|
121
|
- |
|
-
|
-
|
Incorrect access control in the /{form}/webhooks/{webhook} endpoint of Deck9 Input v2.0.1 allows authenticated attackers to arbitrarily modify or delete another tenant's webhook via a crafted request.
New
|
-
|
CVE-2026-50875
|
2026-06-17 00:50 |
2026-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
122
|
- |
|
-
|
-
|
A cross-site scripting (XSS) vulnerability in Deck9 Input v2.0.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.
New
|
-
|
CVE-2026-50876
|
2026-06-17 00:50 |
2026-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
123
|
7.5 |
HIGH
Network
|
-
|
-
|
An issue in Zhoros SuperBin v1.0.0 allows attackers to execute a directory traversal via supplying files with names containing traversal characters.
New
|
CWE-22
Path Traversal
|
CVE-2026-50877
|
2026-06-17 00:50 |
2026-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
124
|
9.8 |
CRITICAL
Network
|
-
|
-
|
An issue in the sendmail transport integration component of YouTransfer v1.0.6 allows attackers to execute arbitrary code via supplying a crafted request.
New
|
CWE-94
Code Injection
|
CVE-2026-50880
|
2026-06-17 00:50 |
2026-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
125
|
- |
|
-
|
-
|
Incorrect access control in the impworks Bonsai v6.0 allows authenticated attackers with Editor privileges to escalate privileges to Administrator and execute unauthorized account, password, and conf…
New
|
-
|
CVE-2026-50881
|
2026-06-17 00:50 |
2026-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
126
|
7.5 |
HIGH
Network
|
-
|
-
|
An issue in the /api/v0/pastes endpoint of anna-is-cute paste v0.1.1 allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
New
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2026-50882
|
2026-06-17 00:50 |
2026-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
127
|
9.6 |
CRITICAL
Network
|
-
|
-
|
An HTML injection vulnerability in the /src/highlight.rs component of matze wastebin v3.4.1 allows attackers to execute arbitrary scripts via a crafted payload.
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-50883
|
2026-06-17 00:50 |
2026-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
128
|
7.5 |
HIGH
Network
|
-
|
-
|
Incorrect access control in the share-based read endpoints of Sismics Docs (Teedy) v1.11 allow unauthorized attackers to access sensitive endpoints via a crafted request.
New
|
CWE-284
Improper Access Control
|
CVE-2026-50885
|
2026-06-17 00:50 |
2026-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
129
|
9.1 |
CRITICAL
Network
|
-
|
-
|
Incorrect access control in the webhook management component of Project Firefly III v6.5.9 allows attackers to scan internal resources via a crafted POST request.
New
|
CWE-284
Improper Access Control
|
CVE-2026-50886
|
2026-06-17 00:50 |
2026-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
130
|
9.1 |
CRITICAL
Network
|
-
|
-
|
A Server-Side Request Forgery (SSRF) in the automatic short URL title resolution component of shlink v5.0.1 allows attackers to scan internal resources via supplying a crafted longUrl.
New
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-50887
|
2026-06-17 00:50 |
2026-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|