|
331
|
- |
|
-
|
-
|
Frappe is a full-stack web application framework. Prior to versions 15.107.0 and 16.17.0, lack of validations in the "submit_discussion()" endpoint allows for unauthorized access to resources. This i…
New
|
CWE-284 CWE-285
Improper Access Control Improper Authorization
|
CVE-2026-44208
|
2026-06-13 01:17 |
2026-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
332
|
- |
|
-
|
-
|
Frappe is a full-stack web application framework. Prior to versions 15.107.2 and 16.17.4, any authenticated user can reset onboarding for all users in the system. This issue has been patched in versi…
New
|
CWE-862
Missing Authorization
|
CVE-2026-44975
|
2026-06-13 01:17 |
2026-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
333
|
- |
|
-
|
-
|
Frappe is a full-stack web application framework. Prior to version 16.17.4, any authenticated user can access private files by guessing the file path. This issue has been patched in version 16.17.4.
New
|
CWE-284
Improper Access Control
|
CVE-2026-47182
|
2026-06-13 01:17 |
2026-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
334
|
- |
|
-
|
-
|
Frappe is a full-stack web application framework. Prior to versions 15.107.0 and 16.17.0, a lack of permission checks in these endpoints allowed unauthorized access to resources. This issue has been …
New
|
CWE-862
Missing Authorization
|
CVE-2026-50026
|
2026-06-13 01:17 |
2026-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
335
|
- |
|
-
|
-
|
Frappe is a full-stack web application framework. Prior to versions 15.107.2 and 16.17.4, there is a stored XSS vulnerablity in Frappe Report/List View. This issue has been patched in versions 15.107…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-53568
|
2026-06-13 01:17 |
2026-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
336
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Authentication bypass by spoofing vulnerability in Hedef Media Promotion Interactive Media Marketing Inc. Related Marketing Cloud (RMC) allows Brute Force.
This issue affects Related Marketing Cloud…
New
|
CWE-290
Authentication Bypass by Spoofing
|
CVE-2026-5792
|
2026-06-13 01:17 |
2026-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
337
|
5.9 |
MEDIUM
Network
|
-
|
-
|
Vulnerability Title
New
|
-
|
CVE-2026-9271
|
2026-06-13 01:16 |
2026-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
338
|
5.3 |
MEDIUM
Network
|
-
|
-
|
Improper access control in Devolutions PowerShell Universal 2026.1.7 and earlier allows an unauthenticated remote attacker to obtain the OpenAPI specification of user-defined REST endpoints.
New
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2026-8694
|
2026-06-13 01:16 |
2026-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
339
|
9.8 |
CRITICAL
Network
|
-
|
-
|
jmespath.php allows users to use JMESPath, software for declaratively specifying how to extract elements from a JSON document, in PHP applications with PHP data structures. Versions prior to 2.9.1 ca…
New
|
CWE-20 CWE-94 CWE-116
Improper Input Validation Code Injection Improper Encoding or Escaping of Output
|
CVE-2026-54133
|
2026-06-13 01:16 |
2026-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
340
|
5.3 |
MEDIUM
Network
|
-
|
-
|
The 'clientId' parameter from incoming HTTP requests is directly concatenated into OAuth2 server log warning messages without sanitizing control characters. This allows an attacker to inject arbitrar…
New
|
CWE-93
CRLF Injection
|
CVE-2026-50629
|
2026-06-13 01:16 |
2026-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|