2026-06-19
2026-06-19 21:17Z
CRIT

CVE-2026-48582 — Microsoft: Missing authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48582

Missing authorization in Microsoft Exchange Online allows an authorized attacker to elevate privileges over a network. CVSSv3.1 9.6 (CRITICAL)

CWECWE 862VNDMicrosoftTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-06-19
2026-06-19 21:16Z
HIGH

CVE-2026-47645 — Url: redirection to untrusted site ('open redirect') in Microsoft 365 Copilot's Business Chat allows

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47645

Url redirection to untrusted site ('open redirect') in Microsoft 365 Copilot's Business Chat allows an unauthorized attacker to elevate privileges over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 601TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-19
2026-06-19 21:16Z
CRIT

CVE-2026-45480 — Azure: Improper authentication in Azure Active Directory allows an unauthorized attacker to elevate privileges over

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45480

Improper authentication in Azure Active Directory allows an unauthorized attacker to elevate privileges over a network. CVSSv3.1 10.0 (CRITICAL)

CWECWE 287VNDAzureTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-06-19
2026-06-19 21:16Z
HIGH

CVE-2026-32208 — Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based)

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-32208

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an authorized attacker to perform spoofing over a network. CVSSv3.1 8.8 (HIGH)

CWECWE 79TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-19
2026-06-19 20:16Z
CRIT

CVE-2026-48773 — ProxySQL: Versions 2.0.18 through 3.0.8 have a pre-authentication heap memory corruption vulnerability in the MySQL

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48773

ProxySQL is a proxy for MySQL and its forks, as well as PostgreSQL. Versions 2.0.18 through 3.0.8 have a pre-authentication heap memory corruption vulnerability in the MySQL and PostgreSQL protocol first-read paths. A remote unauthenticated client can declare an oversized first packet length, and ProxySQL passes that attacker-controlled length directly to `recv()` while writing into a fixed 32 KB input queue. Version 3.0.9 patches the issue. CVSSv3.1 9.8 (CRITICAL)

CWECWE 787VNDProxysqlTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-19
2026-06-19 20:16Z
CRIT

CVE-2026-48772 — ProxySQL: In practice this is a routing and ACL bypass.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48772

ProxySQL is a proxy for MySQL and its forks, as well as PostgreSQL. In versions 2.0.0 through 3.0.8, the ProxySQL MySQL frontend accepts the `PROXY UNKNOWN <addr> <addr> <port> <port>\r\n` PP1 frame as a well-formed PROXY protocol header. The HAProxy PROXY protocol v1 specification says that when the protocol token is `UNKNOWN`, the receiver MUST ignore any address fields that follow it, because the proxy has declared it cannot determine the client identity. ProxySQL parses t CVSSv3.1 10.0 (CRITICAL)

CWECWE 863CWECWE 348VNDProxysqlTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-06-19
2026-06-19 20:16Z
HIGH

CVE-2026-48715 — Radvd.litech Radvd: Prior to version 2.21, the `radvdump` utility shipped with radvd contains a stack buffer

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48715

radvd is a router advertisement daemon for IPv6. Prior to version 2.21, the `radvdump` utility shipped with radvd contains a stack buffer overflow in the Route Information option parser. When processing a crafted ICMPv6 Router Advertisement, `print_ff()` copies up to 2032 bytes from attacker-controlled packet data into a 16-byte `struct in6_addr` on the stack, overflowing by up to 2016 bytes. Note that the main `radvd` daemon is not affected by the vulnerability. Version 2.21 CVSSv3.1 8.8 (HIGH) · EPSS 5th percentile

CWECWE 121VNDRadvd LitechTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-06-19
2026-06-19 19:16Z
HIGH

CVE-2026-49340 — Prior to version 0.21.0, a logic error in `ServeCreateOrUpdatePlaylist` allows any authenticated Subsonic user

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-49340

gonic is a music streaming server / free-software subsonic server API implementation. Prior to version 0.21.0, a logic error in `ServeCreateOrUpdatePlaylist` allows any authenticated Subsonic user (including non-admin) to write playlist M3U content to an attacker-controlled absolute filesystem path on the gonic host, and to create intermediate directories with `0o777` permissions. The bug is independent of CVE-2026-49338 and CVE-2026-49339. It is an unreachable guard clause c CVSSv3.1 8.1 (HIGH)

CWECWE 22CWECWE 732CWECWE 697TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-19
2026-06-19 19:16Z
HIGH

