|
261
|
3.3 |
LOW
Local
|
-
|
-
|
7-Zip for Windows through 26.02 fails to preserve the Mark-of-the-Web when extracting a crafted RAR5 archive, because its guard that suppresses an archive-supplied Zone.Identifier stream matches the …
New
|
CWE-693
Protection Mechanism Failure
|
CVE-2026-58052
|
2026-06-30 01:16 |
2026-06-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
262
|
8.5 |
HIGH
Network
|
-
|
-
|
Contributor SQL Injection in Gallery <= 4.7.8 versions.
Update
|
CWE-89
SQL Injection
|
CVE-2026-57642
|
2026-06-30 01:16 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
263
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Contributor Cross Site Scripting (XSS) in StatCounter <= 2.1.1 versions.
Update
|
CWE-79
Cross-site Scripting
|
CVE-2026-57629
|
2026-06-30 01:16 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264
|
7.1 |
HIGH
Network
|
-
|
-
|
Contributor Arbitrary File Deletion in H5P <= 1.17.7 versions.
Update
|
CWE-22
Path Traversal
|
CVE-2026-57321
|
2026-06-30 01:16 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265
|
7.1 |
HIGH
Network
|
-
|
-
|
Unauthenticated Cross Site Scripting (XSS) in SureCart <= 4.3.2 versions.
Update
|
CWE-79
Cross-site Scripting
|
CVE-2026-57314
|
2026-06-30 01:16 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266
|
7.5 |
HIGH
Network
|
-
|
-
|
phpUploader before 2.0.2 contains an unauthenticated information disclosure vulnerability that allows remote attackers to access the full contents of the uploaded-files database table by visiting any…
New
|
CWE-359 CWE-497
Exposure of Private Personal Information to an Unauthorized Actor Exposure of Sensitive System Information to an Unauthorized Control Sphere
|
CVE-2026-56124
|
2026-06-30 01:16 |
2026-06-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267
|
7.5 |
HIGH
Network
|
-
|
-
|
Unauthenticated Broken Access Control in Subscriptions for WooCommerce <= 1.9.5 versions.
Update
|
CWE-862
Missing Authorization
|
CVE-2026-56061
|
2026-06-30 01:16 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Unauthenticated Insecure Direct Object References (IDOR) in Payment Gateway Based Fees and Discounts for WooCommerce <= 3.0.0 versions.
Update
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-56048
|
2026-06-30 01:16 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269
|
7.1 |
HIGH
Network
|
-
|
-
|
Unauthenticated Cross Site Scripting (XSS) in Responsive Lightbox <= 2.7.6 versions.
Update
|
CWE-79
Cross-site Scripting
|
CVE-2026-56041
|
2026-06-30 01:16 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270
|
9.3 |
CRITICAL
Network
|
-
|
-
|
Unauthenticated SQL Injection in Library Management System <= 3.5.7 versions.
Update
|
CWE-89
SQL Injection
|
CVE-2026-56034
|
2026-06-30 01:16 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|