|
521
|
7.4 |
HIGH
Network
|
-
|
-
|
Subscriber Sensitive Data Exposure in Visual Link Preview <= 2.3.1 versions.
New
|
CWE-201
Insertion of Sensitive Information Into Sent Data
|
CVE-2026-54821
|
2026-06-26 09:16 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
522
|
9.9 |
CRITICAL
Network
|
-
|
-
|
SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, the attribute-view (database) cell renderer genAVValueHTML interpolates cell content raw in four of its branches: text, …
New
|
CWE-79 CWE-1188
Cross-site Scripting Insecure Default Initialization of Resource
|
CVE-2026-54158
|
2026-06-26 09:16 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
523
|
6.1 |
MEDIUM
Local
|
-
|
-
|
Chrome DevTools for agents (chrome-devtools-mcp) lets your coding agent control and inspect a live Chrome browser. From 0.24.0 until 1.1.0, McpContext.validatePath() enforces workspace roots by check…
New
|
CWE-22 CWE-59
Path Traversal Link Following
|
CVE-2026-53766
|
2026-06-26 09:16 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
524
|
- |
|
-
|
-
|
Gogs is an open source self-hosted Git service. Prior to 0.14.3, Git LFS storage is content-addressed by OID alone (<LFS-root>/<oid[0]>/<oid[1]>/<oid>) but per-repo authorization lives in the lfs_obj…
New
|
CWE-345 CWE-639 CWE-862
Insufficient Verification of Data Authenticity Authorization Bypass Through User-Controlled Key Missing Authorization
|
CVE-2026-52812
|
2026-06-26 09:16 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
525
|
9.8 |
CRITICAL
Network
|
cacti
|
cacti
|
Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior are vulnerable to Command Injection due to lack of sanitization in the escape_command() function. The esc…
New
|
CWE-78 CWE-88
OS Command Argument Injection
|
CVE-2026-40079
|
2026-06-26 09:16 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
526
|
5.3 |
MEDIUM
Network
|
cacti
|
cacti
|
Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior are vulnerable to Path Traversal via filename parameter in package_import.php. This issue has been fixed …
New
|
CWE-22
Path Traversal
|
CVE-2026-39899
|
2026-06-26 09:16 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
527
|
7.3 |
HIGH
Local
|
-
|
-
|
A flaw was found in KubeVirt's safepath package used by virt-handler. The OpenAtNoFollow function uses O_PATH|O_NOFOLLOW to obtain a file descriptor to a path leaf, but downstream operations resolve …
New
|
CWE-61
UNIX Symbolic Link (Symlink) Following
|
CVE-2026-13201
|
2026-06-26 09:16 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
528
|
6.5 |
MEDIUM
Network
|
-
|
-
|
The Dokan Pro plugin for WordPress is vulnerable to time-based SQL Injection via the ’orderby’ parameter in all versions up to, and including, 5.0.4 due to insufficient escaping on the user supplied …
New
|
CWE-89
SQL Injection
|
CVE-2026-12079
|
2026-06-26 09:16 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
529
|
6.5 |
MEDIUM
Network
|
-
|
-
|
A flaw was found in the community.general Ansible collection's nexmo module.
The module constructs HTTP requests to the Vonage/Nexmo SMS API by encoding
API credentials (api_key and api_secret) into …
New
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2026-11820
|
2026-06-26 09:16 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
530
|
6.5 |
MEDIUM
Network
|
-
|
-
|
motionEye (mEye) is an online interface for motion software, which is a video surveillance program with motion detection. Versions prior to 0.44.0 are vulnerable to path traversal in the picture and …
New
|
CWE-22 CWE-284
Path Traversal Improper Access Control
|
CVE-2026-31978
|
2026-06-26 08:17 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|