|
1511
|
8.3 |
HIGH
Network
|
-
|
-
|
Insertion of Sensitive Information Into Sent Data vulnerability in Saad Iqbal APIExperts Square for WooCommerce allows Retrieve Embedded Sensitive Data.
This issue affects APIExperts Square for WooC…
|
CWE-201
Insertion of Sensitive Information Into Sent Data
|
CVE-2026-54848
|
2026-06-26 00:16 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1512
|
9.3 |
CRITICAL
Network
|
-
|
-
|
Unauthenticated SQL Injection in MDTF <= 1.3.7 versions.
|
CWE-89
SQL Injection
|
CVE-2026-54843
|
2026-06-26 00:16 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1513
|
8.1 |
HIGH
Network
|
-
|
-
|
Missing Authorization vulnerability in Royal Plugins Royal MCP allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects Royal MCP: from n/a through 1.4.25.
|
CWE-862
Missing Authorization
|
CVE-2026-54842
|
2026-06-26 00:16 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1514
|
7.5 |
HIGH
Network
|
-
|
-
|
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Jacob N. Breetvelt WP Photo Album Plus allows Blind SQL Injection.
This issue affects WP Photo A…
|
CWE-89
SQL Injection
|
CVE-2026-54829
|
2026-06-26 00:16 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1515
|
7.5 |
HIGH
Network
|
-
|
-
|
Unauthenticated Broken Access Control in Motors <= 1.4.109 versions.
|
CWE-862
Missing Authorization
|
CVE-2026-54828
|
2026-06-26 00:16 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1516
|
- |
|
-
|
-
|
SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, SiYuan Note's kernel HTTP server unconditionally trusts all chrome-extension:// origins, granting RoleAdministrator acce…
|
CWE-346
Origin Validation Error
|
CVE-2026-54069
|
2026-06-26 00:16 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1517
|
- |
|
-
|
-
|
Incorrect use of the PUF key for user key generation in EFR32xG27 results in predictable keys
|
CWE-339
Small Seed Space in PRNG
|
CVE-2026-2815
|
2026-06-26 00:16 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1518
|
7.5 |
HIGH
Network
|
-
|
-
|
An issue in the time_t_to_dt component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.
|
CWE-89
SQL Injection
|
CVE-2025-61028
|
2026-06-26 00:16 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1519
|
8.8 |
HIGH
Network
|
google
|
chrome
|
Use after free in Bluetooth in Google Chrome on Mac prior to 149.0.7827.197 allowed a remote attacker to execute arbitrary code via a malicious peripheral. (Chromium security severity: High)
|
CWE-416
Use After Free
|
CVE-2026-13035
|
2026-06-26 00:14 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1520
|
8.8 |
HIGH
Network
|
google
|
chrome
|
Use after free in Blink in Google Chrome prior to 149.0.7827.197 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
|
CWE-416
Use After Free
|
CVE-2026-13036
|
2026-06-26 00:13 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|