|
3251
|
- |
|
-
|
-
|
A mass assignment vulnerability exists in the MISP user edit functionality due to insufficient filtering of user-supplied fields in UsersController::edit(). When processing edit requests, the applica…
|
CWE-269
Improper Privilege Management
|
CVE-2026-10868
|
2026-06-5 01:20 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3252
|
8.8 |
HIGH
Network
|
-
|
-
|
Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Versions prior to 2.17.1 expose `configUpdate` as a state-changing administrator endpoint, but the route does not enforc…
|
CWE-352
Origin Validation Error
|
CVE-2026-43985
|
2026-06-5 01:20 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3253
|
6.1 |
MEDIUM
Network
|
-
|
-
|
Cross Site Scripting vulnerability in usememos Memos v.0.26.0 allows a remote attacker to obtain sensitive information via the SANITIZE_SCHEMA, Memo Rendering Component, and Public/Private Memo View …
|
CWE-79
Cross-site Scripting
|
CVE-2026-30586
|
2026-06-5 01:18 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3254
|
5.0 |
MEDIUM
Local
|
-
|
-
|
A NULL pointer dereference in the gf_filter_pid_resolve_file_template_ex function (/filter_core/filter_pid.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS)…
|
CWE-476
NULL Pointer Dereference
|
CVE-2025-60477
|
2026-06-5 01:18 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3255
|
- |
|
-
|
-
|
backpack/crud provides Create, Read, Update & Delete (CRUD) functions for Backpack, a collection of Laravel packages that help users build custom administration panels. Versions prior to 5.0.13, 4.1.…
|
CWE-79
Cross-site Scripting
|
CVE-2022-31114
|
2026-06-5 01:18 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3256
|
- |
|
-
|
-
|
Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Versions prior to 2.17.1 are vulnerable to remote code execution via the newsletter custom template directory feature. O…
|
CWE-1336
Improper Neutralization of Special Elements Used in a Template Engine
|
CVE-2026-41065
|
2026-06-5 01:16 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3257
|
- |
|
-
|
-
|
Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Prior to version 2.17.1, a path traversal vulnerability in the cache deletion endpoint allows authenticated API access t…
|
CWE-22 CWE-73
Path Traversal External Control of File Name or Path
|
CVE-2026-40605
|
2026-06-5 01:16 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3258
|
4.6 |
MEDIUM
Physics
|
-
|
-
|
The factory reset functionality in GNCC GP5 v7.1.76 fails to clear sensitive cryptographic material in the JFFS2 configuration partition, possibly allowing attackers to recover and obtain sensitive u…
|
CWE-212
Improper Removal of Sensitive Information Before Storage or Transfer
|
CVE-2026-36178
|
2026-06-5 01:16 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3259
|
6.5 |
MEDIUM
Network
|
-
|
-
|
(*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, ".") to execute repeatedly on the sa…
|
-
|
CVE-2026-27145
|
2026-06-5 01:15 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3260
|
7.5 |
HIGH
Network
|
-
|
-
|
Decoding a maliciously-crafted MIME header containing many invalid encoded-words can consume excessive CPU.
|
CWE-407
Inefficient Algorithmic Complexity
|
CVE-2026-42504
|
2026-06-5 01:15 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|