|
91
|
9.6 |
CRITICAL
Network
|
-
|
-
|
mise manages dev tools like node, python, cmake, and terraform. Prior to 2026.3.10, mise processes .tool-versions files through the Tera template engine during parsing, with the exec() function regis…
New
|
CWE-94
Code Injection
|
CVE-2026-33646
|
2026-06-27 03:16 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
92
|
5.0 |
MEDIUM
Network
|
-
|
-
|
In Canonical LXD versions 4.12 through 6.9, a Server-Side Request Forgery (SSRF) vulnerability in the image import functionality allows authenticated users with the can_create_images entitlement to i…
New
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-28385
|
2026-06-27 03:16 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
93
|
- |
|
-
|
-
|
An Improper Authorization vulnerability exists in PayloadCMS version 3.84.1 due to insufficient access control on the account unlock operation.
New
|
CWE-307
mproper Restriction of Excessive Authentication Attempts
|
CVE-2026-11779
|
2026-06-27 03:16 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
94
|
7.5 |
HIGH
Network
|
-
|
-
|
Kernel driver ProcessMonitorDriver.sys in Safetica's endpoint client x64 , versions 10.5.75.0 and 11.11.4.0, allows unprivileged user to abuse IOCTL path and terminate protected system processes.
New
|
-
|
CVE-2026-0828
|
2026-06-27 03:16 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
95
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Server side template inject (SSTI) in the expression evaluation component in Genshi Template Engine version 0.7.9 allows a remote attacker to achieve remote code execution (RCE) via crafted template …
New
|
-
|
CVE-2026-0685
|
2026-06-27 03:16 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
96
|
7.5 |
HIGH
Network
|
-
|
-
|
Contributor Local File Inclusion in Splash - Sport Club WordPress Theme for Basketball, Football, Hockey <= 4.4.3 versions.
New
|
CWE-98
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
|
CVE-2025-68063
|
2026-06-27 03:16 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
97
|
8.8 |
HIGH
Network
|
-
|
-
|
Unauthenticated Cross Site Request Forgery (CSRF) in Eagle Booking <= 1.3.4.3 versions.
New
|
CWE-352
Origin Validation Error
|
CVE-2025-68052
|
2026-06-27 03:16 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
98
|
4.3 |
MEDIUM
Network
|
-
|
-
|
Subscriber Broken Access Control in Restaurant Menu by MotoPress <= 2.4.11 versions.
New
|
CWE-862
Missing Authorization
|
CVE-2025-63078
|
2026-06-27 03:16 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
99
|
5.4 |
MEDIUM
Network
|
-
|
-
|
Contributor Broken Access Control in Forget About Shortcode Buttons <= 2.1.3 versions.
New
|
CWE-862
Missing Authorization
|
CVE-2025-63041
|
2026-06-27 03:16 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
100
|
9.6 |
CRITICAL
Network
|
-
|
-
|
The default JVM can access files and directories under `/tmp/` including the `$TemporaryDirectory` of other users on the same cloud instance (`/tmp/UserTemporaryFiles/`). The `-init` file for the th…
New
|
-
|
CVE-2025-11919
|
2026-06-27 03:16 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|