|
511
|
7.5 |
HIGH
Network
|
-
|
-
|
Unauthenticated Sensitive Data Exposure in ABC Crypto Checkout <= 1.8.2 versions.
New
|
CWE-201
Insertion of Sensitive Information Into Sent Data
|
CVE-2026-52695
|
2026-06-16 06:24 |
2026-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
512
|
8.5 |
HIGH
Network
|
-
|
-
|
Subscriber SQL Injection in Taskbuilder <= 5.0.7 versions.
New
|
CWE-89
SQL Injection
|
CVE-2026-52697
|
2026-06-16 06:24 |
2026-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
513
|
7.5 |
HIGH
Network
|
-
|
-
|
Unauthenticated Insecure Direct Object References (IDOR) in VikRentCar <= 1.4.5 versions.
New
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-52699
|
2026-06-16 06:24 |
2026-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
514
|
8.5 |
HIGH
Network
|
-
|
-
|
Subscriber SQL Injection in WCMultiShipping <= 3.0.2 versions.
New
|
CWE-89
SQL Injection
|
CVE-2026-52700
|
2026-06-16 06:24 |
2026-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
515
|
7.1 |
HIGH
Network
|
-
|
-
|
Unauthenticated Cross Site Scripting (XSS) in SEO Redirection <= 9.17 versions.
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-52702
|
2026-06-16 06:24 |
2026-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
516
|
9.6 |
CRITICAL
Network
|
-
|
-
|
Unauthenticated Path Traversal in FastDup <= 2.7.2 versions.
New
|
CWE-35
Path Traversal: '.../...//'
|
CVE-2026-52703
|
2026-06-16 06:24 |
2026-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
517
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Unauthenticated PHP Object Injection in Integration for ActiveCampaign and Contact Form 7, WPForms, Elementor, Ninja Forms <= 1.1.1 versions.
New
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-9691
|
2026-06-16 06:24 |
2026-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
518
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 1.0.0 to before version 2.2.0, the Nezha dashboard exposes two endpoints that create long-…
New
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2026-53522
|
2026-06-16 06:17 |
2026-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
519
|
7.1 |
HIGH
Network
|
-
|
-
|
Nezha Monitoring is a self-hostable, lightweight, servers and websites monitoring and O&M tool. From version 0.20.0 to before version 2.0.12, authenticated agents can forge service-monitor results fo…
New
|
CWE-862
Missing Authorization
|
CVE-2026-48119
|
2026-06-16 06:17 |
2026-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
520
|
- |
|
-
|
-
|
PenguinMod-BackendApi is the backend api for penguinmod. Prior to version 1.0.0, a NoSQL injection vulnerability in the password reset endpoint allows any authenticated user to change the password of…
Update
|
CWE-20 CWE-943
Improper Input Validation Improper Neutralization of Special Elements in Data Query Logic
|
CVE-2026-47181
|
2026-06-16 06:17 |
2026-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|