|
661
|
7.5 |
HIGH
Adjacent
|
-
|
-
|
Insertion of sensitive information into log file vulnerability in syslink software AG Avantra on Linux, Windows allows Resource Leak Exposure.
This issue affects Avantra: before 25.3.0.
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2026-8671
|
2026-05-23 01:32 |
2026-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
662
|
5.1 |
MEDIUM
Local
|
-
|
-
|
Use of default password vulnerability in syslink software AG Avantra on Linux, Windows allows Try Common or Default Usernames and Passwords.
This issue affects Avantra: before 25.3.0.
|
CWE-1393
Use of Default Password
|
CVE-2026-8672
|
2026-05-23 01:32 |
2026-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
663
|
5.9 |
MEDIUM
Network
|
-
|
-
|
Unprotected transport of credentials vulnerability in syslink software AG Avantra on Linux, Windows allows Sniffing Attacks.
This issue affects Avantra: before 25.3.0.
|
CWE-523
Unprotected Transport of Credentials
|
CVE-2026-8673
|
2026-05-23 01:32 |
2026-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
664
|
7.5 |
HIGH
Network
|
-
|
-
|
Directory traversal in Follett Software's Destiny Library Manager 22_0_2_rc1 and fixed in v.22.5 AU1 allows remote attackers to read arbitrary system and application files via the image parameter
|
CWE-22
Path Traversal
|
CVE-2025-45145
|
2026-05-23 01:32 |
2026-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
665
|
- |
|
-
|
-
|
Simple Hierarchical Select (SHS) for Drupal 7 contains cross-site scripting risk due to improper output escaping of term-derived text. Confirmed affected paths include field formatter output (shs_fie…
|
CWE-79
Cross-site Scripting
|
CVE-2026-4929
|
2026-05-23 01:17 |
2026-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
666
|
- |
|
-
|
-
|
In the Drupal 7 Term Reference Tree module, two stored XSS vectors exist in the widget/formatter rendering pipeline.
Vector A (token display templates): When the Token module is enabled and token di…
|
CWE-79
Cross-site Scripting
|
CVE-2026-4093
|
2026-05-23 01:17 |
2026-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
667
|
- |
|
-
|
-
|
Concrete CMS 9.5.0 and below fails to sanitize path traversal sequences in the ptComposerFormLayoutSetControlCustomTemplate field when saving page type composer form layouts. An authenticated rogue a…
|
CWE-23 CWE-98 CWE-434
Relative Path Traversal Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') Unrestricted Upload of File with Dangerous Type
|
CVE-2026-8134
|
2026-05-23 01:17 |
2026-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
668
|
- |
|
-
|
-
|
Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/page/bulk/design. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 sco…
|
CWE-352 CWE-1275
Origin Validation Error Sensitive Cookie with Improper SameSite Attribute
|
CVE-2026-8413
|
2026-05-23 01:17 |
2026-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
669
|
6.7 |
MEDIUM
Local
|
-
|
-
|
Dell VxRail versions before 7.0.200 contain a Plain-text Password Storage Vulnerability in VxRail Manager. A sys-admin user may exploit this vulnerability, leading to the disclosure of certain user c…
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2021-21508
|
2026-05-23 01:17 |
2026-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
670
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Dell Unisphere for PowerMax vApp version prior to 10.0.0.2, contains an authorization bypass vulnerability in the Unisphere for VMAX application running in vApp
|
CWE-285
Improper Authorization
|
CVE-2022-34363
|
2026-05-23 01:17 |
2026-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|