Url redirection to untrusted site ('open redirect') in Microsoft 365 Copilot's Business Chat allows an unauthorized attacker to elevate privileges over a network.
CVSSv3.1 8.8 (HIGH)
CWECWE 601TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-19
2026-06-19 21:16Z
CRIT
CVE-2026-45480 — Azure: Improper authentication in Azure Active Directory allows an unauthorized attacker to elevate privileges over
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an authorized attacker to perform spoofing over a network.
CVSSv3.1 8.8 (HIGH)
CWECWE 79TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-19
2026-06-19 20:16Z
CRIT
CVE-2026-48773 — ProxySQL: Versions 2.0.18 through 3.0.8 have a pre-authentication heap memory corruption vulnerability in the MySQL
ProxySQL is a proxy for MySQL and its forks, as well as PostgreSQL. Versions 2.0.18 through 3.0.8 have a pre-authentication heap memory corruption vulnerability in the MySQL and PostgreSQL protocol first-read paths. A remote unauthenticated client can declare an oversized first packet length, and ProxySQL passes that attacker-controlled length directly to `recv()` while writing into a fixed 32 KB input queue. Version 3.0.9 patches the issue.
CVSSv3.1 9.8 (CRITICAL)
CWECWE 787VNDProxysqlTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-19
2026-06-19 20:16Z
CRIT
CVE-2026-48772 — ProxySQL: In practice this is a routing and ACL bypass.
ProxySQL is a proxy for MySQL and its forks, as well as PostgreSQL. In versions 2.0.0 through 3.0.8, the ProxySQL MySQL frontend accepts the `PROXY UNKNOWN <addr> <addr> <port> <port>\r\n` PP1 frame as a well-formed PROXY protocol header. The HAProxy PROXY protocol v1 specification says that when the protocol token is `UNKNOWN`, the receiver MUST ignore any address fields that follow it, because the proxy has declared it cannot determine the client identity. ProxySQL parses t
CVSSv3.1 10.0 (CRITICAL)
CWECWE 863CWECWE 348VNDProxysqlTYPVulnerability
10.0
CVSS v3.1
100
Edit Score
2026-06-19
2026-06-19 20:16Z
HIGH
CVE-2026-48715 — Radvd.litech Radvd: Prior to version 2.21, the `radvdump` utility shipped with radvd contains a stack buffer
radvd is a router advertisement daemon for IPv6. Prior to version 2.21, the `radvdump` utility shipped with radvd contains a stack buffer overflow in the Route Information option parser. When processing a crafted ICMPv6 Router Advertisement, `print_ff()` copies up to 2032 bytes from attacker-controlled packet data into a 16-byte `struct in6_addr` on the stack, overflowing by up to 2016 bytes. Note that the main `radvd` daemon is not affected by the vulnerability. Version 2.21
CVSSv3.1 8.8 (HIGH) · EPSS 5th percentile
CWECWE 121VNDRadvd LitechTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-06-19
2026-06-19 19:16Z
HIGH
CVE-2026-49340 — Prior to version 0.21.0, a logic error in `ServeCreateOrUpdatePlaylist` allows any authenticated Subsonic user
gonic is a music streaming server / free-software subsonic server API implementation. Prior to version 0.21.0, a logic error in `ServeCreateOrUpdatePlaylist` allows any authenticated Subsonic user (including non-admin) to write playlist M3U content to an attacker-controlled absolute filesystem path on the gonic host, and to create intermediate directories with `0o777` permissions. The bug is independent of CVE-2026-49338 and CVE-2026-49339. It is an unreachable guard clause c
CVSSv3.1 8.1 (HIGH)
CWECWE 22CWECWE 732CWECWE 697TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-19
2026-06-19 19:16Z
HIGH
CVE-2026-49291 — mcp-memory-service is a semantic memory layer for AI applications.
mcp-memory-service is a semantic memory layer for AI applications. Prior to version 10.65.3, the HTTP MCP JSON-RPC endpoint at `/mcp` requires only OAuth `read` scope for all requests, then dispatches `tools/call` directly to handlers that include mutating tools. A read-only OAuth client can call `store_memory` and `delete_memory` through MCP even though the corresponding REST endpoints require `write` scope. Version 10.65.3 patches the issue.