CVE-2026-49291 — mcp-memory-service is a semantic memory layer for AI applications.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-49291

mcp-memory-service is a semantic memory layer for AI applications. Prior to version 10.65.3, the HTTP MCP JSON-RPC endpoint at `/mcp` requires only OAuth `read` scope for all requests, then dispatches `tools/call` directly to handlers that include mutating tools. A read-only OAuth client can call `store_memory` and `delete_memory` through MCP even though the corresponding REST endpoints require `write` scope. Version 10.65.3 patches the issue. CVSSv3.1 8.1 (HIGH)

CWECWE 862TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-19
2026-06-19 18:16Z
HIGH

CVE-2026-49286 — PhpWeasyPrint: bypass the check and reach `fileExists()` (`file_exists()`) in `prepareOutput()`.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-49286

PhpWeasyPrint is a PHP library allowing PDF generation from a URL or an HTML page. Prior to version 2.6.0, `pontedilana/php-weasyprint` guarded the output filename against the `phar://` stream wrapper with a case-sensitive blacklist. PHP stream wrappers are case-insensitive, so `PHAR://`, `Phar://`, etc. bypass the check and reach `fileExists()` (`file_exists()`) in `prepareOutput()`. On PHP 7 (which the library still supports — PHP 7.4+), this triggers deserialization of a c CVSSv3.1 8.1 (HIGH)

CWECWE 502VNDPhpweasyprintTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-19
2026-06-19 18:16Z
HIGH

CVE-2019-25758 — Component: vBizz 1.0.7 contains an unrestricted file upload vulnerability that allows authenticated attackers to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2019-25758

Joomla! Component vBizz 1.0.7 contains an unrestricted file upload vulnerability that allows authenticated attackers to upload arbitrary PHP files by submitting malicious files through the profile_pic parameter. Attackers can upload PHP files via POST requests to the employee view endpoint and execute them from the uploads directory to achieve remote code execution. CVSSv3.1 8.8 (HIGH)

CWECWE 434TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-19
2026-06-19 18:16Z
HIGH

CVE-2019-25756 — Component: vAccount 2.0.2 contains an SQL injection vulnerability that allows unauthenticated attackers to execute

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2019-25756

Joomla! Component vAccount 2.0.2 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the vid parameter. Attackers can send GET requests to the vaccount-dashboard/expense endpoint with crafted SQL payloads in the vid parameter to extract sensitive database information including version and database names. CVSSv3.1 8.2 (HIGH)

CWECWE 89TYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-06-19
2026-06-19 18:16Z
HIGH

CVE-2019-25755 — Joomla: Component vReview 1.9.11 contains an SQL injection vulnerability that allows unauthenticated attackers to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2019-25755

Joomla Component vReview 1.9.11 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the cmId parameter. Attackers can send POST requests to the editReview task endpoint with URL-encoded SQL UNION statements in the cmId parameter to extract database information including usernames, passwords, and database versions. CVSSv3.1 8.2 (HIGH)

CWECWE 89VNDJoomlaTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-06-19
2026-06-19 18:16Z
HIGH

CVE-2019-25754 — Joomla: Component vRestaurant 1.9.4 contains an SQL injection vulnerability that allows unauthenticated attackers to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2019-25754

Joomla Component vRestaurant 1.9.4 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the keysearch parameter. Attackers can send POST requests to the menu-listing-layout endpoint with crafted SQL payloads in the keysearch parameter to extract database table names and sensitive information from the database. CVSSv3.1 8.2 (HIGH)

CWECWE 89VNDJoomlaTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-06-19
2026-06-19 18:16Z
HIGH

CVE-2019-25753 — Component: VMap 1.9.6 contains an SQL injection vulnerability that allows unauthenticated attackers to execute

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2019-25753

Joomla! Component VMap 1.9.6 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code into the latlngbound parameter. Attackers can send GET requests to index.php with the option=com_vmap&task=loadmarker parameters containing SQL injection payloads to manipulate database queries and extract sensitive information. CVSSv3.1 8.2 (HIGH)

CWECWE 89TYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-06-19
2026-06-19 18:16Z
HIGH

CVE-2019-25752 — Component: J-BusinessDirectory 4.9.7 contains an SQL injection vulnerability that allows unauthenticated attackers to execute

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2019-25752

Joomla! Component J-BusinessDirectory 4.9.7 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the type parameter. Attackers can send GET requests to index.php with the option=com_jbusinessdirectory&task=categories.getCategories parameters and inject UNION-based SQL statements in the type parameter to extract database information including schema names and sensitive data. CVSSv3.1 8.2 (HIGH)

CWECWE 89TYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-06-19
2026-06-19 18:16Z
HIGH

CVE-2019-25751 — Joomla: Component J-ClassifiedsManager 3.0.5 contains an SQL injection vulnerability that allows unauthenticated attackers to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2019-25751

