|
751
|
9.8 |
CRITICAL
Network
|
joomla
|
joomla\!
|
An improper validation of user-supplied input leads to a local file inclusion vulnerability.
New
|
CWE-22
Path Traversal
|
CVE-2026-40383
|
2026-05-27 21:24 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
752
|
7.5 |
HIGH
Network
|
microsoft
|
global_secure_access
|
Improper privilege management in Azure Entra ID allows an unauthorized attacker to elevate privileges over a network.
New
|
CWE-269
Improper Privilege Management
|
CVE-2026-23663
|
2026-05-27 21:16 |
2026-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
753
|
10.0 |
CRITICAL
Network
|
microsoft
|
entra_id
|
Origin validation error in Microsoft Entra ID allows an unauthorized attacker to elevate privileges over a network.
New
|
CWE-346
Origin Validation Error
|
CVE-2026-42901
|
2026-05-27 21:13 |
2026-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
754
|
- |
|
-
|
-
|
The vulnerability in the Tassos Framework Plugin allows users to delete arbitrary files on the affected sites.
New
|
CWE-284
Improper Access Control
|
CVE-2026-48906
|
2026-05-27 20:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
755
|
- |
|
-
|
-
|
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') in the Publish Audit API endpoints (/api/auditPublishing/get and /api/auditPublishing/getAll) in dotCMS Core 25.11…
New
|
CWE-89
SQL Injection
|
CVE-2026-8054
|
2026-05-27 18:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
756
|
9.1 |
CRITICAL
Network
|
-
|
-
|
Access control failure means that an application does not effectively check user access permissions, so that unauthorized users can access system data beyond their permissions, such as viewing and mo…
New
|
CWE-284
Improper Access Control
|
CVE-2026-49002
|
2026-05-27 18:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
757
|
5.3 |
MEDIUM
Network
|
-
|
-
|
Cross-site request forgery (CSRF) vulnerabilities allow attackers to exploit a user's authenticated session to forge cross-site requests, inducing the execution of unintended operations such as tampe…
New
|
CWE-352
Origin Validation Error
|
CVE-2026-49001
|
2026-05-27 17:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
758
|
7.0 |
HIGH
Network
|
-
|
-
|
An insecure password scheme refers to vulnerabilities arising from improper selection of encryption algorithms, inadequate key management, or flawed code implementation, which may lead to data leakag…
New
|
CWE-310
Cryptographic Issues
|
CVE-2026-49000
|
2026-05-27 17:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
759
|
5.7 |
MEDIUM
Network
|
-
|
-
|
Attackers carefully craft malicious scripts, such as JavaScript, and inject them into target systems; when other users access pages containing such malicious content, the scripts are automatically lo…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-48999
|
2026-05-27 17:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
760
|
- |
|
-
|
-
|
IO::Compress versions from 2.207 before 2.220 for Perl ship a zipdetails CLI tool that crashes with undefined subroutine on Info-ZIP Unix Extra Field with 8-byte UID or GID.
When decode_ux() in bin/…
New
|
CWE-755
Improper Handling of Exceptional Conditions
|
CVE-2026-48961
|
2026-05-27 17:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|