|
921
|
4.3 |
MEDIUM
Network
|
-
|
-
|
Unauthenticated Cross Site Request Forgery (CSRF) in Abandoned Cart Lite for WooCommerce <= 6.8.0 versions.
|
CWE-352
Origin Validation Error
|
CVE-2026-57637
|
2026-06-27 02:16 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
922
|
8.8 |
HIGH
Network
|
-
|
-
|
Zed Attack Proxy (ZAP) ViewState add-on before version 4 contains an insecure deserialization vulnerability that allows attackers who control a proxied web server to achieve arbitrary code execution …
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-57527
|
2026-06-27 02:16 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
923
|
7.3 |
HIGH
Local
|
vim
|
vim
|
Vim is an open source, command line text editor. From 9.1.1784 until 9.2.0678, when the bundled zip plugin autoload/zip.vim falls back to PowerShell to browse, read, extract, update or delete entries…
|
CWE-77
Command Injection
|
CVE-2026-57453
|
2026-06-27 02:16 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
924
|
7.2 |
HIGH
Network
|
-
|
-
|
Dell Wyse Management Suite, versions prior to WMS 5.5 HF1, contain an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability. A high privileged attacker with rem…
|
CWE-22
Path Traversal
|
CVE-2026-49506
|
2026-06-27 02:16 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
925
|
7.5 |
HIGH
Network
|
-
|
-
|
The TIFF decoder does not set a limit on the size of tiles in tiled images, permitting a malicious or corrupt image containing a very large tile to cause unbounded memory consumption.
|
-
|
CVE-2026-46602
|
2026-06-27 02:16 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
926
|
7.5 |
HIGH
Network
|
-
|
-
|
The webp decoder can panic when processing a VP8 chunk with dimensions that do not match the canvas size.
|
-
|
CVE-2026-46601
|
2026-06-27 02:16 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
927
|
7.5 |
HIGH
Network
|
-
|
-
|
An integer overflow in the PSD parser compnent of FastStone Image Viewer v8.3 allows attackers to execute arbitrary code or cause a Denial of Service (DoS) via supplying a crafted PSD file.
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2026-30041
|
2026-06-27 02:16 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
928
|
6.5 |
MEDIUM
Network
|
-
|
-
|
A heap overflow in the FSViewer.exe process of FastStone Image Viewer v8.3 allows attackers to cause a execute arbitrary code in the context of the current process via supplying a crafted JPEG 2000 (…
|
CWE-122
Heap-based Buffer Overflow
|
CVE-2026-30040
|
2026-06-27 02:16 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
929
|
8.4 |
HIGH
Local
|
-
|
-
|
Broken Access Control in the devLXDInstancePatchHandler component of Canonical LXD allows an untrusted guest to mount, read, and overwrite another guest's custom storage volume via a crafted device P…
|
CWE-639 CWE-862
Authorization Bypass Through User-Controlled Key Missing Authorization
|
CVE-2026-12411
|
2026-06-27 02:16 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
930
|
7.5 |
HIGH
Network
|
-
|
-
|
Bytes::Random::Secure::Tiny versions through 1.011 for Perl share internal state across forked processes.
When an object is initialised before forking, then the internal state for the PRNG is shared…
|
CWE-335
Incorrect Usage of Seeds in Pseudo-Random Number Generator (PRNG)
|
CVE-2026-11702
|
2026-06-27 02:16 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|