|
671
|
- |
|
-
|
-
|
CWE-617 Reachable Assertion vulnerability exists that could allow an authenticated attacker to trigger a denial-of-service condition, impacting system availability when a specially crafted request is…
New
|
CWE-617
Reachable Assertion
|
CVE-2026-9718
|
2026-06-26 04:10 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
672
|
5.4 |
MEDIUM
Network
|
-
|
-
|
The AI Share & Summarize WordPress plugin before 2.0.4 does not sanitise and escape some of its shortcode attributes before outputting them in a page, allowing users with the Contributor role and abo…
New
|
-
|
CVE-2026-10531
|
2026-06-26 04:07 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
673
|
7.5 |
HIGH
Network
|
-
|
-
|
Multiple Shapedsmart-post-show-pro WordPress plugin before 4.0.2, Real Testimonials Pro WordPress plugin before 3.2.5, Product Slider for WooCommerce Pro WordPress plugin before 3.5.3 Pro smart-post-…
New
|
-
|
CVE-2026-10735
|
2026-06-26 04:07 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
674
|
7.2 |
HIGH
Network
|
-
|
-
|
The Post Duplicator WordPress plugin before 3.0.15 does not safely handle custom meta-data during post duplication, storing attacker-supplied serialized values without the WordPress meta API's double…
New
|
-
|
CVE-2026-10749
|
2026-06-26 04:07 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
675
|
2.7 |
LOW
Network
|
-
|
-
|
The Site Kit by Google WordPress plugin before 1.176.0 does not properly restrict a REST API write endpoint to administrators, allowing lower-privileged users who have been granted dashboard sharing…
New
|
-
|
CVE-2026-10753
|
2026-06-26 04:07 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
676
|
7.7 |
HIGH
Network
|
-
|
-
|
The Cornerstone WordPress plugin before 7.8.9 does not enforce capability checks on one of its REST API routes, allowing any authenticated user to disclose the metadata of any other user, including r…
New
|
-
|
CVE-2026-9709
|
2026-06-26 04:07 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
677
|
7.7 |
HIGH
Network
|
-
|
-
|
The Cornerstone WordPress plugin before 7.8.8 does not enforce capability checks on one of its CSS-preview request handlers, and exposes the nonce needed to call it to every logged-in user on any wp-…
New
|
-
|
CVE-2026-9710
|
2026-06-26 04:07 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
678
|
7.5 |
HIGH
Network
|
microsoft
|
365_copilot
|
Missing authentication for critical function in M365 Copilot allows an unauthorized attacker to disclose information over a network.
New
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2026-54130
|
2026-06-26 03:59 |
2026-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
679
|
6.5 |
MEDIUM
Adjacent
|
-
|
-
|
The Zephyr PL011 UART driver (drivers/serial/uart_pl011.c) contains an unbounded software loop in pl011_irq_tx_enable() that repeatedly invokes the interrupt-driven application callback while the TX …
New
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2026-10642
|
2026-06-26 03:58 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
680
|
5.3 |
MEDIUM
Network
|
-
|
-
|
LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. Prior to 0.8.4-rc1, the GET /api/auth/2fa/enable endpoint can be called by an authenticated user (or attacker with a stolen…
New
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2026-54036
|
2026-06-26 03:58 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|