|
811
|
3.5 |
LOW
Network
|
-
|
-
|
action/cookie.php in ecrire in SPIP before 4.4.15 is prone to an open redirect vulnerability.
New
|
CWE-601
Open Redirect
|
CVE-2026-48832
|
2026-05-27 05:19 |
2026-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
812
|
- |
|
-
|
-
|
Easyelife App lock (aka Fingerprint,Applock or locker.app.safe.applocker) 1.9.2 for Android allows a local attacker with physical access to bypass the PIN lock. The lock is implemented as an overlay …
New
|
-
|
CVE-2025-68710
|
2026-05-27 05:19 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
813
|
4.3 |
MEDIUM
Network
|
-
|
-
|
Missing Authorization vulnerability in bPlugins Tiktok Feed allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects Tiktok Feed: from n/a through 1.0.24.
New
|
CWE-862
Missing Authorization
|
CVE-2026-24520
|
2026-05-27 05:19 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
814
|
5.3 |
MEDIUM
Network
|
-
|
-
|
Missing Authorization vulnerability in Magepeople inc. Taxi Booking Manager for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects Taxi Booking M…
New
|
CWE-862
Missing Authorization
|
CVE-2026-25426
|
2026-05-27 05:19 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
815
|
4.3 |
MEDIUM
Network
|
-
|
-
|
Missing Authorization vulnerability in Magepeople inc. WpBookingly allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects WpBookingly: from n/a through 1.2.9.
New
|
CWE-862
Missing Authorization
|
CVE-2026-25444
|
2026-05-27 05:19 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
816
|
6.3 |
MEDIUM
Network
|
-
|
-
|
Missing Authorization vulnerability in Magepeople inc. WpTravelly allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects WpTravelly: from n/a through 2.1.5.
New
|
CWE-862
Missing Authorization
|
CVE-2026-27331
|
2026-05-27 05:19 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
817
|
7.3 |
HIGH
Network
|
-
|
-
|
A flaw has been found in itsourcecode Student Transcript Processing System 1.0. This vulnerability affects unknown code of the file /admin/modules/student/trans.php. Executing a manipulation of the a…
New
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-9574
|
2026-05-27 05:19 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
818
|
7.3 |
HIGH
Network
|
-
|
-
|
A vulnerability has been found in itsourcecode Student Transcript Processing System 1.0. This issue affects some unknown processing of the file /admin/modules/class/index.php?view=view. The manipulat…
New
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-9575
|
2026-05-27 05:19 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
819
|
9.8 |
CRITICAL
Network
|
litespeedtech
|
litespeed_cpanel_plugin litespeed_whm_plugin
|
LiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalation (possibly to root), as exploited in the wild in May 2026. Detection is best done via a command line of grep -rE "cpanel_jsona…
Update
|
CWE-266
Incorrect Privilege Assignment
|
CVE-2026-48172
|
2026-05-27 05:19 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
820
|
7.5 |
HIGH
Network
|
-
|
-
|
D-Link DIR601 2.02NA contains a credential disclosure vulnerability that allows unauthenticated attackers to retrieve sensitive configuration data by manipulating the table_name parameter in POST req…
New
|
CWE-497
Exposure of Sensitive System Information to an Unauthorized Control Sphere
|
CVE-2018-25358
|
2026-05-27 05:16 |
2026-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|