|
1771
|
9.1 |
CRITICAL
Network
|
apache
|
apisix
|
Insufficient Verification of Data Authenticity vulnerability in Apache APISIX.
The openid-connect plugin under default configuration has an attack surface that allows the attacker to spoof identity …
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2026-44087
|
2026-06-24 00:11 |
2026-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1772
|
5.8 |
MEDIUM
Network
|
apache
|
apisix
|
Use of Less Trusted Source vulnerability in Apache APISIX.
Attacker can take advantage of wolf-rbac plugin under default configuration to potentially pollute logs with spoofed identity information a…
|
CWE-348
Use of Less Trusted Source
|
CVE-2026-44046
|
2026-06-24 00:10 |
2026-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1773
|
7.8 |
HIGH
Local
|
-
|
-
|
Realtek Audio Service 1.0.0.55 contains an unquoted service path vulnerability in RtkAudioService64.exe that allows local attackers to escalate privileges by injecting malicious code. Attackers can p…
|
CWE-428
Unquoted Search Path or Element
|
CVE-2020-37252
|
2026-06-24 00:09 |
2026-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1774
|
9.1 |
CRITICAL
Network
|
apache
|
apisix
|
Authentication Bypass by Spoofing vulnerability in Apache APISIX.
The attacker can completely bypass authentication capitalising on certain configurations of jwt-auth plugin.
This issue affects Apac…
|
CWE-290
Authentication Bypass by Spoofing
|
CVE-2026-39999
|
2026-06-24 00:08 |
2026-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1775
|
- |
|
-
|
-
|
Overview:
A vulnerability has been found in FAST/TOOLS and CI Server. The web server may return a response containing the CI Server setting information. This information could
be exploited by an at…
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2026-11833
|
2026-06-24 00:06 |
2026-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1776
|
- |
|
-
|
-
|
Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to 0.6.5 and 0.5.15, when Net::IMAP#id is called with a hash argument, although the ID field value str…
|
CWE-77 CWE-93
Command Injection CRLF Injection
|
CVE-2026-47242
|
2026-06-24 00:03 |
2026-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1777
|
5.3 |
MEDIUM
Network
|
-
|
-
|
Filament is a collection of full-stack components for accelerated Laravel development. From 4.0.0 until 4.11.5 and 5.6.5, the login page has an observable timing discrepancy that allows unauthenticat…
|
CWE-208
Information Exposure Through Timing Discrepancy
|
CVE-2026-48166
|
2026-06-24 00:03 |
2026-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1778
|
6.4 |
MEDIUM
Network
|
-
|
-
|
Filament is a collection of full-stack components for accelerated Laravel development. From 4.0.0 until 4.11.5 and 5.6.5, the ImageColumn and ImageEntry components render raw database values without …
|
CWE-79
Cross-site Scripting
|
CVE-2026-48167
|
2026-06-24 00:03 |
2026-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1779
|
7.6 |
HIGH
Network
|
-
|
-
|
Filament is a collection of full-stack components for accelerated Laravel development. From 3.0.0 until 3.3.53, a disabled RichEditor field rendered its raw state without sanitizing HTML. Where the d…
|
CWE-79
Cross-site Scripting
|
CVE-2026-55409
|
2026-06-24 00:03 |
2026-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1780
|
8.8 |
HIGH
Network
|
apache
|
apisix
|
Improper Input Validation vulnerability in Apache APISIX.
The attacker can take advantage of certain configuration in forward-auth plugin to spoof identity headers.
This issue affects Apache APISIX:…
|
CWE-20
Improper Input Validation
|
CVE-2026-39998
|
2026-06-23 23:57 |
2026-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|