|
761
|
7.5 |
HIGH
Network
|
-
|
-
|
Unauthenticated Sensitive Data Exposure in Vitepos <= 3.4.2 versions.
New
|
CWE-201
Insertion of Sensitive Information Into Sent Data
|
CVE-2026-54841
|
2026-06-26 01:16 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
762
|
8.5 |
HIGH
Network
|
-
|
-
|
Subscriber SQL Injection in WC Vendors Marketplace <= 2.6.8 versions.
New
|
CWE-89
SQL Injection
|
CVE-2026-54838
|
2026-06-26 01:16 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
763
|
9.9 |
CRITICAL
Network
|
-
|
-
|
Contributor Remote Code Execution (RCE) in Widget Options <= 4.2.3 versions.
New
|
CWE-94
Code Injection
|
CVE-2026-54823
|
2026-06-26 01:16 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
764
|
8.5 |
HIGH
Network
|
-
|
-
|
Subscriber SQL Injection in SALESmanago & Leadoo <= 3.11.2 versions.
New
|
CWE-89
SQL Injection
|
CVE-2026-54822
|
2026-06-26 01:16 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
765
|
9.9 |
CRITICAL
Network
|
-
|
-
|
SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, CSS snippet body containing </style> breaks out of its surrounding <style> tag when renderSnippet() interpolates it via …
New
|
CWE-79 CWE-1188
Cross-site Scripting Insecure Default Initialization of Resource
|
CVE-2026-54067
|
2026-06-26 01:16 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
766
|
4.0 |
MEDIUM
Network
|
-
|
-
|
Ghost is a Node.js content management system. From 6.0.9 until 6.21.1, Ghost’s private-IP check for outbound HTTP requests could be bypassed via DNS rebinding, allowing an attacker to coerce the Ghos…
New
|
CWE-367 CWE-918
Time-of-check Time-of-use (TOCTOU) Race Condition Server-Side Request Forgery (SSRF)
|
CVE-2026-53945
|
2026-06-26 01:16 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
767
|
- |
|
-
|
-
|
Gogs is an open source self-hosted Git service. Prior to 0.14.3, Gogs has an unauthenticated information disclosure vulnerability. The GET /api/v1/orgs/:orgname/teams endpoint at internal/route/api/v…
New
|
CWE-200
Information Exposure
|
CVE-2026-52815
|
2026-06-26 01:16 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
768
|
- |
|
-
|
-
|
Gogs is an open source self-hosted Git service. Prior to 0.14.3, Git smart HTTP authorizes POST …/git-receive-pack using the client-supplied service query string (so ?service=git-upload-pack is evalu…
New
|
CWE-284
Improper Access Control
|
CVE-2026-52810
|
2026-06-26 01:16 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
769
|
7.1 |
HIGH
Network
|
-
|
-
|
Gogs is an open source self-hosted Git service. Prior to 0.14.3, three API endpoints — PATCH /api/v1/repos/:owner/:repo/issue-tracker, PATCH /api/v1/repos/:owner/:repo/wiki, and POST /api/v1/repos/:o…
New
|
CWE-269 CWE-863
Improper Privilege Management Incorrect Authorization
|
CVE-2026-52808
|
2026-06-26 01:16 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
770
|
- |
|
-
|
-
|
Gogs is an open source self-hosted Git service. Prior to 0.14.3, in new_form.tmpl, milestone names are rendered with Go's default auto-escaping ({{.Name}}), which converts < to < etc. This prevent…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-52807
|
2026-06-26 01:16 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|