|
3691
|
6.2 |
MEDIUM
Local
|
-
|
-
|
IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service via the optional module mod_fastcgi module.
|
CWE-617
Reachable Assertion
|
CVE-2026-8852
|
2026-05-27 02:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3692
|
7.5 |
HIGH
Network
|
-
|
-
|
IBM HTTP Server 8.5, and 9.0 is vulnerable to denial of service via the optional module mod_ibm_upload.
|
CWE-476
NULL Pointer Dereference
|
CVE-2026-8850
|
2026-05-27 02:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3693
|
- |
|
-
|
-
|
Lack of input filtering leads to an XSS vector in the HTML filter code.
|
CWE-79
Cross-site Scripting
|
CVE-2026-48905
|
2026-05-27 02:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3694
|
- |
|
-
|
-
|
An improper access check allows privelege escalation through the com_users group editing webservice endpoint.
|
CWE-284
Improper Access Control
|
CVE-2026-48904
|
2026-05-27 02:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3695
|
- |
|
-
|
-
|
Inadequate content filtering within the checkAttribute methods leads to XSS vulnerabilities in various components.
|
CWE-79
Cross-site Scripting
|
CVE-2026-48903
|
2026-05-27 02:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3696
|
- |
|
-
|
-
|
An improper access check allowed low privileged users to edit the task types of existing scheduler tasks.
|
CWE-284
Improper Access Control
|
CVE-2026-48900
|
2026-05-27 02:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3697
|
- |
|
-
|
-
|
An improper access check allows privilege escalation through the com_users batch task.
|
CWE-284
Improper Access Control
|
CVE-2026-48899
|
2026-05-27 02:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3698
|
- |
|
-
|
-
|
An improper access check allows privilege escalation through the com_users batch task.
|
CWE-284
Improper Access Control
|
CVE-2026-48898
|
2026-05-27 02:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3699
|
- |
|
-
|
-
|
Rejected reason: Further research determined the issue is not a vulnerability.
|
-
|
CVE-2026-48091
|
2026-05-27 02:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3700
|
4.3 |
MEDIUM
Network
|
-
|
-
|
Bugsink is a self-hosted error tracking tool. Prior to 2.2.0, Bugsink resolved sourcemaps and debug files by debug ID without scoping that lookup to the project that owned the uploaded metadata. An a…
|
CWE-862
Missing Authorization
|
CVE-2026-47728
|
2026-05-27 02:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|