|
1041
|
5.3 |
MEDIUM
Network
|
-
|
-
|
Unauthenticated Broken Access Control in Donation Thermometer <= 2.2.7 versions.
|
CWE-862
Missing Authorization
|
CVE-2025-64636
|
2026-06-27 01:16 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1042
|
4.3 |
MEDIUM
Network
|
-
|
-
|
Contributor Broken Access Control in Live Copy Paste for Elementor <= 1.5.3 versions.
|
CWE-862
Missing Authorization
|
CVE-2025-63079
|
2026-06-27 01:16 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1043
|
5.4 |
MEDIUM
Network
|
-
|
-
|
The Mattermost Go module github.com/mattermost/mattermost/server/public versions < v0.1.22 fail to validate path parameters when constructing API route paths which allows an attacker to redirect API …
|
CWE-22
Path Traversal
|
CVE-2026-13426
|
2026-06-27 01:12 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1044
|
5.9 |
MEDIUM
Network
|
-
|
-
|
A flaw in Node.js proxy tunnel error handling could expose proxy credentials in `ERR_PROXY_TUNNEL` error messages.
When proxy credentials are embedded in the proxy URL, they may be exposed through…
|
CWE-359
Exposure of Private Personal Information to an Unauthorized Actor
|
CVE-2026-48615
|
2026-06-27 01:11 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1045
|
5.3 |
MEDIUM
Network
|
-
|
-
|
A flaw in Node.js HTTP/2 client allows a server to send an unlimited number of ORIGIN frames, which could lead to an Out of Memory error on the client.
This vulnerability affects all supported rel…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2026-48619
|
2026-06-27 01:11 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1046
|
4.2 |
MEDIUM
Network
|
-
|
-
|
A inconsistency in Node.js hostname matching can cause a trust-policy bypass in multi-context mTLS setups.
This vulnerability affects all supported release lines: **Node.js 22**, **Node.js 24**, a…
|
CWE-284
Improper Access Control
|
CVE-2026-48928
|
2026-06-27 01:11 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1047
|
5.6 |
MEDIUM
Network
|
-
|
-
|
A flaw in Node.js TLS hostname handling can cause Embedded-nul hostnames can lead to silent authority rebinding due to c-string truncation in resolver bindings.
This vulnerability affects all supp…
|
CWE-284
Improper Access Control
|
CVE-2026-48930
|
2026-06-27 01:11 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1048
|
3.3 |
LOW
Local
|
-
|
-
|
A flaw in Node.js Permission API can cause a file metadata to be modified even on a path that was set as read-only with e.g. `--allow-fs-read`.
This vulnerability affects all supported release lin…
|
CWE-276
Incorrect Default Permissions
|
CVE-2026-48935
|
2026-06-27 01:11 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1049
|
3.3 |
LOW
Local
|
-
|
-
|
A flaw in Node.js Permission API can cause a local server to be started (via a Unix domain socket), even without the `--allow-net` permission.
This vulnerability affects one supported release line…
|
CWE-284
Improper Access Control
|
CVE-2026-48936
|
2026-06-27 01:11 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1050
|
4.3 |
MEDIUM
Network
|
-
|
-
|
A bypass for CVE‑2026‑34913 exists with proper ownership validation that had not been applied to the reverse operation of linking campaigns and trackers through the `tracker-campaigns.php` script in …
|
CWE-284
Improper Access Control
|
CVE-2026-50739
|
2026-06-27 01:11 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|