|
331
|
9.6 |
CRITICAL
Adjacent
|
-
|
-
|
OpenProject is open-source, web-based project management software. Prior to 17.3.3 and 17.4.1, cache store poisoning leads to Remote Code Execution (RCE). This vulnerability is fixed in 17.3.3 and 17…
New
|
CWE-20
Improper Input Validation
|
CVE-2026-52780
|
2026-06-27 13:17 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
332
|
7.4 |
HIGH
Network
|
-
|
-
|
Budibase is an open-source low-code platform. Prior to 3.39.3, the application server exposes an unauthenticated endpoint that generates S3 PutObject presigned URLs using credentials stored in a work…
New
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2026-50136
|
2026-06-27 13:17 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
333
|
6.0 |
MEDIUM
Network
|
-
|
-
|
GitHub MCP Server is GitHub's official MCP Server. From 0.22.0 until 1.1.2, when running in HTTP mode with --lockdown-mode enabled, the RepoAccessCache is implemented as a process-global singleton in…
New
|
CWE-284
Improper Access Control
|
CVE-2026-48529
|
2026-06-27 13:17 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
334
|
4.4 |
MEDIUM
Network
|
-
|
-
|
Envoy is an open source edge and service proxy designed for cloud-native applications. Prior to 1.35.11, 1.36.7, 1.37.3, and 1.38.1, a structural flaw was identified in DefaultCertValidator::verifySu…
New
|
CWE-158
Improper Neutralization of Null Byte or NUL Character
|
CVE-2026-47778
|
2026-06-27 13:17 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
335
|
5.9 |
MEDIUM
Network
|
-
|
-
|
Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.36.0 until 1.36.9, 1.37.5, and 1.38.3, a Use-After-Free (UAF) vulnerability leading to a sudden segmentat…
New
|
CWE-416
Use After Free
|
CVE-2026-47205
|
2026-06-27 13:17 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
336
|
6.5 |
MEDIUM
Network
|
-
|
-
|
OpenProject is open-source, web-based project management software. Prior to 17.4.0, the GET /api/v3/relations endpoint allows any authenticated user to retrieve relations — and the subject (title) of…
New
|
CWE-200 CWE-639 CWE-836
Information Exposure Authorization Bypass Through User-Controlled Key Use of Password Hash Instead of Password for Authentication
|
CVE-2026-44736
|
2026-06-27 13:17 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
337
|
6.5 |
MEDIUM
Network
|
-
|
-
|
OpenProject is open-source, web-based project management software. Prior to 17.3.2 and 17.4.0, a Missing Authorization vulnerability exists in OpenProject's CostReportsController. The rename and upda…
New
|
CWE-862
Missing Authorization
|
CVE-2026-44734
|
2026-06-27 13:17 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
338
|
5.7 |
MEDIUM
Network
|
-
|
-
|
OpenProject is open-source, web-based project management software. Prior to 17.4.0, OpenProject's rich text (markdown) rendering pipeline uses Sanitize::Config::RELAXED[:css] for inline style sanitiz…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-44696
|
2026-06-27 13:17 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
339
|
5.4 |
MEDIUM
Network
|
-
|
-
|
Patool before 4.0.5 contains a path traversal vulnerability in the safe_extract() function in patoolib/programs/py_tarfile.py when running on Python before 3.12, where the is_within_directory() helpe…
New
|
CWE-22
Path Traversal
|
CVE-2026-29509
|
2026-06-27 13:17 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
340
|
4.9 |
MEDIUM
Network
|
-
|
-
|
A flaw was found in KubeVirt's network annotation generator. When a tenant creates a VirtualMachineInstance with a Multus network configuration, the supplied networkName value is written verbatim int…
New
|
CWE-20
Improper Input Validation
|
CVE-2026-13434
|
2026-06-27 13:17 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|