|
251
|
7.5 |
HIGH
Network
|
-
|
-
|
It is possible for an unauthenticated adjacent attacker to download log files of the controller, which may disclose some restricted information.
New
|
CWE-200
Information Exposure
|
CVE-2026-41032
|
2026-06-3 20:16 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252
|
8.8 |
HIGH
Network
|
-
|
-
|
Incorrect Privilege Assignment vulnerability in Mojoomla School Management allows Privilege Escalation.
This issue affects School Management: from n/a through 93.2.0.
New
|
CWE-266
Incorrect Privilege Assignment
|
CVE-2025-15656
|
2026-06-3 20:16 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253
|
7.6 |
HIGH
Network
|
-
|
-
|
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mojoomla School Management allows SQL Injection.
This issue affects School Management: from n/a …
New
|
CWE-89
SQL Injection
|
CVE-2025-15655
|
2026-06-3 20:16 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
254
|
7.4 |
HIGH
Adjacent
|
-
|
-
|
Incorrect Authorization vulnerability in ABB T-MAC Plus.
This issue affects T-MAC Plus: 4.0-24.
New
|
CWE-863
Incorrect Authorization
|
CVE-2025-14774
|
2026-06-3 20:16 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255
|
8.0 |
HIGH
Network
|
-
|
-
|
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in ABB T-MAC Plus.
This issue affects T-MAC Plus: 4.0-24.
New
|
CWE-79
Cross-site Scripting
|
CVE-2025-14773
|
2026-06-3 20:16 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256
|
8.8 |
HIGH
Network
|
-
|
-
|
Authorization bypass through User-Controlled key vulnerability in ABB T-MAC Plus.
This issue affects T-MAC Plus: 4.0-24.
New
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2025-14772
|
2026-06-3 20:16 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257
|
9.9 |
CRITICAL
Network
|
-
|
-
|
Files or directories accessible to external parties vulnerability in ABB T-MAC Plus.
This issue affects T-MAC Plus: 4.0-24.
New
|
CWE-552
Files or Directories Accessible to External Parties
|
CVE-2025-14771
|
2026-06-3 20:16 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
258
|
7.1 |
HIGH
Network
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Fox-themes Prague allows Reflected XSS.
This issue affects Prague: from n/a through 2.2.8.
New
|
CWE-79
Cross-site Scripting
|
CVE-2025-15654
|
2026-06-3 18:16 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
259
|
5.3 |
MEDIUM
Network
|
-
|
-
|
Impact: The morgan logging middleware's :remote-user token extracts the Basic auth username from the Authorization request header and writes it to the log stream without neutralizing control characte…
New
|
CWE-117
Improper Output Neutralization for Logs
|
CVE-2026-5078
|
2026-06-3 17:16 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
260
|
- |
|
-
|
-
|
In Vinyl Cache before 9.0.1 and Varnish Cache before 9.0.3, a deficiency in HTTP/2 request parsing can be exploited to launch a backend request desync
attack (request smuggling), which in turn can be…
New
|
CWE-444
HTTP Request Smuggling
|
CVE-2026-50052
|
2026-06-3 15:16 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|