|
771
|
6.1 |
MEDIUM
Network
|
angularjs
|
angularjs
|
Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.0-rc.2, 21.2.15, 20.3.22, and 19.2.23, an issue in th…
|
CWE-79
Cross-site Scripting
|
CVE-2026-52725
|
2026-06-27 04:34 |
2026-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
772
|
5.8 |
MEDIUM
Network
|
guzzlephp
|
guzzle
|
Guzzle is an extensible PHP HTTP client. Prior to 7.12.1, CookieJar incorrectly accepts cookies with a dot-only Domain attribute and whitespace-padded variants. SetCookie::matchesDomain() removes lea…
|
CWE-346 CWE-1286
Origin Validation Error Improper Validation of Syntactic Correctness of Input
|
CVE-2026-55767
|
2026-06-27 04:34 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
773
|
5.9 |
MEDIUM
Network
|
guzzlephp
|
guzzle
|
Guzzle is an extensible PHP HTTP client. Prior to 7.12.1, in certain configurations, traffic expected to be protected by TLS on the hop to the proxy is transmitted in cleartext. Proxy authentication …
|
CWE-311 CWE-319 CWE-636
Missing Encryption of Sensitive Data Cleartext Transmission of Sensitive Information Not Failing Securely ('Failing Open')
|
CVE-2026-55568
|
2026-06-27 04:34 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
774
|
6.1 |
MEDIUM
Network
|
angularjs
|
angularjs
|
Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.0-rc.2, 21.2.16, 20.3.24, and 19.2.25, a Cross-Site S…
|
CWE-79
Cross-site Scripting
|
CVE-2026-50556
|
2026-06-27 04:33 |
2026-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
775
|
6.1 |
MEDIUM
Network
|
angularjs
|
angularjs
|
Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.0-next.12, 21.2.13, 20.3.21, and 19.2.22, a Server-Si…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-46417
|
2026-06-27 04:33 |
2026-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
776
|
6.1 |
MEDIUM
Network
|
angularjs
|
angularjs
|
Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.0-rc.2, 21.2.15, 20.3.22, and 19.2.23, a Denial of Se…
|
CWE-400 CWE-834
Uncontrolled Resource Consumption Excessive Iteration
|
CVE-2026-50171
|
2026-06-27 04:32 |
2026-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
777
|
6.1 |
MEDIUM
Network
|
angularjs
|
angularjs
|
Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.0-rc.2, 21.2.15, 20.3.22, and 19.2.23, an issue in th…
|
CWE-200 CWE-524
Information Exposure Use of Cache Containing Sensitive Information
|
CVE-2026-50184
|
2026-06-27 04:31 |
2026-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
778
|
6.1 |
MEDIUM
Network
|
angularjs
|
angularjs
|
Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.1, 21.2.17, and 20.3.25, an information disclosure vu…
|
CWE-200 CWE-359
Information Exposure Exposure of Private Personal Information to an Unauthorized Actor
|
CVE-2026-54264
|
2026-06-27 04:30 |
2026-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
779
|
7.1 |
HIGH
Local
|
home-assistant
|
home_assistant_companion
|
Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2026.5.3, the LocationSensorManager BroadcastReceiver is exported with no permission. Any in…
|
CWE-926
Improper Export of Android Application Components
|
CVE-2026-54318
|
2026-06-27 04:28 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
780
|
7.5 |
HIGH
Network
|
aiohttp
|
aiohttp
|
AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to 3.14.1, during cleanup it is possible for a compressed request body to be decompressed into memory in one chun…
|
CWE-409
Improper Handling of Highly Compressed Data (Data Amplification)
|
CVE-2026-54278
|
2026-06-27 04:27 |
2026-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|