|
861
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Contributor Cross Site Scripting (XSS) in Neve PRO <= 3.1.2 versions.
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-57618
|
2026-06-27 03:17 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
862
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Unauthenticated Broken Access Control in GIFT4U <= 1.0.10 versions.
New
|
CWE-862
Missing Authorization
|
CVE-2026-57324
|
2026-06-27 03:17 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
863
|
5.8 |
MEDIUM
Network
|
-
|
-
|
Unauthenticated Broken Access Control in Flash & HTML5 Video <= 2.11.0 versions.
New
|
CWE-862
Missing Authorization
|
CVE-2026-57323
|
2026-06-27 03:17 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
864
|
7.1 |
HIGH
Network
|
-
|
-
|
Unauthenticated Cross Site Scripting (XSS) in Simply Schedule Appointments <= 1.6.12.2 versions.
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-57317
|
2026-06-27 03:17 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
865
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Subscriber Sensitive Data Exposure in GetGenie <= 4.4.2 versions.
New
|
CWE-497
Exposure of Sensitive System Information to an Unauthorized Control Sphere
|
CVE-2026-57316
|
2026-06-27 03:17 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
866
|
8.1 |
HIGH
Network
|
-
|
-
|
extract-zip does not validate symlink targets when extracting zip archives. When processing a malicious zip file containing a symlink with a relative path like '../../../../etc/passwd', extract-zip w…
New
|
CWE-22 CWE-61
Path Traversal UNIX Symbolic Link (Symlink) Following
|
CVE-2026-56876
|
2026-06-27 03:17 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
867
|
7.3 |
HIGH
Local
|
-
|
-
|
CANBoat through 6.22, fixed in commit a5a22b7, contains an off-by-one global buffer overflow in the searchForPgn() function in analyzer/pgn.c that allows remote attackers to crash the application. At…
New
|
CWE-193
Off-by-one Error
|
CVE-2026-56790
|
2026-06-27 03:17 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
868
|
7.1 |
HIGH
Network
|
-
|
-
|
Unauthenticated Cross Site Scripting (XSS) in WoodMart <= 8.5.3 versions.
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-56072
|
2026-06-27 03:17 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
869
|
9.3 |
CRITICAL
Network
|
-
|
-
|
Unauthenticated SQL Injection in Advance Product Search <= 1.4.4 versions.
New
|
CWE-89
SQL Injection
|
CVE-2026-56070
|
2026-06-27 03:17 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
870
|
8.5 |
HIGH
Network
|
-
|
-
|
Subscriber SQL Injection in Tourfic <= 2.22.5 versions.
New
|
CWE-89
SQL Injection
|
CVE-2026-56064
|
2026-06-27 03:17 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|