Joomla Component J-ClassifiedsManager 3.0.5 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through POST parameters. Attackers can submit crafted SQL payloads in the categorySearch, adType, and citySearch parameters to the displayads component to extract sensitive database information including usernames, databases, and version details. CVSSv3.1 8.2 (HIGH)

CWECWE 89VNDJoomlaTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-06-19
2026-06-19 18:16Z
HIGH

CVE-2019-25750 — Joomla: Component J-MultipleHotelReservation 6.0.7 contains an SQL injection vulnerability that allows unauthenticated attackers to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2019-25750

Joomla Component J-MultipleHotelReservation 6.0.7 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the hotel_id parameter. Attackers can send POST requests to the search-hotels endpoint with crafted SQL UNION SELECT statements to extract sensitive database information including table names and column data. CVSSv3.1 8.2 (HIGH)

CWECWE 89VNDJoomlaTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-06-19
2026-06-19 17:16Z
CRIT

CVE-2026-51846 — Tenda: In Tenda AC7 v15.03.06.44, the wanSpeed parameter of the route /goform/AdvSetMacMtuWan has a stack

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51846

In Tenda AC7 v15.03.06.44, the wanSpeed parameter of the route /goform/AdvSetMacMtuWan has a stack buffer overflow vulnerability that can lead to remote arbitrary code execution. CVSSv3.1 9.8 (CRITICAL)

CWECWE 121VNDTendaTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-19
2026-06-19 17:16Z
CRIT

CVE-2026-51845 — Tenda: AC7 v15.03.06.44 contains a stack buffer overflow vulnerability in the /goform/AdvSetMacMtuWan interface via

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51845

Tenda AC7 v15.03.06.44 contains a stack buffer overflow vulnerability in the /goform/AdvSetMacMtuWan interface via the mac parameter. CVSSv3.1 9.8 (CRITICAL)

CWECWE 121VNDTendaTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-19
2026-06-19 17:16Z
CRIT

CVE-2026-51844 — Tenda: AC7 v15.03.06.44 contains a stack buffer overflow vulnerability in the /goform/AdvSetMacMtuWan interface via

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51844

Tenda AC7 v15.03.06.44 contains a stack buffer overflow vulnerability in the /goform/AdvSetMacMtuWan interface via the cloneType parameter. CVSSv3.1 9.8 (CRITICAL)

CWECWE 121VNDTendaTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-19
2026-06-19 17:16Z
CRIT

CVE-2026-51843 — Tenda: AC7 v15.03.06.44 contains a stack buffer overflow vulnerability in the /goform/AdvSetMacMtuWan interface via

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-51843

Tenda AC7 v15.03.06.44 contains a stack buffer overflow vulnerability in the /goform/AdvSetMacMtuWan interface via the wanMTU parameter. CVSSv3.1 9.8 (CRITICAL)

CWECWE 121VNDTendaTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-19
2026-06-19 17:16Z
HIGH

CVE-2026-49260 — PhpWeasyPrint: Any deployment whose binary path is sourced from configuration, an environment variable, or a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-49260

PhpWeasyPrint is a PHP library allowing PDF generation from a URL or an HTML page. Prior to version 2.5.1, `pontedilana/php-weasyprint` builds the shell command for WeasyPrint by passing the binary path through `escapeshellarg()` first and then checking the *quoted* result with `is_executable()`. On POSIX `escapeshellarg('/usr/local/bin/weasyprint')` returns `'/usr/local/bin/weasyprint'` with the single-quote characters as part of the string, so `is_executable()` looks for a CVSSv3.1 8.2 (HIGH)

CWECWE 78VNDPhpweasyprintTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-06-19
2026-06-19 17:16Z
HIGH

CVE-2019-25748 — Joomla: JHotelReservation 6.0.7 contains an SQL injection vulnerability that allows unauthenticated attackers to execute

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2019-25748

Joomla JHotelReservation 6.0.7 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the rooms parameter. Attackers can send POST requests to the search-hotels endpoint with crafted SQL payloads in the rooms parameter to extract sensitive database information including version details. CVSSv3.1 8.2 (HIGH)

CWECWE 89VNDJoomlaTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-06-19
2026-06-19 17:16Z
HIGH

CVE-2017-20282 — Component: jCart for OpenCart 2.0 contains an SQL injection vulnerability that allows unauthenticated attackers

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2017-20282

Joomla! Component jCart for OpenCart 2.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the product_id parameter. Attackers can send GET requests to index.php with the option=com_jcart&route=product/product parameters and malicious product_id values to extract sensitive database information. CVSSv3.1 8.2 (HIGH)

CWECWE 89TYPVulnerability
8.2
CVSS v3.1
91
Edit Score