|
871
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Affiliate Broken Access Control in Affiliates Manager <= 2.9.49 versions.
New
|
CWE-862
Missing Authorization
|
CVE-2026-57654
|
2026-06-27 00:49 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
872
|
8.2 |
HIGH
Network
|
-
|
-
|
Unauthenticated Cross Site Request Forgery (CSRF) in Child Theme Wizard <= 1.4 versions.
New
|
CWE-352
Origin Validation Error
|
CVE-2026-57655
|
2026-06-27 00:49 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
873
|
5.3 |
MEDIUM
Network
|
-
|
-
|
Unauthenticated Broken Access Control in Booking and Rental Manager <= 2.7.1 versions.
New
|
CWE-862
Missing Authorization
|
CVE-2026-57660
|
2026-06-27 00:49 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
874
|
5.4 |
MEDIUM
Network
|
-
|
-
|
Subscriber Broken Access Control in WPComplete <= 2.9.5.5 versions.
New
|
CWE-862
Missing Authorization
|
CVE-2026-57661
|
2026-06-27 00:49 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
875
|
8.5 |
HIGH
Network
|
-
|
-
|
Sales Representative SQL Injection in Groundhogg <= 4.5 versions.
New
|
CWE-89
SQL Injection
|
CVE-2026-57667
|
2026-06-27 00:49 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
876
|
8.0 |
HIGH
Network
|
-
|
-
|
Dell Dell Container Storage Modules, version(s) csi-powerstore v2.16.0, csi-unity v2.16.0, csi-powerflex v2.16.0, csi-powermax v2.16.0, contain(s) an Improper Neutralization of Special Elements used …
New
|
CWE-78
OS Command
|
CVE-2026-40711
|
2026-06-27 00:48 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
877
|
6.8 |
MEDIUM
Physics
|
google
|
chrome
|
Use after free in Payments in Google Chrome on Android prior to 149.0.7827.201 allowed a local attacker to potentially exploit heap corruption via physical access to the device. (Chromium security se…
New
|
CWE-416
Use After Free
|
CVE-2026-13282
|
2026-06-27 00:41 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
878
|
7.3 |
HIGH
Network
|
-
|
-
|
It is possible to bypass the Kerberos pre-authentication check in Apache Kerby by sending a PA-DATA with an unrecognized or unsupported type. Users are recommended to upgrade to version 2.1.2, which …
New
|
CWE-304
Missing Critical Step in Authentication
|
CVE-2026-57915
|
2026-06-27 00:16 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
879
|
8.6 |
HIGH
Network
|
-
|
-
|
Crawl4AI is an open-source LLM friendly web crawler & scraper. Prior to 0.8.9, the Docker API server applied its SSRF destination check to the crawl target URL only, not to the proxy address. An unau…
New
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-53755
|
2026-06-27 00:16 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
880
|
7.5 |
HIGH
Network
|
-
|
-
|
An issue in the pthread_rwlockattr_setpshared() function of relibc commit 61f42d allows attackers to cause a Denial of Service (DoS) via a crafted input.
New
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2026-38637
|
2026-06-27 00:16 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|