CVSSv3.1 8.1 (HIGH)
CWECWE 862TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-19
2026-06-19 18:16Z
HIGH
CVE-2026-49286 — PhpWeasyPrint: bypass the check and reach `fileExists()` (`file_exists()`) in `prepareOutput()`.
PhpWeasyPrint is a PHP library allowing PDF generation from a URL or an HTML page. Prior to version 2.6.0, `pontedilana/php-weasyprint` guarded the output filename against the `phar://` stream wrapper with a case-sensitive blacklist. PHP stream wrappers are case-insensitive, so `PHAR://`, `Phar://`, etc. bypass the check and reach `fileExists()` (`file_exists()`) in `prepareOutput()`. On PHP 7 (which the library still supports — PHP 7.4+), this triggers deserialization of a c
CVSSv3.1 8.1 (HIGH)
CWECWE 502VNDPhpweasyprintTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-19
2026-06-19 18:16Z
HIGH
CVE-2019-25758 — Component: vBizz 1.0.7 contains an unrestricted file upload vulnerability that allows authenticated attackers to
Joomla! Component vBizz 1.0.7 contains an unrestricted file upload vulnerability that allows authenticated attackers to upload arbitrary PHP files by submitting malicious files through the profile_pic parameter. Attackers can upload PHP files via POST requests to the employee view endpoint and execute them from the uploads directory to achieve remote code execution.
CVSSv3.1 8.8 (HIGH)
CWECWE 434TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-19
2026-06-19 18:16Z
HIGH
CVE-2019-25756 — Component: vAccount 2.0.2 contains an SQL injection vulnerability that allows unauthenticated attackers to execute
Joomla! Component vAccount 2.0.2 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the vid parameter. Attackers can send GET requests to the vaccount-dashboard/expense endpoint with crafted SQL payloads in the vid parameter to extract sensitive database information including version and database names.
CVSSv3.1 8.2 (HIGH)
CWECWE 89TYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-06-19
2026-06-19 18:16Z
HIGH
CVE-2019-25755 — Joomla: Component vReview 1.9.11 contains an SQL injection vulnerability that allows unauthenticated attackers to
Joomla Component vReview 1.9.11 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the cmId parameter. Attackers can send POST requests to the editReview task endpoint with URL-encoded SQL UNION statements in the cmId parameter to extract database information including usernames, passwords, and database versions.
CVSSv3.1 8.2 (HIGH)
CWECWE 89VNDJoomlaTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-06-19
2026-06-19 18:16Z
HIGH
CVE-2019-25754 — Joomla: Component vRestaurant 1.9.4 contains an SQL injection vulnerability that allows unauthenticated attackers to
Joomla Component vRestaurant 1.9.4 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the keysearch parameter. Attackers can send POST requests to the menu-listing-layout endpoint with crafted SQL payloads in the keysearch parameter to extract database table names and sensitive information from the database.
CVSSv3.1 8.2 (HIGH)
CWECWE 89VNDJoomlaTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-06-19
2026-06-19 18:16Z
HIGH
CVE-2019-25753 — Component: VMap 1.9.6 contains an SQL injection vulnerability that allows unauthenticated attackers to execute
Joomla! Component VMap 1.9.6 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code into the latlngbound parameter. Attackers can send GET requests to index.php with the option=com_vmap&task=loadmarker parameters containing SQL injection payloads to manipulate database queries and extract sensitive information.
CVSSv3.1 8.2 (HIGH)
CWECWE 89TYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-06-19
2026-06-19 18:16Z
HIGH
CVE-2019-25752 — Component: J-BusinessDirectory 4.9.7 contains an SQL injection vulnerability that allows unauthenticated attackers to execute
Joomla! Component J-BusinessDirectory 4.9.7 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the type parameter. Attackers can send GET requests to index.php with the option=com_jbusinessdirectory&task=categories.getCategories parameters and inject UNION-based SQL statements in the type parameter to extract database information including schema names and sensitive data.
CVSSv3.1 8.2 (HIGH)
CWECWE 89TYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-06-19
2026-06-19 18:16Z
HIGH
CVE-2019-25751 — Joomla: Component J-ClassifiedsManager 3.0.5 contains an SQL injection vulnerability that allows unauthenticated attackers to
Joomla Component J-ClassifiedsManager 3.0.5 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through POST parameters. Attackers can submit crafted SQL payloads in the categorySearch, adType, and citySearch parameters to the displayads component to extract sensitive database information including usernames, databases, and version details.
