|
851
|
3.5 |
LOW
Network
|
-
|
-
|
A vulnerability was found in vBulletin 6.x. This impacts an unknown function of the component Login. Performing a manipulation results in cross site scripting. It is possible to initiate the attack r…
New
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-9357
|
2026-05-27 04:54 |
2026-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
852
|
4.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was determined in postcss up to 7.1.1. Affected is the function toString of the file src/selectors/container.js of the component AST Serialization. Executing a manipulation can lead t…
New
|
CWE-404 CWE-674
Improper Resource Shutdown or Release Uncontrolled Recursion
|
CVE-2026-9358
|
2026-05-27 04:54 |
2026-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
853
|
5.6 |
MEDIUM
Network
|
-
|
-
|
A security vulnerability has been detected in ItzCrazyKns Vane up to 1.12.1. Affected by this issue is some unknown functionality of the file route.ts of the component API. The manipulation leads to …
New
|
CWE-287 CWE-306
Improper Authentication Missing Authentication for Critical Function
|
CVE-2026-9371
|
2026-05-27 04:54 |
2026-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
854
|
7.3 |
HIGH
Network
|
-
|
-
|
A flaw has been found in ItzCrazyKns Vane up to 1.12.1. This vulnerability affects unknown code of the file src/app/api/providers/route.ts of the component Model Provider API. This manipulation of th…
New
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-9372
|
2026-05-27 04:54 |
2026-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
855
|
3.7 |
LOW
Network
|
-
|
-
|
A weakness has been identified in ulisesbocchio jasypt-spring-boot up to 3.0.5/4.0.4. Affected by this vulnerability is the function getSecretKeySaltGenerator of the file jasypt-spring-boot/src/main/…
New
|
CWE-759 CWE-760
Use of a One-Way Hash without a Salt Use of a One-Way Hash with a Predictable Salt
|
CVE-2026-9370
|
2026-05-27 04:54 |
2026-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
856
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was found in yangzongzhuan RuoYi-Vue up to 3.9.2. Impacted is the function FileUploadUtils.upload of the file /common/upload of the component Common Upload Endpoint. Performing a mani…
New
|
CWE-284 CWE-434
Improper Access Control Unrestricted Upload of File with Dangerous Type
|
CVE-2026-9374
|
2026-05-27 04:54 |
2026-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
857
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was determined in JPress up to 1.0.3. The affected element is an unknown function of the file /ucenter/article/doWriteSave of the component UCenter Article Submission Endpoint. Execut…
New
|
CWE-266 CWE-285
Incorrect Privilege Assignment Improper Authorization
|
CVE-2026-9376
|
2026-05-27 04:54 |
2026-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
858
|
2.4 |
LOW
Network
|
-
|
-
|
A vulnerability was identified in SourceCodester SUP Online Shopping 1.0. The impacted element is an unknown function of the file /admin/productedit.php. The manipulation of the argument productName …
New
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-9377
|
2026-05-27 04:54 |
2026-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
859
|
4.3 |
MEDIUM
Network
|
-
|
-
|
A flaw has been found in Sushmi-pal Invoice-System up to a0a3faa16dee2621b231ae227333f5761607283b. This affects an unknown part of the file /user of the component User Management Handler. This manipu…
New
|
CWE-266 CWE-285
Incorrect Privilege Assignment Improper Authorization
|
CVE-2026-9409
|
2026-05-27 04:54 |
2026-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
860
|
4.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability has been found in Sushmi-pal Invoice-System up to a0a3faa16dee2621b231ae227333f5761607283b. This vulnerability affects unknown code of the file /profile of the component Profile Workf…
New
|
CWE-266 CWE-285
Incorrect Privilege Assignment Improper Authorization
|
CVE-2026-9410
|
2026-05-27 04:54 |
2026-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|