|
1421
|
- |
|
-
|
-
|
Concrete CMS below 9.5.2 is vulnerable to PHP Object Injection via unserialize() calls in the in Permission, Cache, and Search components. An unauthenticated attacker may trigger arbitrary PHP objec…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-10721
|
2026-06-10 17:16 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1422
|
- |
|
-
|
-
|
A vulnerability has been found in some Dahua products could
allow an unauthenticated remote attacker to send a specially crafted packet,
triggering an exception that causes the system to reboot unexp…
|
CWE-617
Reachable Assertion
|
CVE-2026-29116
|
2026-06-10 16:16 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1423
|
- |
|
-
|
-
|
A vulnerability has been found in some Dahua products could allow an authenticated remote attacker to send a specially crafted packet, triggering an exception that causes the system to reboot unexpec…
|
CWE-617
Reachable Assertion
|
CVE-2026-29115
|
2026-06-10 16:16 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1424
|
- |
|
-
|
-
|
A vulnerability has been found in some Dahua products. An attacker
may obtain the device’s CA root certificate. If that CA is installed and
trusted on client systems, the attacker could issue fraudul…
|
CWE-538
File and Directory Information Exposure
|
CVE-2026-29114
|
2026-06-10 16:16 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1425
|
- |
|
-
|
-
|
An attacker who intercepts and tampers with traffic between the client application and the API Gateway server could potentially deserialize arbitrary objects. This vulnerability could lead to broken …
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-11815
|
2026-06-10 16:16 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1426
|
7.3 |
HIGH
Local
|
-
|
-
|
A local privilege escalation vulnerability was found in the ansible.posix authorized_key module. The module's keyfile() function uses os.chown() instead of os.lchown() and opens files without O_NOFOL…
|
CWE-59
Link Following
|
CVE-2026-11837
|
2026-06-10 14:16 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1427
|
2.4 |
LOW
Network
|
-
|
-
|
A weakness has been identified in FluentCMS 0.0.5. The impacted element is an unknown function of the file /admin/blocks of the component Blocks Plugin. This manipulation causes cross site scripting.…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-11434
|
2026-06-10 14:16 |
2026-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1428
|
- |
|
-
|
-
|
A cross-site request forgery (CSRF) vulnerability has been reported to affect Notification Center. The remote attackers can then exploit the vulnerability to gain privileges or hijack user identities…
|
CWE-352
Origin Validation Error
|
CVE-2025-58468
|
2026-06-10 12:16 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1429
|
5.4 |
MEDIUM
Network
|
-
|
-
|
WordPress Popup Builder 3.49 contains a persistent cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by breaking out of option tags in the post_title …
|
CWE-79
Cross-site Scripting
|
CVE-2019-25744
|
2026-06-10 11:16 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1430
|
5.4 |
MEDIUM
Network
|
-
|
-
|
WordPress Soliloquy Lite 2.5.6 contains a persistent cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by inserting script tags in the post title fiel…
|
CWE-79
Cross-site Scripting
|
CVE-2019-25743
|
2026-06-10 11:16 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|