|
3571
|
4.4 |
MEDIUM
Network
|
-
|
-
|
In Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1, an unsanitized subject field in the draft restored value could lead to stored XSS/HTML/CSS injection on shared mailboxes.
|
CWE-79
Cross-site Scripting
|
CVE-2026-48849
|
2026-05-27 04:26 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3572
|
7.5 |
HIGH
Network
|
powerdns
|
authoritative
|
Insufficient Validation of Autoprimary SOA Queries
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2026-42001
|
2026-05-27 04:24 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3573
|
7.5 |
HIGH
Network
|
powerdns
|
authoritative
|
Concurrency and locking defects in GSS-TSIG
|
CWE-364
Signal Handler Race Condition
|
CVE-2026-42002
|
2026-05-27 04:23 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3574
|
6.5 |
MEDIUM
Network
|
powerdns
|
authoritative
|
Insufficient Validation of Member Zone Data May Cause Catalog Zone Transfer to Fail
|
CWE-94
Code Injection
|
CVE-2026-42396
|
2026-05-27 04:19 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3575
|
- |
|
-
|
-
|
XWiki Platform is a generic wiki platform offering runtime services for applications built on top of it. XWiki Platform is a generic wiki platform. In versions starting with 15.10.6 and prior to 18.1…
|
CWE-862
Missing Authorization
|
CVE-2026-33137
|
2026-05-27 04:16 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3576
|
- |
|
-
|
-
|
An authentication logic vulnerability in multiple TP-Link range extenders allows an unauthenticated attacker on an adjacent network to manipulate a login parameter and reset the administrator passwor…
|
CWE-20
Improper Input Validation
|
CVE-2026-3294
|
2026-05-27 04:08 |
2026-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3577
|
- |
|
-
|
-
|
NitroSense 3.x before 3.01.3052 contains Local Privilege Escalation (LPE) vulnerability.The program exposes a Windows Named Pipe that uses a custom protocol to invoke internal functions. However, thi…
|
CWE-22 CWE-269 CWE-284 CWE-732
Path Traversal Improper Privilege Management Improper Access Control Incorrect Permission Assignment for Critical Resource
|
CVE-2026-9489
|
2026-05-27 04:05 |
2026-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3578
|
- |
|
-
|
-
|
A security vulnerability has been identified in Acer Care Center where the ACCSvc service creates a Named Pipe with a weak Security Descriptor. This vulnerability allows an authenticated local user t…
|
CWE-269
Improper Privilege Management
|
CVE-2026-9490
|
2026-05-27 04:05 |
2026-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3579
|
7.2 |
HIGH
Network
|
concretecms
|
concrete_cms
|
Concrete CMS 9.5.0 and below fails to sanitize path traversal sequences in the ptComposerFormLayoutSetControlCustomTemplate field when saving page type composer form layouts. An authenticated rogue a…
|
CWE-23 CWE-98 CWE-434
Relative Path Traversal Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') Unrestricted Upload of File with Dangerous Type
|
CVE-2026-8134
|
2026-05-27 04:02 |
2026-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3580
|
8.8 |
HIGH
Network
|
concretecms
|
concrete_cms
|
Concrete CMS 9 before 9.5.0 is vulnerable to Cross Site Request Forgery (CSRF) at concrete/controllers/dialog/page/bulk/design. The Concrete CMS security team gave this vulnerability a CVSS v.4.0 sco…
|
CWE-352 CWE-1275
Origin Validation Error Sensitive Cookie with Improper SameSite Attribute
|
CVE-2026-8413
|
2026-05-27 04:01 |
2026-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|