2026-06-15
2026-06-15 21:16Z
CRIT

CVE-2026-34901 — Privilege: Unauthenticated Privilege Escalation in iControlWP <= 5.5.3 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-34901

Unauthenticated Privilege Escalation in iControlWP <= 5.5.3 versions. CVSSv3.1 9.8 (CRITICAL)

CWECWE 266TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-15
2026-06-15 21:16Z
HIGH

CVE-2026-27333 — Deserialization: Unauthenticated Deserialization of untrusted data in Paid Videochat Turnkey Site <= 7.3.23 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-27333

Unauthenticated Deserialization of untrusted data in Paid Videochat Turnkey Site <= 7.3.23 versions. CVSSv3.1 8.1 (HIGH)

CWECWE 502TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-15
2026-06-15 21:16Z
CRIT

CVE-2026-27053 — PHP: Unauthenticated PHP Object Injection in Broadcast Live Video < 7.1.3 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-27053

Unauthenticated PHP Object Injection in Broadcast Live Video < 7.1.3 versions. CVSSv3.1 9.8 (CRITICAL)

CWECWE 502TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-15
2026-06-15 21:16Z
HIGH

CVE-2026-24637 — Contributor: SQL Injection in PowerPress Podcasting <= 11.15.10 versions.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-24637

Contributor SQL Injection in PowerPress Podcasting <= 11.15.10 versions. CVSSv3.1 8.5 (HIGH)

CWECWE 89VNDContributorTYPVulnerability
8.5
CVSS v3.1
93
Edit Score
2026-06-15
2026-06-15 20:55Z
INFO

v9.3.0-rc6

BloodHound releases·github.com

BloodHound v9.3.0-rc6 release candidate published with minor maintenance updates including npm audit warning fixes, database migration improvements, and AzureHound version bump to v2.12.2.

SWBloodhoundVNDSpecteropsTYPTool
25
Edit Score
2026-06-15
2026-06-15 20:16Z
HIGH

CVE-2026-52720 — A heap buffer overflow vulnerability was found in GStreamer's librfb (RFB/VNC client).

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-52720

A heap buffer overflow vulnerability was found in GStreamer's librfb (RFB/VNC client). The rectangle bounds check incorrectly validates area rather than individual dimensions, allowing a malicious VNC server to send a rectangle that extends beyond the framebuffer. A remote attacker could set up a malicious VNC server and trick a user into connecting, resulting in an out-of-bounds heap write that could lead to code execution or a crash. CVSSv3.1 8.8 (HIGH)

CWECWE 122TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-15
2026-06-15 20:16Z
HIGH

CVE-2026-50891 — Incorrect: access control in the /admin/api/config component of Filestash v0.4.0 allows attackers to escalate

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-50891

Incorrect access control in the /admin/api/config component of Filestash v0.4.0 allows attackers to escalate privileges via sending a crafted request. CVSSv3.1 8.1 (HIGH)

CWECWE 284TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-06-15
2026-06-15 20:16Z
CRIT

CVE-2026-50890 — Bernd: Bestel grocy v4.6.0 was discovered to contain a SQL injection vulnerability in the

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-50890

Bernd Bestel grocy v4.6.0 was discovered to contain a SQL injection vulnerability in the product-group parameter at /stockreports/spendings. This vulnerability allows attackers to access sensitive database information via a crafted SQL statement. CVSSv3.1 9.8 (CRITICAL)

CWECWE 89VNDBerndTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-15
2026-06-15 20:16Z
HIGH

CVE-2026-50888 — Server: An authenticated Server-Side Request Forgery (SSRF) in the custom scraper subsystem component of Benjamin

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-50888

An authenticated Server-Side Request Forgery (SSRF) in the custom scraper subsystem component of Benjamin Jonard Koillection v1.8.0 allows attackers to scan internal resources via supplying a crafted URL. CVSSv3.1 8.1 (HIGH)

CWECWE 918TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-15
2026-06-15 20:16Z
CRIT

