|
1181
|
7.8 |
HIGH
Local
|
vim
|
vim
|
Vim is an open source, command line text editor. Prior to 9.2.0698, the single-byte branch of spell_soundfold_sofo() in src/spell.c translates a word through a spell file's SOFO (sound-folding) byte …
|
CWE-787
Out-of-bounds Write
|
CVE-2026-57455
|
2026-06-26 13:23 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1182
|
6.1 |
MEDIUM
Local
|
vim
|
vim
|
Vim is an open source, command line text editor. From 9.2.0320 until 9.2.0679, a crafted undo or swap file can store a virtual-text property whose offset and length point outside the line's property …
|
CWE-125
Out-of-bounds Read
|
CVE-2026-57454
|
2026-06-26 13:22 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1183
|
8.5 |
HIGH
Network
|
-
|
-
|
NewsBlur before version 14.5.0 contains a server-side request forgery vulnerability in the add_url endpoint that allows authenticated users to make arbitrary server requests to internal networks by f…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-56771
|
2026-06-26 13:17 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1184
|
8.2 |
HIGH
Network
|
-
|
-
|
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.16, a scoped, non-admin File Browser user holdin…
|
CWE-22 CWE-59
Path Traversal Link Following
|
CVE-2026-55667
|
2026-06-26 13:17 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1185
|
6.5 |
MEDIUM
Network
|
-
|
-
|
File Browser is a file managing interface for uploading, deleting, previewing, renaming, and editing files within a specified directory. Prior to 2.63.6, unchecked passwords maximums allow for an arb…
|
CWE-400 CWE-1284
Uncontrolled Resource Consumption Improper Validation of Specified Quantity in Input
|
CVE-2026-54092
|
2026-06-26 13:17 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1186
|
- |
|
-
|
-
|
pnpm is a package manager. Prior to 10.33.4 and 11.0.7, a malicious codeload.github.com server can serve whatever tarball it wants and pnpm will install it regardless of the lockfile. The lockfile do…
|
CWE-353
Missing Support for Integrity Check
|
CVE-2026-48995
|
2026-06-26 13:17 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1187
|
5.3 |
MEDIUM
Network
|
-
|
-
|
Glances is an open-source system cross-platform monitoring tool. Prior to 4.5.5, the Glances XML-RPC server (glances -s, implemented in glances/server.py) does not validate the HTTP Host header, leav…
|
CWE-346 CWE-350
Origin Validation Error Reliance on Reverse DNS Resolution for a Security-Critical Action
|
CVE-2026-46611
|
2026-06-26 13:17 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1188
|
5.5 |
MEDIUM
Local
|
vim
|
vim
|
Vim is an open source, command line text editor. Prior to 9.2.0671, when Vim opens a file encrypted with the VimCrypt~04! or VimCrypt~05!
method (xchacha20poly1305, requires the +sodium feature) whos…
|
CWE-125 CWE-191
Out-of-bounds Read Integer Underflow (Wrap or Wraparound)
|
CVE-2026-57452
|
2026-06-26 13:12 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1189
|
6.1 |
MEDIUM
Local
|
vim
|
vim
|
Vim is an open source, command line text editor. Prior to 9.2.0670, get_text_props() in src/textprop.c reads a uint16 property count stored inline after a line's text and returns it as the number of …
|
CWE-125
Out-of-bounds Read
|
CVE-2026-57451
|
2026-06-26 13:11 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1190
|
6.6 |
MEDIUM
Local
|
nokogiri
|
nokogiri
|
Nokogiri is an open source XML and HTML library for the Ruby programming language. Prior to 1.19.4, XInclude substitution performed by Nokogiri::XML::Node#do_xinclude replaced each <xi:include> in pl…
|
CWE-416
Use After Free
|
CVE-2026-57438
|
2026-06-26 13:11 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|