|
131
|
4.3 |
MEDIUM
Network
|
-
|
-
|
Unauthenticated Cross Site Request Forgery (CSRF) in Abandoned Cart Lite for WooCommerce <= 6.8.0 versions.
New
|
CWE-352
Origin Validation Error
|
CVE-2026-57637
|
2026-06-27 02:16 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
132
|
8.8 |
HIGH
Network
|
-
|
-
|
Zed Attack Proxy (ZAP) ViewState add-on before version 4 contains an insecure deserialization vulnerability that allows attackers who control a proxied web server to achieve arbitrary code execution …
New
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-57527
|
2026-06-27 02:16 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
133
|
7.3 |
HIGH
Local
|
vim
|
vim
|
Vim is an open source, command line text editor. From 9.1.1784 until 9.2.0678, when the bundled zip plugin autoload/zip.vim falls back to PowerShell to browse, read, extract, update or delete entries…
New
|
CWE-77
Command Injection
|
CVE-2026-57453
|
2026-06-27 02:16 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
134
|
7.2 |
HIGH
Network
|
-
|
-
|
Dell Wyse Management Suite, versions prior to WMS 5.5 HF1, contain an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. A high privileged attacker with rem…
New
|
CWE-22
Path Traversal
|
CVE-2026-49506
|
2026-06-27 02:16 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
135
|
6.0 |
MEDIUM
Network
|
-
|
-
|
GitHub MCP Server is GitHub's official MCP Server. From 0.22.0 until 1.1.2, when running in HTTP mode with --lockdown-mode enabled, the RepoAccessCache is implemented as a process-global singleton in…
New
|
CWE-284
Improper Access Control
|
CVE-2026-48529
|
2026-06-27 02:16 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
136
|
7.5 |
HIGH
Network
|
-
|
-
|
The TIFF decoder does not set a limit on the size of tiles in tiled images, permitting a malicious or corrupt image containing a very large tile to cause unbounded memory consumption.
New
|
-
|
CVE-2026-46602
|
2026-06-27 02:16 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
137
|
7.5 |
HIGH
Network
|
-
|
-
|
The webp decoder can panic when processing a VP8 chunk with dimensions that do not match the canvas size.
New
|
-
|
CVE-2026-46601
|
2026-06-27 02:16 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
138
|
7.5 |
HIGH
Network
|
-
|
-
|
An integer overflow in the PSD parser compnent of FastStone Image Viewer v8.3 allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via supplying a crafted PSD file.
New
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2026-30041
|
2026-06-27 02:16 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
139
|
6.5 |
MEDIUM
Network
|
-
|
-
|
A heap overflow in the FSViewer.exe process of FastStone Image Viewer v8.3 allows attackers to cause a execute arbitrary code in the context of the current process via supplying a crafted JPEG 2000 (…
New
|
CWE-122
Heap-based Buffer Overflow
|
CVE-2026-30040
|
2026-06-27 02:16 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
140
|
8.3 |
HIGH
Network
|
-
|
-
|
The WSO2 API Manager's message flow component, when processing WS-Addressing headers, does not sufficiently validate or restrict user-controlled input within these headers. This omission allows an at…
New
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-2053
|
2026-06-27 02:16 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|