|
1631
|
6.5 |
MEDIUM
Local
|
libexpat_project
|
libexpat
|
xmlwf in libexpat before 2.8.2 has an integer overflow for the output filename when -d outputDir is used.
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2026-56409
|
2026-06-24 01:21 |
2026-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1632
|
6.9 |
MEDIUM
Local
|
libexpat_project
|
libexpat
|
xmlwf in libexpat before 2.8.2 has an integer overflow in resolveSystemId.
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2026-56410
|
2026-06-24 01:18 |
2026-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1633
|
7.4 |
HIGH
Local
|
-
|
-
|
pwnlift before d7a9544, in a privileged deployment, contains a symlink following vulnerability in the upload handler in Components/Pages/Home.razor.
|
CWE-61
UNIX Symbolic Link (Symlink) Following
|
CVE-2026-56815
|
2026-06-24 01:17 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1634
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Grav before 2.0.0-beta.2 contains an XML external entity injection vulnerability in SVG file upload processing that allows authenticated attackers to read arbitrary files. The application uses simple…
|
CWE-611
XXE
|
CVE-2026-56701
|
2026-06-24 01:17 |
2026-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1635
|
7.2 |
HIGH
Network
|
misp-project
|
misp
|
MISP allowed a site administrator to configure an arbitrary filesystem path for the NDJSON error log used by JsonLogTool. Because log entries can include attacker-controlled content, an authenticated…
|
CWE-94
Code Injection
|
CVE-2026-56446
|
2026-06-24 01:17 |
2026-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1636
|
7.5 |
HIGH
Network
|
-
|
-
|
Capgo before 12.128.2 contains an information disclosure vulnerability in the /functions/v1/channel_self endpoint that allows unauthenticated attackers to enumerate non-public channel names and deter…
|
CWE-200
Information Exposure
|
CVE-2026-56323
|
2026-06-24 01:17 |
2026-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1637
|
7.5 |
HIGH
Network
|
-
|
-
|
Capgo before 12.128.2 contains an information disclosure vulnerability in the unauthenticated /updates endpoint that resolves the defaultChannel parameter before enforcing privacy restrictions, allow…
|
CWE-200
Information Exposure
|
CVE-2026-56322
|
2026-06-24 01:17 |
2026-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1638
|
8.1 |
HIGH
Network
|
-
|
-
|
Capgo before 12.128.2 contains a security control bypass vulnerability where the PostgREST/RLS plane accepts plaintext API keys through the capgkey header despite enforce_hashed_api_keys being enable…
|
CWE-288
Authentication Bypass Using an Alternate Path or Channel
|
CVE-2026-56243
|
2026-06-24 01:17 |
2026-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1639
|
8.2 |
HIGH
Network
|
-
|
-
|
Chainlit before 2.10.1 contains a session hijacking vulnerability that allows unauthenticated attackers to restore and inherit authenticated user sessions by presenting a valid sessionId during WebSo…
|
CWE-862
Missing Authorization
|
CVE-2026-56104
|
2026-06-24 01:17 |
2026-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1640
|
7.5 |
HIGH
Network
|
astro
|
astro
|
Astro is a web framework. Prior to 6.4.6, Astro SSR apps with prerendered error pages (/404 or /500 using export const prerender = true) fetch those pages over HTTP at runtime when an error occurs. T…
|
CWE-20 CWE-918
Improper Input Validation Server-Side Request Forgery (SSRF)
|
CVE-2026-54299
|
2026-06-24 01:17 |
2026-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|