|
891
|
7.5 |
HIGH
Network
|
-
|
-
|
Unauthenticated Broken Access Control in Five Star Restaurant Reservations <= 2.7.19 versions.
New
|
CWE-862
Missing Authorization
|
CVE-2026-54830
|
2026-06-25 23:29 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
892
|
7.5 |
HIGH
Network
|
-
|
-
|
Unauthenticated Broken Access Control in CheckView Automated Testing <= 2.1.0 versions.
New
|
CWE-862
Missing Authorization
|
CVE-2026-54844
|
2026-06-25 23:29 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
893
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Unauthenticated Insecure Direct Object References (IDOR) in License Manager for WooCommerce <= 3.0.15 versions.
New
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-56013
|
2026-06-25 23:29 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
894
|
7.1 |
HIGH
Network
|
-
|
-
|
Unauthenticated Cross Site Scripting (XSS) in TablePress <= 3.3.1 versions.
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-56051
|
2026-06-25 23:29 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
895
|
6.5 |
MEDIUM
Network
|
openwebui
|
open_webui
|
Open WebUI is a self-hosted artificial intelligence platform designed to operate entirely offline. Prior to 0.9.6, Open WebUI added collection-level ACL checks, but the patch can still be bypassed wh…
New
|
CWE-862 CWE-943
Missing Authorization Improper Neutralization of Special Elements in Data Query Logic
|
CVE-2026-54019
|
2026-06-25 23:27 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
896
|
8.1 |
HIGH
Network
|
-
|
-
|
picklescan before 0.0.29 fails to detect malicious pickle files that exploit idlelib.debugobj.ObjectTreeItem.SetText function in reduce methods. Attackers can craft pickle files with embedded code th…
New
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2025-71354
|
2026-06-25 23:25 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
897
|
8.1 |
HIGH
Network
|
-
|
-
|
picklescan before 0.0.29 fails to detect malicious idlelib.calltip.Calltip.fetch_tip calls in pickle files, allowing remote code execution. Attackers can embed undetected payloads in pickle files tha…
New
|
CWE-95
Eval Injection
|
CVE-2025-71361
|
2026-06-25 23:25 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
898
|
8.8 |
HIGH
Network
|
-
|
-
|
Unraid Web Server ToggleState Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Unraid. Authenti…
New
|
CWE-78
OS Command
|
CVE-2026-9773
|
2026-06-25 23:23 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
899
|
5.5 |
MEDIUM
Network
|
-
|
-
|
ATEN Unizon updateLicense Directory Traversal Arbitrary File Deletion Vulnerability. This vulnerability allows remote attackers to delete arbitrary files on affected installations of ATEN Unizon. Aut…
New
|
CWE-22
Path Traversal
|
CVE-2026-9774
|
2026-06-25 23:23 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
900
|
5.5 |
MEDIUM
Network
|
-
|
-
|
ATEN Unizon uploadSSL Directory Traversal Arbitrary File Deletion Vulnerability. This vulnerability allows remote attackers to delete arbitrary files on affected installations of ATEN Unizon. Authent…
New
|
CWE-22
Path Traversal
|
CVE-2026-9775
|
2026-06-25 23:23 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|