|
121
|
5.5 |
MEDIUM
Local
|
deno
|
deno
|
Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.7.12, when Deno was run in BYONM mode (nodeModulesDir: "manual"), the module resolver did not validate that a package's resolved …
New
|
CWE-22
Path Traversal
|
CVE-2026-49406
|
2026-06-27 02:29 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
122
|
6.5 |
MEDIUM
Local
|
deno
|
deno
|
Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.8.0, the Node.js compatibility TCP path checked the permission against the original hostname string before resolution and then di…
New
|
CWE-284 NVD-CWE-noinfo
Improper Access Control
|
CVE-2026-49411
|
2026-06-27 02:27 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
123
|
7.2 |
HIGH
Network
|
-
|
-
|
A privilege escalation vulnerability exists in LXD from 6.0 before 6.9, 5.21.0 before 5.21.5, and 5.0.0 before 5.0.7 regarding the handling of project-restriction policies during snapshot restoration…
New
|
CWE-863
Incorrect Authorization
|
CVE-2026-9640
|
2026-06-27 02:16 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
124
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Nil-pointer dereference in CreateCustomVolumeFromBackup in LXD up to version 6.8 and 5.21 on Linux allows an authenticated user with can_create_storage_volumes permissions to cause a denial of servic…
New
|
CWE-476
NULL Pointer Dereference
|
CVE-2026-9639
|
2026-06-27 02:16 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
125
|
9.8 |
CRITICAL
Network
|
-
|
-
|
An unauthenticated
stack-based buffer overflow vulnerability exists in vlsvr in GeoVision
GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerability is caused by
insufficient length validation wh…
New
|
CWE-121
Stack-based Buffer Overflow
|
CVE-2026-57881
|
2026-06-27 02:16 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
126
|
9.8 |
CRITICAL
Network
|
-
|
-
|
An unauthenticated
stack-based buffer overflow vulnerability exists in ssvr in GeoVision
GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerability is caused by
insufficient bounds checking when …
New
|
CWE-121
Stack-based Buffer Overflow
|
CVE-2026-57879
|
2026-06-27 02:16 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
127
|
8.5 |
HIGH
Network
|
-
|
-
|
Contributor SQL Injection in Contest Gallery <= 30.0.0 versions.
New
|
CWE-89
SQL Injection
|
CVE-2026-57662
|
2026-06-27 02:16 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
128
|
5.9 |
MEDIUM
Network
|
-
|
-
|
Author Cross Site Scripting (XSS) in Hester Core <= 1.1.8 versions.
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-57656
|
2026-06-27 02:16 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
129
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Contributor Cross Site Scripting (XSS) in Magazine Blocks <= 1.8.3 versions.
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-57650
|
2026-06-27 02:16 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
130
|
8.5 |
HIGH
Network
|
-
|
-
|
Contributor SQL Injection in Restaurant Menu by MotoPress <= 2.4.10 versions.
New
|
CWE-89
SQL Injection
|
CVE-2026-57644
|
2026-06-27 02:16 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|