|
2841
|
9.1 |
CRITICAL
Network
|
-
|
-
|
ApostropheCMS is an open-source Node.js content management system. In versions up to and including 4.30.0, `apos.util.set()` traverses dot-notation paths without sanitizing `__proto__`, allowing an a…
|
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
|
CVE-2026-53609
|
2026-06-16 05:54 |
2026-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2842
|
7.8 |
HIGH
Local
|
-
|
-
|
Insufficient Verification of Data Authenticity in Remote Control for Zoom Contact Center for Windows before version 7.0.0 may allow an authenticated user to enable an escalation of privilege via loca…
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2026-53406
|
2026-06-16 05:52 |
2026-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2843
|
8.1 |
HIGH
Network
|
-
|
-
|
Improper Authorization in Handler for Custom URL Scheme in Zoom Workplace before version 7.0.4 for Android and before 7.0.3 for iOS may allow an unauthenticated user to conduct an escalation of privi…
|
CWE-939
Improper Authorization in Handler for Custom URL Scheme
|
CVE-2026-53407
|
2026-06-16 05:52 |
2026-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2844
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Allegra exportReport Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Allegra. Authe…
|
CWE-22
Path Traversal
|
CVE-2026-11442
|
2026-06-16 05:52 |
2026-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2845
|
4.6 |
MEDIUM
Network
|
-
|
-
|
Allegra downloadAttachment Cross-Site Scripting Authentication Bypass Vulnerability. This vulnerability allows remote attackers to execute arbitrary script on affected installations of Allegra. User …
|
CWE-79
Cross-site Scripting
|
CVE-2026-11443
|
2026-06-16 05:52 |
2026-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2846
|
7.6 |
HIGH
Network
|
-
|
-
|
Cap-go prior to 12.128.2 contains an account takeover vulnerability in its email change mechanism that allows an attacker with temporary authenticated session access to change the registered email ad…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2026-53981
|
2026-06-16 05:50 |
2026-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2847
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Cap-go Console < 12.28.2 contains a denial-of-service vulnerability in its account deletion flow that allows an attacker to block authentication and onboarding functions by triggering account deletio…
|
CWE-645
Overly Restrictive Account Lockout Mechanism
|
CVE-2026-53982
|
2026-06-16 05:50 |
2026-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2848
|
10.0 |
CRITICAL
Network
|
-
|
-
|
SimpleHelp versions 5.5.15 and prior and 6.0 pre-release versions contain an authentication bypass vulnerability in the OIDC authentication flow. When OIDC authentication is configured, identity toke…
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2026-48558
|
2026-06-16 05:50 |
2026-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2849
|
4.3 |
MEDIUM
Network
|
-
|
-
|
Capgo before 12.128.2 fails to delete previously uploaded profile images from backend storage when users replace or remove them. Attackers can access orphaned image files through previously generated…
|
CWE-459
Incomplete Cleanup
|
CVE-2026-53867
|
2026-06-16 05:50 |
2026-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2850
|
7.5 |
HIGH
Network
|
-
|
-
|
Capgo before 12.128.2 contains a denial of service vulnerability allowing attackers to register accounts using arbitrary email addresses without verification, then initiate deletion to lock emails in…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2026-53868
|
2026-06-16 05:50 |
2026-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|