CVE-2026-50887 — Server: A Server-Side Request Forgery (SSRF) in the automatic short URL title resolution component of

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-50887

A Server-Side Request Forgery (SSRF) in the automatic short URL title resolution component of shlink v5.0.1 allows attackers to scan internal resources via supplying a crafted longUrl. CVSSv3.1 9.1 (CRITICAL)

CWECWE 918TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-06-15
2026-06-15 20:16Z
CRIT

CVE-2026-50886 — Incorrect: access control in the webhook management component of Project Firefly III v6.5.9 allows

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-50886

Incorrect access control in the webhook management component of Project Firefly III v6.5.9 allows attackers to scan internal resources via a crafted POST request. CVSSv3.1 9.1 (CRITICAL)

CWECWE 284TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-06-15
2026-06-15 20:16Z
HIGH

CVE-2026-50884 — Incorrect: access control in statping-ng v0.93.0 allows attackers to escalate privileges to Administrator and

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-50884

Incorrect access control in statping-ng v0.93.0 allows attackers to escalate privileges to Administrator and access sensitive components. CVSSv3.1 8.8 (HIGH)

CWECWE 284TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-15
2026-06-15 20:16Z
CRIT

CVE-2026-50883 — HTML: An HTML injection vulnerability in the /src/highlight.rs component of matze wastebin v3.4.1 allows attackers

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-50883

An HTML injection vulnerability in the /src/highlight.rs component of matze wastebin v3.4.1 allows attackers to execute arbitrary scripts via a crafted payload. CVSSv3.1 9.6 (CRITICAL)

CWECWE 79TYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-06-15
2026-06-15 20:16Z
HIGH

CVE-2026-50881 — Incorrect: access control in the impworks Bonsai v6.0 allows authenticated attackers with Editor privileges

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-50881

Incorrect access control in the impworks Bonsai v6.0 allows authenticated attackers with Editor privileges to escalate privileges to Administrator and execute unauthorized account, password, and configuration changes. CVSSv3.1 8.1 (HIGH)

CWECWE 284TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-15
2026-06-15 20:16Z
CRIT

CVE-2026-50880 — An issue in the sendmail transport integration component of YouTransfer v1.0.6 allows attackers to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-50880

An issue in the sendmail transport integration component of YouTransfer v1.0.6 allows attackers to execute arbitrary code via supplying a crafted request. CVSSv3.1 9.8 (CRITICAL)

CWECWE 94TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-15
2026-06-15 20:16Z
HIGH

CVE-2026-50875 — Incorrect: access control in the /{form}/webhooks/{webhook} endpoint of Deck9 Input v2.0.1 allows authenticated attackers

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-50875

Incorrect access control in the /{form}/webhooks/{webhook} endpoint of Deck9 Input v2.0.1 allows authenticated attackers to arbitrarily modify or delete another tenant's webhook via a crafted request. CVSSv3.1 8.1 (HIGH)

CWECWE 284TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-15
2026-06-15 20:16Z
HIGH

CVE-2026-50874 — An OS command injection vulnerability in the /manage/features/media component of kanishka-linux Reminiscence v0.3.0 allows

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-50874

An OS command injection vulnerability in the /manage/features/media component of kanishka-linux Reminiscence v0.3.0 allows attackers to execute arbitrary commands via supplying a crafted input. CVSSv3.1 8.1 (HIGH)

CWECWE 78TYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-15
2026-06-15 20:16Z
CRIT

CVE-2026-50873 — An arbitrary file upload vulnerability in the attachment handling component of flatnotes v5.5.4 allows

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-50873

An arbitrary file upload vulnerability in the attachment handling component of flatnotes v5.5.4 allows attackers to execute arbitrary code via uploading a crafted HTML or SVG file. CVSSv3.1 9.8 (CRITICAL)

CWECWE 434TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-15
2026-06-15 20:16Z
CRIT

CVE-2026-50872 — An issue in the loopback request handling component of fossar selfoss v2.20-SNAPSHOT allows attackers

