|
131
|
5.9 |
MEDIUM
Network
|
-
|
-
|
Vulnerability Title
New
|
-
|
CVE-2026-9271
|
2026-06-13 01:16 |
2026-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
132
|
5.3 |
MEDIUM
Network
|
-
|
-
|
Improper access control in Devolutions PowerShell Universal 2026.1.7 and earlier allows an unauthenticated remote attacker to obtain the OpenAPI specification of user-defined REST endpoints.
New
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2026-8694
|
2026-06-13 01:16 |
2026-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
133
|
9.8 |
CRITICAL
Network
|
-
|
-
|
jmespath.php allows users to use JMESPath, software for declaratively specifying how to extract elements from a JSON document, in PHP applications with PHP data structures. Versions prior to 2.9.1 ca…
New
|
CWE-20 CWE-94 CWE-116
Improper Input Validation Code Injection Improper Encoding or Escaping of Output
|
CVE-2026-54133
|
2026-06-13 01:16 |
2026-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
134
|
5.3 |
MEDIUM
Network
|
-
|
-
|
The 'clientId' parameter from incoming HTTP requests is directly concatenated into OAuth2 server log warning messages without sanitizing control characters. This allows an attacker to inject arbitrar…
New
|
CWE-93
CRLF Injection
|
CVE-2026-50629
|
2026-06-13 01:16 |
2026-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
135
|
6.5 |
MEDIUM
Network
|
-
|
-
|
An authentication bypass vulnerability exists in the OAuth2 TokenIntrospectionService in Apache CXF. Due to a missing 'throw' keyword in the security context check, the introspection endpoint (/servi…
New
|
CWE-287
Improper Authentication
|
CVE-2026-50623
|
2026-06-13 01:16 |
2026-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
136
|
10.0 |
CRITICAL
Network
|
-
|
-
|
vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, VM2 suffers from a sandbox breakout vulnerability. This allows attackers to write code which can escape from the VM2 sandbox and…
New
|
CWE-913
Improper Control of Dynamically-Managed Code Resources
|
CVE-2026-47208
|
2026-06-13 01:16 |
2026-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
137
|
- |
|
-
|
-
|
Quest Bot is an opensource Discord Bot. Prior to version 1.1.6, the automod add command trims user input but does not reject an empty result. Adding a rule containing only whitespace stores an empty …
New
|
CWE-20
Improper Input Validation
|
CVE-2026-47196
|
2026-06-13 01:16 |
2026-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
138
|
8.8 |
HIGH
Network
|
-
|
-
|
ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 - #132, any authenticated user who can upload videos can add multiple subtitles from different files and change their ti…
New
|
CWE-89
SQL Injection
|
CVE-2026-45418
|
2026-06-13 01:16 |
2026-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
139
|
1.8 |
LOW
Physics
|
-
|
-
|
A vulnerability was identified in Groww Stock, Mutual Fund, Gold App up to 20260805 on Android. This affects an unknown part of the component WebView URL Handler. The manipulation leads to improper a…
New
|
CWE-285 CWE-939
Improper Authorization Improper Authorization in Handler for Custom URL Scheme
|
CVE-2026-12065
|
2026-06-13 01:16 |
2026-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
140
|
7.3 |
HIGH
Network
|
-
|
-
|
A security flaw has been discovered in PbootCMS up to 3.2.12. This vulnerability affects the function retrieve of the file apps/home/controller/MemberController.php of the component Password Handler.…
New
|
CWE-640
Weak Password Recovery Mechanism for Forgotten Password
|
CVE-2026-12066
|
2026-06-13 01:16 |
2026-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|