|
341
|
8.8 |
HIGH
Network
|
-
|
-
|
Teable's v2 REST API controller lacks @Permissions metadata on ORPC endpoints, allowing any authenticated user to bypass authorization checks. Attackers can read table schemas, create tables, and mod…
New
|
CWE-862
Missing Authorization
|
CVE-2026-56773
|
2026-06-27 00:16 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342
|
8.6 |
HIGH
Network
|
-
|
-
|
Crawl4AI is an open-source LLM friendly web crawler & scraper. Prior to 0.8.9, the Docker API server applied its SSRF destination check to the crawl target URL only, not to the proxy address. An unau…
New
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-53755
|
2026-06-27 00:16 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343
|
7.5 |
HIGH
Network
|
-
|
-
|
An issue in the pthread_rwlockattr_setpshared() function of relibc commit 61f42d allows attackers to cause a Denial of Service (DoS) via a crafted input.
New
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2026-38637
|
2026-06-27 00:16 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344
|
7.5 |
HIGH
Network
|
-
|
-
|
Insecure Permissions vulnerability in MSI NBFoundation Service v.2.0.2506.1201 allows a remote attacker to obtain sensitive information via the 3DES-ECB encryption
New
|
CWE-200
Information Exposure
|
CVE-2026-37454
|
2026-06-27 00:16 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345
|
7.5 |
HIGH
Network
|
-
|
-
|
Insecure Permissions vulnerability in MSI NBFoundation Service v.2.0.2506.1201 allows a remote attacker to obtain sensitive information via the MSI_SERVICE_2 pipe
New
|
CWE-200
Information Exposure
|
CVE-2026-37453
|
2026-06-27 00:16 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346
|
7.5 |
HIGH
Network
|
-
|
-
|
Insecure Permissions vulnerability in MSI NBFoundation Service v.2.0.2506.1201 allows a remote attacker to obtain sensitive information via the MSIAPService.exe component
New
|
CWE-200
Information Exposure
|
CVE-2026-37452
|
2026-06-27 00:16 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347
|
7.7 |
HIGH
Local
|
-
|
-
|
GROCERY-STORE-MANAGEMENT-SYSTEM-USING-PHP-AND-MYSQL-PHPMYADMIN v1.0 was discovered to contain a SQL injection vulnerability in the scost parameter in /grocery/search_products.php. This vulnerability …
New
|
CWE-89
SQL Injection
|
CVE-2026-37149
|
2026-06-27 00:16 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348
|
- |
|
-
|
-
|
FOSSBilling is a free, open-source billing and client management system. In versions 0.7.2 and prior, a query-construction flaw in client list endpoints allowed authenticated clients to bypass tenant…
New
|
CWE-863
Incorrect Authorization
|
CVE-2026-23513
|
2026-06-27 00:16 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349
|
6.5 |
MEDIUM
Network
|
-
|
-
|
By sending a deeply nested ASN1 structure to a Apache Kerby client or service, it's possible to trigger a StackOverFlow Exception which can lead to denial of service issues. Users are recommended to …
New
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2026-57914
|
2026-06-26 23:51 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350
|
- |
|
-
|
-
|
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache IoTDB.
This issue affects Apache IoTDB: from 2.0.0 before 2.0.6, from 1.0.0 before 1.3.6.
User…
New
|
CWE-22
Path Traversal
|
CVE-2025-55017
|
2026-06-26 23:51 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|