|
861
|
7.5 |
HIGH
Network
|
joomla
|
joomla\!
|
Insufficient state checks lead to a vector that allows to bypass 2FA checks.
|
CWE-287 NVD-CWE-noinfo
Improper Authentication
|
CVE-2026-48896
|
2026-05-29 04:46 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
862
|
7.5 |
HIGH
Network
|
joomla
|
joomla\!
|
Insufficient state checks lead to a vector that allows to bypass 2FA checks.
|
CWE-287
Improper Authentication
|
CVE-2026-48897
|
2026-05-29 04:40 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
863
|
8.2 |
HIGH
Network
|
-
|
-
|
deepobj provides get, set, delete deep objects in javascript. Prior to 1.0.3, prototype pollution is possible when property paths contain __proto__/constructor/prototype. The property path must not b…
|
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
|
CVE-2026-46509
|
2026-05-29 04:16 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
864
|
7.5 |
HIGH
Network
|
joomla
|
joomla\!
|
An improper validation of the search parameter of the com_media files API endpoint leads to a path traversal vulnerability.
|
CWE-22
Path Traversal
|
CVE-2026-40384
|
2026-05-29 04:07 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
865
|
9.8 |
CRITICAL
Network
|
joomla
|
joomla\!
|
An improper access check allows unauthorized access to com_config webservice endpoints.
|
CWE-284 NVD-CWE-noinfo
Improper Access Control
|
CVE-2026-35223
|
2026-05-29 04:07 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
866
|
7.8 |
HIGH
Local
|
-
|
-
|
Microsoft UFO open-source framework for intelligent automation across devices and platforms. Microsoft UFO tagged releases up to and including v3.0.0 contain an OS command injection vulnerability in …
|
CWE-78
OS Command
|
CVE-2026-45322
|
2026-05-29 03:56 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
867
|
8.8 |
HIGH
Network
|
-
|
-
|
Microsoft UFO open-source framework for intelligent automation across devices and platforms. In 3.0.1-4-ge2626659, Microsoft UFO's WebSocket control plane trusts client-supplied identity and role fie…
|
CWE-290 CWE-639 CWE-862
Authentication Bypass by Spoofing Authorization Bypass Through User-Controlled Key Missing Authorization
|
CVE-2026-46414
|
2026-05-29 03:56 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
868
|
6.3 |
MEDIUM
Network
|
-
|
-
|
Microsoft UFO open-source framework for intelligent automation across devices and platforms. In 3.0.1-4-ge2626659, Microsoft UFO creates one shared UFOWebSocketHandler instance and reuses it for mult…
|
CWE-284 CWE-488
Improper Access Control Exposure of Data Element to Wrong Session
|
CVE-2026-46416
|
2026-05-29 03:56 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
869
|
5.9 |
MEDIUM
Network
|
-
|
-
|
Microsoft UFO open-source framework for intelligent automation across devices and platforms. In 3.0.1-4-ge2626659, Microsoft UFO's constellation client tracks pending task responses by session_id onl…
|
CWE-294 CWE-345
Authentication Bypass by Capture-replay Insufficient Verification of Data Authenticity
|
CVE-2026-46538
|
2026-05-29 03:56 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
870
|
5.3 |
MEDIUM
Network
|
-
|
-
|
Microsoft UFO open-source framework for intelligent automation across devices and platforms. In 3.0.1-4-ge2626659, Microsoft UFO accepts client-supplied session_id values in WebSocket task messages a…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-46544
|
2026-05-29 03:56 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|