|
1871
|
- |
|
-
|
-
|
A Missing Authorization vulnerability in a GraphQL private API operation of the Google App Engine section of the Cloud Console allows an unauthenticated remote attacker to leak sensitive App Engine r…
|
CWE-862
Missing Authorization
|
CVE-2026-8934
|
2026-06-23 05:18 |
2026-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1872
|
9.0 |
CRITICAL
Network
|
-
|
-
|
An issue was discovered in Canonical ADSys upstream versions through v0.16.2. During Active Directory Certificate Services (AD CS) certificate auto-enrollment via the vendored Samba client script (in…
|
CWE-348
Use of Less Trusted Source
|
CVE-2026-12249
|
2026-06-23 05:18 |
2026-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1873
|
9.8 |
CRITICAL
Network
|
-
|
-
|
FileRise before 3.16.0 is vulnerable to path traversal in the shared-folder upload endpoint (/api/folder/uploadToSharedFolder.php), leading to arbitrary file write and administrator account takeover.…
|
CWE-22 CWE-434
Path Traversal Unrestricted Upload of File with Dangerous Type
|
CVE-2026-54414
|
2026-06-23 05:17 |
2026-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1874
|
7.5 |
HIGH
Network
|
-
|
-
|
Capgo (Cap-go/capgo) before 12.128.2 contains an improper access control vulnerability in the SECURITY DEFINER PostgREST RPC function public.record_build_time, which is granted to the anon role and c…
|
CWE-284
Improper Access Control
|
CVE-2026-56082
|
2026-06-23 05:17 |
2026-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1875
|
5.3 |
MEDIUM
Network
|
-
|
-
|
Capgo before 12.128.2 contains an authorization bypass vulnerability in the public.upsert_version_meta SECURITY DEFINER function exposed via PostgREST RPC, allowing unauthenticated attackers to inser…
|
CWE-862
Missing Authorization
|
CVE-2026-56213
|
2026-06-23 05:17 |
2026-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1876
|
- |
|
-
|
-
|
picklescan before 0.0.25 fails to detect malicious pickle files that use timeit.timeit() in the __reduce__ method, allowing remote code execution. Attackers can craft pickle files that import dangero…
|
CWE-184
Incomplete Blacklist
|
CVE-2025-71351
|
2026-06-23 05:17 |
2026-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1877
|
5.4 |
MEDIUM
Network
|
-
|
-
|
EasyFlow .NET developed by Digiwin has a Stored Cross-Site Scripting vulnerability, allowing authenticated remote attackers to inject persistent JavaScript code executed in users' browsers upon page …
|
CWE-79
Cross-site Scripting
|
CVE-2026-12580
|
2026-06-23 05:17 |
2026-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1878
|
7.5 |
HIGH
Network
|
-
|
-
|
EasyFlow .NET developed by Digiwin has a Session Fixation vulnerability. If unauthenticated remote attackers replace a specific session ID for a user, they can gain the user's privilege once the user…
|
CWE-384
Session Fixation
|
CVE-2026-12581
|
2026-06-23 05:17 |
2026-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1879
|
9.8 |
CRITICAL
Network
|
-
|
-
|
The BetterDocs Pro plugin for WordPress is vulnerable to Local File Inclusion in versions up to, and including, 3.8.0 via the `doc_style` parameter. This makes it possible for unauthenticated attacke…
|
CWE-98
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
|
CVE-2026-7515
|
2026-06-23 05:16 |
2026-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1880
|
5.3 |
MEDIUM
Network
|
-
|
-
|
The 2Download Connector for 2DL Hosted Checkout plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 0.1.5. This is due to the plugin not properly verifying…
|
CWE-862
Missing Authorization
|
CVE-2026-6798
|
2026-06-23 05:16 |
2026-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|