|
181
|
4.3 |
MEDIUM
Network
|
-
|
-
|
Sharp is a content management framework built for Laravel as a package. From version 9.0.0 to before version 9.22.3, the create and store endpoints of the Quick Creation Command feature did not enfor…
New
|
CWE-862
Missing Authorization
|
CVE-2026-53634
|
2026-06-12 00:31 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
182
|
7.6 |
HIGH
Network
|
-
|
-
|
Xibo is an open source digital signage platform with a web content management system and Windows display player software. Prior to 4.4.2, a vulnerability chain consisting of Stored XSS and Iframe San…
New
|
CWE-79 CWE-116 CWE-346
Cross-site Scripting Improper Encoding or Escaping of Output Origin Validation Error
|
CVE-2026-42558
|
2026-06-12 00:30 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
183
|
4.3 |
MEDIUM
Network
|
-
|
-
|
Yamcs is a mission control framework. Prior to versions 5.13.0 and 5.12.7, an LDAP injection vulnerability exists in `org.yamcs.security.LdapAuthModule` when constructing search filters. The username…
New
|
CWE-90
LDAP Injection
|
CVE-2026-42568
|
2026-06-12 00:30 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
184
|
4.3 |
MEDIUM
Network
|
-
|
-
|
SQLAdmin is a flexible Admin interface for SQLAlchemy models. Prior to version 0.25.1, the ajax_lookup endpoint in application.py bypasses the is_accessible() access control check that all other endp…
New
|
CWE-862
Missing Authorization
|
CVE-2026-46645
|
2026-06-12 00:30 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
185
|
7.8 |
HIGH
Local
|
-
|
-
|
A local privilege escalation vulnerability exists in Check Point Identity Agent Full for Windows OS. An authenticated local user may be able to execute arbitrary code with SYSTEM privileges due to im…
New
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2026-10847
|
2026-06-12 00:30 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
186
|
6.6 |
MEDIUM
Local
|
-
|
-
|
Authentication bypass by primary weakness vulnerability in ABB Freelance.
This issue affects Freelance: through 2013, 2013 SP1, 2016, 2016 SP1, 2019, 2019 SP1, 2019 SP1 FP1, 2024.
New
|
CWE-305
Authentication Bypass by Primary Weakness
|
CVE-2025-7064
|
2026-06-12 00:28 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
187
|
- |
|
-
|
-
|
Golem OEE MES is vulnerable to an unauthenticated path traversal flaw. This vulnerability allows an attacker in the same local network to read arbitrary files from the server's operating system by ma…
New
|
CWE-22
Path Traversal
|
CVE-2026-8464
|
2026-06-12 00:28 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
188
|
5.3 |
MEDIUM
Network
|
-
|
-
|
Improper neutralization of special elements used in an expression language statement ('expression language injection') vulnerability in Soagen Informatics Technologies Software and Consulting Inc. Ap…
New
|
CWE-917
Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')
|
CVE-2026-11561
|
2026-06-12 00:28 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
189
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Unrestricted upload of file with dangerous type vulnerability in Limatek System Inc. LimRAD NAC allows Remote Code Inclusion.
This issue affects LimRAD NAC: before 5.5.7.3.9.
New
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2026-7852
|
2026-06-12 00:28 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
190
|
7.9 |
HIGH
Local
|
microsoft
|
windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2012 windows_server_2016 w…
|
Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.
New
|
CWE-693
Protection Mechanism Failure
|
CVE-2026-45588
|
2026-06-12 00:25 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|