|
121
|
- |
|
-
|
-
|
backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. Versions prior to 5.0.13, 4.1.…
New
|
CWE-79
Cross-site Scripting
|
CVE-2022-31114
|
2026-06-5 01:18 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
122
|
- |
|
-
|
-
|
A DLL hijacking vulnerability in Wassimulator (GitHub) CactusViewer v2.3.0 allows attackers to escalate privileges and execute arbitrary code via a crafted DLL.
New
|
-
|
CVE-2026-36574
|
2026-06-5 01:18 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
123
|
- |
|
-
|
-
|
Missing input validation in the rfapiRibBi2Ri() function (rfapi_rib.c) of FRRouting (FRR) stable/10.0 to stable/10.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted BGP UP…
New
|
-
|
CVE-2026-37460
|
2026-06-5 01:17 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
124
|
7.1 |
HIGH
Adjacent
|
-
|
-
|
Version 3.0.7 of the Securly Chrome Extension downloads JSON files containing crisis alert keywords and filtering rules over unencrypted HTTP via the Fetch API. Other endpoints in the same extension …
New
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2026-8874
|
2026-06-5 01:16 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
125
|
5.3 |
MEDIUM
Network
|
-
|
-
|
Strawberry GraphQL is a library for creating GraphQL APIs. In versions 0.172.0 through0.315.6, the MaxAliasesLimiter extension in Strawberry fails to account for the multiplicative/amplification effe…
New
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2026-47707
|
2026-06-5 01:16 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
126
|
- |
|
-
|
-
|
Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Versions prior to 2.17.1 are vulnerable to remote code execution via the newsletter custom template directory feature. O…
New
|
CWE-1336
Improper Neutralization of Special Elements Used in a Template Engine
|
CVE-2026-41065
|
2026-06-5 01:16 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
127
|
- |
|
-
|
-
|
Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to version 2.17.1, a path traversal vulnerability in the cache deletion endpoint allows authenticated API access t…
New
|
CWE-22 CWE-73
Path Traversal External Control of File Name or Path
|
CVE-2026-40605
|
2026-06-5 01:16 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
128
|
4.6 |
MEDIUM
Physics
|
-
|
-
|
The factory reset functionality in GNCC GP5 v7.1.76 fails to clear sensitive cryptographic material in the JFFS2 configuration partition, possibly allowing attackers to recover and obtain sensitive u…
New
|
CWE-212
Improper Removal of Sensitive Information Before Storage or Transfer
|
CVE-2026-36178
|
2026-06-5 01:16 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
129
|
6.5 |
MEDIUM
Network
|
-
|
-
|
(*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, ".") to execute repeatedly on the sa…
New
|
-
|
CVE-2026-27145
|
2026-06-5 01:15 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
130
|
7.5 |
HIGH
Network
|
-
|
-
|
Decoding a maliciously-crafted MIME header containing many invalid encoded-words can consume excessive CPU.
New
|
CWE-407
Inefficient Algorithmic Complexity
|
CVE-2026-42504
|
2026-06-5 01:15 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|