|
211
|
4.3 |
MEDIUM
Network
|
-
|
-
|
Elide through 7.1.17 fails to enforce @ReadPermission on client-supplied sort expressions in SortingImpl.getValidSortingRules, allowing attackers to sort collections by forbidden fields. Attackers ca…
New
|
CWE-862
Missing Authorization
|
CVE-2026-57954
|
2026-06-30 03:16 |
2026-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212
|
5.4 |
MEDIUM
Network
|
-
|
-
|
Mythic before 3.4.0.60 contains an authorization bypass vulnerability that allows authenticated spectator-role users to perform unauthorized write operations by accessing the eventing_import_automati…
New
|
CWE-863
Incorrect Authorization
|
CVE-2026-57953
|
2026-06-30 03:16 |
2026-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213
|
5.3 |
MEDIUM
Network
|
-
|
-
|
Mythic before 3.4.0.60 contains an authorization bypass vulnerability in four REST endpoints (c2profile_config_check_webhook, c2profile_redirect_rules_webhook, c2profile_get_ioc_webhook, c2profile_sa…
New
|
CWE-862
Missing Authorization
|
CVE-2026-57952
|
2026-06-30 03:16 |
2026-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
214
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Mythic before 3.4.0.60 contains a broken hasura permission filter on the payload_build_step table with an always-satisfied _or condition that bypasses operation-scoped access controls. Authenticated …
New
|
CWE-863
Incorrect Authorization
|
CVE-2026-57951
|
2026-06-30 03:16 |
2026-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
215
|
8.1 |
HIGH
Network
|
-
|
-
|
ruoyi-vue-pro through 2026.05, fixed in commit 5d1fd70 contains a broken access control vulnerability in ErpSaleOrderController that allows attackers with erp:sale-out permissions to gain unauthorize…
New
|
CWE-863
Incorrect Authorization
|
CVE-2026-57950
|
2026-06-30 03:16 |
2026-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
216
|
6.5 |
MEDIUM
Network
|
-
|
-
|
ruoyi-vue-pro through 2026.05, fixed in commit c779a47, contains a missing authorization vulnerability in the CRM module's GET /admin-api/crm/follow-up-record/get endpoint that allows authenticated u…
New
|
CWE-862
Missing Authorization
|
CVE-2026-57949
|
2026-06-30 03:16 |
2026-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
217
|
6.8 |
MEDIUM
Network
|
-
|
-
|
Pinpoint through version 3.1.0 contains an insecure session management vulnerability that allows attackers to access the pinpointJwt session cookie due to missing HttpOnly and Secure attributes, enab…
New
|
CWE-614 CWE-1004
Sensitive Cookie in HTTPS Session Without 'Secure' Attribute Sensitive Cookie Without 'HttpOnly' Flag
|
CVE-2026-57948
|
2026-06-30 03:16 |
2026-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218
|
8.5 |
HIGH
Network
|
-
|
-
|
Pinpoint through 3.1.0 contains a server-side request forgery vulnerability in the webhook registration endpoint that allows authenticated users to register internal URLs due to missing SSRF protecti…
New
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-57947
|
2026-06-30 03:16 |
2026-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219
|
3.7 |
LOW
Network
|
-
|
-
|
Invidious before version 2.20260626.0 contains a broken access control vulnerability that allows unauthenticated attackers to retrieve private playlist contents by accessing the RSS feed playlist end…
New
|
CWE-862
Missing Authorization
|
CVE-2026-57946
|
2026-06-30 03:16 |
2026-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
220
|
4.3 |
MEDIUM
Network
|
-
|
-
|
PhotoPrism before 260601-a7d098548 contains a broken access control vulnerability that allows authenticated non-admin users to modify other users' profile information by sending requests to arbitrary…
New
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-57945
|
2026-06-30 03:16 |
2026-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|