
SQL Injection
|
CVE-2026-57955
|
2026-06-30 03:16 |
2026-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|