|
291
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior are vulnerable to Path Traversal through the Report format_file Parameter, causing arbitrary file read. …
New
|
CWE-22
Path Traversal
|
CVE-2026-40084
|
2026-06-27 01:09 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292
|
- |
|
-
|
-
|
Cacti is an open source performance and fault management framework. Versions 1.2.30 and prior have a package import signature validation bypass allows which allows self-signed packages. This issue ha…
New
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2026-40941
|
2026-06-27 01:09 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293
|
6.5 |
MEDIUM
Network
|
-
|
-
|
The User Registration & Membership – Free & Paid Memberships, Subscriptions, Content Restriction, User Profile, Custom User Registration & Login Builder plugin for WordPress is vulnerable to unauthor…
New
|
CWE-862
Missing Authorization
|
CVE-2026-1869
|
2026-06-27 00:49 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Tim Strifler Exclusive Addons Elementor allows Stored XSS.
This issue affects Exclusive Addons E…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-57620
|
2026-06-27 00:49 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
295
|
5.3 |
MEDIUM
Network
|
-
|
-
|
Unauthenticated Content Injection in Auros Core <= 5.3.1 versions.
New
|
CWE-80
Basic XSS
|
CVE-2025-64637
|
2026-06-27 00:49 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
296
|
5.3 |
MEDIUM
Network
|
-
|
-
|
Unauthenticated Insecure Direct Object References (IDOR) in BookPro <= 1.1.0 versions.
New
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2025-66123
|
2026-06-27 00:49 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
297
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Contributor Cross Site Scripting (XSS) in BNE Testimonials <= 2.0.8 versions.
New
|
CWE-79
Cross-site Scripting
|
CVE-2025-68075
|
2026-06-27 00:49 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
298
|
5.3 |
MEDIUM
Network
|
-
|
-
|
Unauthenticated Broken Access Control in SiteGround Email Marketing <= 1.7.5 versions.
New
|
CWE-862
Missing Authorization
|
CVE-2026-24547
|
2026-06-27 00:49 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
299
|
7.6 |
HIGH
Network
|
-
|
-
|
Subscriber Insecure Direct Object References (IDOR) in SupportCandy <= 3.4.6 versions.
New
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-54826
|
2026-06-27 00:49 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
300
|
9.3 |
CRITICAL
Network
|
-
|
-
|
Unauthenticated SQL Injection in Real Estate 7 <= 3.5.9 versions.
New
|
CWE-89
SQL Injection
|
CVE-2026-54827
|
2026-06-27 00:49 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|