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-50872

An issue in the loopback request handling component of fossar selfoss v2.20-SNAPSHOT allows attackers to execute arbitrary commands and obtain sensitive information via supplying a crafted HTTP request. CVSSv3.1 9.8 (CRITICAL)

CWECWE 94TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-15
2026-06-15 20:16Z
CRIT

CVE-2026-50871 — An OS command injection vulnerability in the media archiving and export pipeline component of

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-50871

An OS command injection vulnerability in the media archiving and export pipeline component of kanishka-linux Reminiscence v0.3.0 allows attackers to execute arbitrary commands via supplying a crafted input. CVSSv3.1 9.8 (CRITICAL)

CWECWE 94TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-15
2026-06-15 20:16Z
CRIT

CVE-2026-50869 — An issue in the api/plugin.php component of Bludit v3.19.0 allows attackers to execute a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-50869

An issue in the api/plugin.php component of Bludit v3.19.0 allows attackers to execute a directory traversal via supplying a crafted request. CVSSv3.1 9.8 (CRITICAL)

CWECWE 22TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-15
2026-06-15 20:16Z
CRIT

CVE-2026-49952 — X5.0 releases 20260320 through 20260501 contains an authentication bypass vulnerability that allows unauthenticated remote

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-49952

Discuz! X5.0 releases 20260320 through 20260501 contains an authentication bypass vulnerability that allows unauthenticated remote attackers to gain unauthorized access to database backup and restore functionality by exploiting a shared cryptographic key between UCenter integration and the database backup API exposed by dbbak.php. Attackers can inject a crafted payload through the username parameter during login to abuse the encryption oracle in logging_ctl::logging_more(), o CVSSv3.1 9.1 (CRITICAL)

CWECWE 323TYPVulnerability
9.1
CVSS v3.1
96
Edit Score
2026-06-15
2026-06-15 20:16Z
CRIT

CVE-2026-48114 — Metacat: Versions 2.0.0 and and above contain an unauthenticated SQL injection in the /harvesterRegistration endpoint.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-48114

Metacat is data repository software that helps researchers preserve, share, and discover data. Versions 2.0.0 and and above contain an unauthenticated SQL injection in the /harvesterRegistration endpoint. HarvesterRegistration.dbInsert() builds an INSERT against HARVEST_SITE_SCHEDULE via string concatenation, using a quoteString() helper that performs raw single-quote wrapping without escaping. Three request parameters reach the sink: unit, contactEmail, and documentListURL. CVSSv3.1 9.8 (CRITICAL)

CWECWE 89CWECWE 287VNDMetacatTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-15
2026-06-15 20:16Z
HIGH

CVE-2026-47835 — Spring: In Spring AI Vector Stores, special characters could be used to force the execution

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47835

In Spring AI Vector Stores, special characters could be used to force the execution of arbitrary queries in Elasticsearch, OpenSearch, and GemFire VectorDB. Affected components: spring-ai-elasticsearch-store, spring-ai-opensearch-store, spring-ai-gemfire-store. Affected versions: Spring AI 1.0.0 through 1.0.x (fix 1.0.9). Spring AI 1.1.0 through 1.1.x (fix 1.1.8). CVSSv3.1 8.6 (HIGH)

CWECWE 943VNDSpringTYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-06-15
2026-06-15 20:16Z
CRIT

CVE-2026-45390 — OCaml: In OCaml-tar before 3.4.0, a crafted archive with ../ path segments in its name

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45390

In OCaml-tar before 3.4.0, a crafted archive with ../ path segments in its name allows escaping the current working directory. This is not desired behavior, and tar(1) rejects such extractions, but ocaml-tar decompresses it anyway. The impact is that it allows arbitrary file writes outside of the desired extraction directory (to an attacker that can reach a tar decompression endpoint). CVSSv3.1 9.1 (CRITICAL)

CWECWE 22VNDOcamlTYPVulnerability
9.1
CVSS v3.1
96
Edit Score