|
2301
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Capgo before 12.128.2 contains a cross-tenant authorization bypass vulnerability in PostgREST endpoints that allows org-scoped read API keys to access other tenants' webhook secrets and delivery logs…
|
CWE-200
Information Exposure
|
CVE-2026-56079
|
2026-06-23 04:17 |
2026-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2302
|
8.8 |
HIGH
Network
|
-
|
-
|
PraisonAI before 1.5.115 contains a path traversal vulnerability in MultiAgentMonitor that fails to sanitize agent IDs when building file paths. Attackers can include traversal sequences like ../ in …
|
CWE-22
Path Traversal
|
CVE-2026-56078
|
2026-06-23 04:17 |
2026-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2303
|
- |
|
-
|
-
|
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
|
-
|
CVE-2026-53778
|
2026-06-23 04:17 |
2026-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2304
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Initialization of a resource with an insecure default in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to disclose information over a network.
|
CWE-1188
Insecure Default Initialization of Resource
|
CVE-2026-50519
|
2026-06-23 04:17 |
2026-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2305
|
- |
|
-
|
-
|
Angular is a development platform for building mobile and desktop web applications using TypeScript/JavaScript and other languages. Prior to 22.0.0-rc.2, 21.2.15, 20.3.22, and 19.2.23, an issue in th…
|
CWE-346 CWE-918
Origin Validation Error Server-Side Request Forgery (SSRF)
|
CVE-2026-50168
|
2026-06-23 04:17 |
2026-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2306
|
6.4 |
MEDIUM
Network
|
-
|
-
|
The Appointment Booking Calendar plugin for WordPress is vulnerable to Stored Cross-Site Scripting via custom booking field labels in all versions up to, and including, 1.4.4 due to insufficient inpu…
|
CWE-79
Cross-site Scripting
|
CVE-2026-1856
|
2026-06-23 04:16 |
2026-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2307
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability has been found in coollabsio coolify 4.0.0. Impacted is an unknown function of the component Image Name Handler. Such manipulation leads to os command injection. The attack may be per…
|
CWE-77 CWE-78
Command Injection OS Command
|
CVE-2026-12815
|
2026-06-23 04:16 |
2026-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2308
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was determined in zhilink 智互联(深圳)科技有限公司 ADP Application Developer Platform 应用开发者平台 1.0.0. This vulnerability affects unknown code of the file /adpweb/a/base/barcodeDetail/import of th…
|
CWE-610 CWE-611
Externally Controlled Reference to a Resource in Another Sphere XXE
|
CVE-2026-12788
|
2026-06-23 04:16 |
2026-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2309
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was found in zhilink 智互联(深圳)科技有限公司 ADP Application Developer Platform 应用开发者平台 1.0.0. This affects an unknown part of the component testConnection Endpoint. The manipulation of the arg…
|
CWE-20 CWE-502
Improper Input Validation Deserialization of Untrusted Data
|
CVE-2026-12787
|
2026-06-23 04:16 |
2026-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2310
|
7.8 |
HIGH
Local
|
-
|
-
|
A weakness has been identified in IM-Magic Partition Resizer up to 7.9.0. This affects an unknown function in the library MDA_NTDRV.sys of the component Kernel Driver. This manipulation causes improp…
|
CWE-266 CWE-284
Incorrect Privilege Assignment Improper Access Control
|
CVE-2026-12784
|
2026-06-23 04:16 |
2026-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|