|
631
|
7.1 |
HIGH
Network
|
-
|
-
|
Unauthenticated Cross Site Scripting (XSS) in MapPress Maps for WordPress <= 2.97.3 versions.
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-56011
|
2026-06-27 03:17 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
632
|
7.5 |
HIGH
Network
|
-
|
-
|
Echo is a Go web framework. Prior to 4.15.3 and 5.2.0, Echo's router and static file handler disagree on URL path decoding. The router matches routes using the raw encoded path (preserving %2F as-is)…
New
|
CWE-22
Path Traversal
|
CVE-2026-55677
|
2026-06-27 03:17 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
633
|
8.6 |
HIGH
Local
|
-
|
-
|
mise manages dev tools like node, python, cmake, and terraform. Prior to 2026.6.4, mise's trust feature gates config files (mise.toml, .tool-versions) through trust_check, but task-include files are …
New
|
CWE-78 CWE-94 CWE-732
OS Command Code Injection Incorrect Permission Assignment for Critical Resource
|
CVE-2026-55441
|
2026-06-27 03:17 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
634
|
7.3 |
HIGH
Network
|
-
|
-
|
Unauthenticated Broken Access Control in Newsletters <= 4.13 versions.
New
|
CWE-862
Missing Authorization
|
CVE-2026-54840
|
2026-06-27 03:17 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
635
|
7.5 |
HIGH
Network
|
-
|
-
|
Unauthenticated Sensitive Data Exposure in Trinity Backup – Backup, Migrate, Restore, Clone & Schedule Backups <= 2.0.9 versions.
New
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-54839
|
2026-06-27 03:17 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
636
|
7.5 |
HIGH
Network
|
-
|
-
|
Unauthenticated Broken Access Control in Gutenverse Companion <= 2.5.0 versions.
New
|
CWE-862
Missing Authorization
|
CVE-2026-54832
|
2026-06-27 03:17 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
637
|
9.3 |
CRITICAL
Network
|
-
|
-
|
Unauthenticated SQL Injection in GeoDirectory <= 2.8.162 versions.
New
|
CWE-89
SQL Injection
|
CVE-2026-54831
|
2026-06-27 03:17 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
638
|
9.3 |
CRITICAL
Network
|
-
|
-
|
Unauthenticated SQL Injection in JetBooking <= 4.0.4.1 versions.
New
|
CWE-89
SQL Injection
|
CVE-2026-54820
|
2026-06-27 03:17 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
639
|
5.5 |
MEDIUM
Local
|
-
|
-
|
mise manages dev tools like node, python, cmake, and terraform. Prior to 2026.6.1, the mise HTTP backend builds its install symlink destination from the raw resolved version string for non-latest ver…
New
|
CWE-22
Path Traversal
|
CVE-2026-54557
|
2026-06-27 03:17 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
640
|
7.5 |
HIGH
Network
|
-
|
-
|
Dragonfly is an in-memory data store built for modern application workloads. Prior to 1.39.0, a crafted RESTORE payload triggers an out-of-bounds read in DragonflyDB's listpack collection loaders, cr…
New
|
CWE-125
Out-of-bounds Read
|
CVE-2026-54341
|
2026-06-27 03:17 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|