CVSSv3.1 8.2 (HIGH)
CWECWE 89VNDJoomlaTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-06-19
2026-06-19 18:16Z
HIGH
CVE-2019-25750 — Joomla: Component J-MultipleHotelReservation 6.0.7 contains an SQL injection vulnerability that allows unauthenticated attackers to
Joomla Component J-MultipleHotelReservation 6.0.7 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the hotel_id parameter. Attackers can send POST requests to the search-hotels endpoint with crafted SQL UNION SELECT statements to extract sensitive database information including table names and column data.
CVSSv3.1 8.2 (HIGH)
CWECWE 89VNDJoomlaTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-06-19
2026-06-19 17:16Z
CRIT
CVE-2026-51846 — Tenda: In Tenda AC7 v15.03.06.44, the wanSpeed parameter of the route /goform/AdvSetMacMtuWan has a stack
In Tenda AC7 v15.03.06.44, the wanSpeed parameter of the route /goform/AdvSetMacMtuWan has a stack buffer overflow vulnerability that can lead to remote arbitrary code execution.
CVSSv3.1 9.8 (CRITICAL)
CWECWE 121VNDTendaTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-19
2026-06-19 17:16Z
CRIT
CVE-2026-51845 — Tenda: AC7 v15.03.06.44 contains a stack buffer overflow vulnerability in the /goform/AdvSetMacMtuWan interface via
Tenda AC7 v15.03.06.44 contains a stack buffer overflow vulnerability in the /goform/AdvSetMacMtuWan interface via the mac parameter.
CVSSv3.1 9.8 (CRITICAL)
CWECWE 121VNDTendaTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-19
2026-06-19 17:16Z
CRIT
CVE-2026-51844 — Tenda: AC7 v15.03.06.44 contains a stack buffer overflow vulnerability in the /goform/AdvSetMacMtuWan interface via
Tenda AC7 v15.03.06.44 contains a stack buffer overflow vulnerability in the /goform/AdvSetMacMtuWan interface via the cloneType parameter.
CVSSv3.1 9.8 (CRITICAL)
CWECWE 121VNDTendaTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-19
2026-06-19 17:16Z
CRIT
CVE-2026-51843 — Tenda: AC7 v15.03.06.44 contains a stack buffer overflow vulnerability in the /goform/AdvSetMacMtuWan interface via
Tenda AC7 v15.03.06.44 contains a stack buffer overflow vulnerability in the /goform/AdvSetMacMtuWan interface via the wanMTU parameter.
CVSSv3.1 9.8 (CRITICAL)
CWECWE 121VNDTendaTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-19
2026-06-19 17:16Z
HIGH
CVE-2026-49260 — PhpWeasyPrint: Any deployment whose binary path is sourced from configuration, an environment variable, or a
PhpWeasyPrint is a PHP library allowing PDF generation from a URL or an HTML page. Prior to version 2.5.1, `pontedilana/php-weasyprint` builds the shell command for WeasyPrint by passing the binary path through `escapeshellarg()` first and then checking the *quoted* result with `is_executable()`. On POSIX `escapeshellarg('/usr/local/bin/weasyprint')` returns `'/usr/local/bin/weasyprint'` with the single-quote characters as part of the string, so `is_executable()` looks for a
CVSSv3.1 8.2 (HIGH)
CWECWE 78VNDPhpweasyprintTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-06-19
2026-06-19 17:16Z
HIGH
CVE-2019-25748 — Joomla: JHotelReservation 6.0.7 contains an SQL injection vulnerability that allows unauthenticated attackers to execute
Joomla JHotelReservation 6.0.7 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the rooms parameter. Attackers can send POST requests to the search-hotels endpoint with crafted SQL payloads in the rooms parameter to extract sensitive database information including version details.
CVSSv3.1 8.2 (HIGH)
CWECWE 89VNDJoomlaTYPVulnerability
8.2
CVSS v3.1
91
Edit Score
2026-06-19
2026-06-19 17:16Z
HIGH
CVE-2017-20282 — Component: jCart for OpenCart 2.0 contains an SQL injection vulnerability that allows unauthenticated attackers
Joomla! Component jCart for OpenCart 2.0 contains an SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code through the product_id parameter. Attackers can send GET requests to index.php with the option=com_jcart&route=product/product parameters and malicious product_id values to extract sensitive database information.
CVSSv3.1 8.2 (HIGH)