|
1741
|
- |
|
-
|
-
|
Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.1, 21.2.17, and 20.3.25, an information disclosure vu…
|
CWE-200 CWE-359
Information Exposure Exposure of Private Personal Information to an Unauthorized Actor
|
CVE-2026-54264
|
2026-06-24 00:16 |
2026-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1742
|
- |
|
-
|
-
|
Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.0-rc.2, 21.2.15, 20.3.22, and 19.2.23, an issue in th…
|
CWE-200 CWE-524
Information Exposure Use of Cache Containing Sensitive Information
|
CVE-2026-50184
|
2026-06-24 00:16 |
2026-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1743
|
- |
|
-
|
-
|
Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.0-rc.2, 21.2.15, 20.3.22, and 19.2.23, a Denial of Se…
|
CWE-400 CWE-834
Uncontrolled Resource Consumption Excessive Iteration
|
CVE-2026-50171
|
2026-06-24 00:16 |
2026-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1744
|
6.1 |
MEDIUM
Network
|
astro
|
astro
|
Astro is a web framework. Prior to 6.3.3, when a component uses a client:* directive, Astro inserts named slot content into a data-astro-template attribute without HTML escaping the slot name allowin…
|
CWE-80
Basic XSS
|
CVE-2026-50146
|
2026-06-24 00:16 |
2026-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1745
|
3.7 |
LOW
Network
|
-
|
-
|
A flaw in Node.js HTTP Agent can cause a client to accept as valid a response that is send before the client has sent the request.
This vulnerability affects all supported release lines: **Node.js…
|
CWE-367
Time-of-check Time-of-use (TOCTOU) Race Condition
|
CVE-2026-48931
|
2026-06-24 00:16 |
2026-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1746
|
7.4 |
HIGH
Network
|
-
|
-
|
Filament is a collection of full-stack components for accelerated Laravel development. From 4.0.0 until 4.11.5 and 5.6.5, a flaw in the handling of recovery codes for app-based multi-factor authentic…
|
CWE-362 CWE-841
Race Condition Improper Enforcement of Behavioral Workflow
|
CVE-2026-48505
|
2026-06-24 00:16 |
2026-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1747
|
6.5 |
MEDIUM
Network
|
apache
|
apisix
|
Authentication Bypass by Capture-replay vulnerability in Apache APISIX.
Attacker can benefit from certain configurations in hmac-auth to re-use a token forever, bypassing expiry.
This issue affects …
|
CWE-294
Authentication Bypass by Capture-replay
|
CVE-2026-47341
|
2026-06-24 00:16 |
2026-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1748
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Filament is a collection of full-stack components for accelerated Laravel development. From 3.0.0 until 3.3.52, 4.11.5, and 5.6.5, any schema can contain a file upload form field, so Filament applies…
|
CWE-862
Missing Authorization
|
CVE-2026-48500
|
2026-06-24 00:16 |
2026-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1749
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Filament is a collection of full-stack components for accelerated Laravel development. From filament/actions 4.0.0 until 4.11.4 and 5.6.4 and from filament/tables 3.0.0 until 3.3.51, the recordSelect…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-48067
|
2026-06-24 00:16 |
2026-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1750
|
- |
|
-
|
-
|
Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to 0.6.5 and 0.5.15, several Net::IMAP commands accept a raw string argument which is only validated t…
|
CWE-162 CWE-182 CWE-186
Collapse of Data into Unsafe Value Overly Restrictive Regular Expression
|
CVE-2026-47241
|
2026-06-24 00:16 |
2026-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|