|
271
|
5.3 |
MEDIUM
Network
|
jetbrains
|
youtrack
|
In JetBrains YouTrack before 2026.2.16593 improper access control allowed reading saved queries and tags
New
|
CWE-862
Missing Authorization
|
CVE-2026-57925
|
2026-06-28 04:29 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272
|
7.5 |
HIGH
Network
|
jenkins
|
script_security
|
Jenkins Script Security Plugin 1402.v94c9ce464861 and earlier does not reject Groovy AST transformation annotations carrying an extensions member, allowing attackers able to run sandboxed Groovy scri…
New
|
CWE-93 CWE-693
CRLF Injection Protection Mechanism Failure
|
CVE-2026-57281
|
2026-06-28 04:27 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273
|
6.5 |
MEDIUM
Network
|
gnu
|
sed
|
Arbitrary File Read vulnerability in Rapid7 InsightConnect Sed Plugin on Linux allows authenticated attackers to read arbitrary files via the expression parameter due to insufficient input validation.
New
|
CWE-22 CWE-200
Path Traversal Information Exposure
|
CVE-2026-9153
|
2026-06-28 04:26 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
274
|
6.5 |
MEDIUM
Network
|
gnu
|
sed
|
Arbitrary File Write vulnerability in Rapid7 InsightConnect Sed Plugin on Linux allows authenticated attackers to write attacker-controlled content to arbitrary file paths via the expression paramete…
New
|
CWE-22
Path Traversal
|
CVE-2026-9154
|
2026-06-28 04:25 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
275
|
8.8 |
HIGH
Network
|
gnu
|
sed
|
OS Command Injection vulnerability in Rapid7 InsightConnect Sed Plugin on Linux allows authenticated attackers to execute arbitrary OS commands via the expression parameter due to insufficient input …
New
|
CWE-78
OS Command
|
CVE-2026-9155
|
2026-06-28 04:24 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276
|
7.2 |
HIGH
Network
|
aten
|
unizon
|
ATEN Unizon doCryptoHugeFileToFile Improper Verification of Cryptographic Signature Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affect…
New
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2026-9779
|
2026-06-28 04:02 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277
|
7.2 |
HIGH
Network
|
aten
|
unizon
|
ATEN Unizon ImportDeviceList Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of ATEN Unizon. Au…
New
|
CWE-22
Path Traversal
|
CVE-2026-9778
|
2026-06-28 04:01 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278
|
7.2 |
HIGH
Network
|
aten
|
unizon
|
ATEN Unizon restoreDB Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of ATEN Unizon. Authentic…
New
|
CWE-22
Path Traversal
|
CVE-2026-9777
|
2026-06-28 04:01 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279
|
7.5 |
HIGH
Network
|
aten
|
unizon
|
ATEN Unizon writeFileToHttpServletResponse Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installat…
New
|
CWE-22
Path Traversal
|
CVE-2026-9776
|
2026-06-28 04:00 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280
|
6.5 |
MEDIUM
Network
|
aten
|
unizon
|
ATEN Unizon uploadSSL Directory Traversal Arbitrary File Deletion Vulnerability. This vulnerability allows remote attackers to delete arbitrary files on affected installations of ATEN Unizon. Authent…
New
|
CWE-22
Path Traversal
|
CVE-2026-9775
|
2026-06-28 03:59 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|