|
1571
|
6.1 |
MEDIUM
Local
|
-
|
-
|
Summarize versions through 0.14.1, fixed in commit 0cfb0fb, creates the daemon configuration directory and file with default filesystem permissions that may be world-readable on Unix-like systems, al…
Update
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2026-45222
|
2026-05-14 00:30 |
2026-05-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1572
|
8.1 |
HIGH
Network
|
-
|
-
|
MailEnable Enterprise Premium 10.55 and earlier contains an improper authorization vulnerability in the WebAdmin mobile portal that allows attackers to bypass authentication checks by reusing Authent…
Update
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-44400
|
2026-05-14 00:30 |
2026-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1573
|
8.1 |
HIGH
Network
|
-
|
-
|
SmarterTools SmarterMail builds prior to 9560 contain a local file inclusion vulnerability in the /api/v1/report/summary/{type} API endpoint that allows authenticated users to read arbitrary .json fi…
Update
|
CWE-22
Path Traversal
|
CVE-2026-7807
|
2026-05-14 00:29 |
2026-05-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1574
|
8.8 |
HIGH
Network
|
-
|
-
|
CyberPanel 2.1 contains a command execution vulnerability that allows authenticated attackers to read arbitrary files and execute remote code by exploiting symlink attacks through the filemanager con…
Update
|
CWE-59
Link Following
|
CVE-2021-47949
|
2026-05-14 00:29 |
2026-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1575
|
6.1 |
MEDIUM
Network
|
-
|
-
|
Drupal avatar_uploader 7.x-1.0-beta8 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by manipulating the file parameter. Atta…
Update
|
CWE-79
Cross-site Scripting
|
CVE-2022-50957
|
2026-05-14 00:29 |
2026-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1576
|
6.1 |
MEDIUM
Network
|
-
|
-
|
Moodle LMS 4.0 contains a cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts by submitting payloads through the search parameter. Attackers can injec…
Update
|
CWE-79
Cross-site Scripting
|
CVE-2022-50943
|
2026-05-14 00:27 |
2026-05-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1577
|
8.8 |
HIGH
Network
|
-
|
-
|
SPIP versions prior to 4.4.14 contain a remote code execution vulnerability in the private space that allows attackers to execute arbitrary code in the context of the web server. Attackers can exploi…
New
|
CWE-94
Code Injection
|
CVE-2026-8429
|
2026-05-14 00:26 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1578
|
8.1 |
HIGH
Network
|
-
|
-
|
SPIP versions prior to 4.4.14 contain a remote code execution vulnerability in the public space that is limited to certain nginx configurations, allowing attackers to execute arbitrary code in the co…
New
|
CWE-94
Code Injection
|
CVE-2026-8430
|
2026-05-14 00:26 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1579
|
7.1 |
HIGH
Network
|
-
|
-
|
Heym before 0.0.21 contains an authorization bypass vulnerability in workflow execution that allows authenticated users to execute arbitrary workflows by referencing victim workflow UUIDs without pro…
New
|
CWE-863
Incorrect Authorization
|
CVE-2026-45226
|
2026-05-14 00:26 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1580
|
6.5 |
MEDIUM
Network
|
-
|
-
|
The The Advanced Custom Fields: Extended plugin for WordPress is vulnerable to arbitrary shortcode execution in all versions up to, and including, 0.9.2.3. This is due to the software allowing users …
New
|
CWE-94
Code Injection
|
CVE-2025-15463
|
2026-05-14 00:26 |
2026-05-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|