|
31
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Bernd Bestel grocy v4.6.0 was discovered to contain a SQL injection vulnerability in the product-group parameter at /stockreports/spendings. This vulnerability allows attackers to access sensitive da…
New
|
CWE-89
SQL Injection
|
CVE-2026-50890
|
2026-06-17 02:16 |
2026-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
32
|
7.5 |
HIGH
Network
|
-
|
-
|
An input handling flaw in the HTTP refresh token process of LLDAP v0.6.2 allows attackers to cause a Denial of Service (DoS) via sending a crafted refresh-token header.
New
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2026-50889
|
2026-06-17 02:16 |
2026-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
33
|
8.1 |
HIGH
Network
|
-
|
-
|
An authenticated Server-Side Request Forgery (SSRF) in the custom scraper subsystem component of Benjamin Jonard Koillection v1.8.0 allows attackers to scan internal resources via supplying a crafted…
New
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-50888
|
2026-06-17 02:16 |
2026-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
34
|
8.8 |
HIGH
Network
|
-
|
-
|
Incorrect access control in statping-ng v0.93.0 allows attackers to escalate privileges to Administrator and access sensitive components.
New
|
CWE-284
Improper Access Control
|
CVE-2026-50884
|
2026-06-17 02:16 |
2026-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
35
|
8.8 |
HIGH
Network
|
-
|
-
|
DbGate is cross-platform database manager. In versions 7.1.8 and prior, the POST /runners/load-reader endpoint in DbGate accepts a functionName parameter that is directly interpolated into a JavaScri…
New
|
CWE-94
Code Injection
|
CVE-2026-48017
|
2026-06-17 02:16 |
2026-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
36
|
- |
|
-
|
-
|
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
New
|
-
|
CVE-2026-39927
|
2026-06-17 02:16 |
2026-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
37
|
- |
|
-
|
-
|
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
New
|
-
|
CVE-2026-39926
|
2026-06-17 02:16 |
2026-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
38
|
- |
|
-
|
-
|
Rejected reason: loading template...
New
|
-
|
CVE-2026-12412
|
2026-06-17 02:16 |
2026-06-17 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
39
|
5.4 |
MEDIUM
Network
|
-
|
-
|
Incorrect boundary conditions in the Internationalization component. This vulnerability was fixed in Firefox ESR 140.12, Firefox ESR 115.37, and Thunderbird 140.12.
New
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2026-12330
|
2026-06-17 02:16 |
2026-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
40
|
5.3 |
MEDIUM
Network
|
-
|
-
|
Memory safety bug fixed in Thunderbird ESR 140.12. This vulnerability was fixed in Firefox ESR 140.12 and Thunderbird 140.12.
New
|
CWE-119 CWE-416 CWE-476
Incorrect Access of Indexable Resource ('Range Error') Use After Free NULL Pointer Dereference
|
CVE-2026-12329
|
2026-06-17 02:16 |
2026-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|