|
1591
|
4.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was found in kerwincui FastBee up to 1.2.1. The affected element is the function ToolController.download of the file springboot/fastbee-open-api/src/main/java/com/fastbee/data/control…
|
CWE-22
Path Traversal
|
CVE-2026-7676
|
2026-05-6 04:15 |
2026-05-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1592
|
3.5 |
LOW
Network
|
-
|
-
|
A vulnerability was determined in kerwincui FastBee up to 1.2.1. The impacted element is the function Add of the file springboot/fastbee-admin/src/main/java/com/fastbee/web/controller/system/SysNotic…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-7677
|
2026-05-6 04:15 |
2026-05-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1593
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was identified in YunaiV yudao-cloud up to 2026.01. This affects the function getDataBySQL of the file yudao-module-report-biz/src/main/java/io/github/ruoyi/report/service/impl/GoView…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-7678
|
2026-05-6 04:13 |
2026-05-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1594
|
7.3 |
HIGH
Network
|
-
|
-
|
A security flaw has been discovered in YunaiV yudao-cloud up to 2026.01. This impacts the function getAccessToken of the file yudao-module-system-biz/src/main/java/io/github/ruoyi/common/oauth2/servi…
|
CWE-287
Improper Authentication
|
CVE-2026-7679
|
2026-05-6 04:13 |
2026-05-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1595
|
7.2 |
HIGH
Network
|
-
|
-
|
The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via POST parameter key names in the submit_nex_form() function in versions up to,…
|
CWE-79
Cross-site Scripting
|
CVE-2026-5063
|
2026-05-6 04:13 |
2026-05-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1596
|
4.3 |
MEDIUM
Network
|
-
|
-
|
A weakness has been identified in jsbroks COCO Annotator up to 0.11.1. Affected is an unknown function of the file backend/webserver/api/datasets.py of the component Data Endpoint. Executing a manipu…
|
CWE-22
Path Traversal
|
CVE-2026-7680
|
2026-05-6 04:13 |
2026-05-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1597
|
6.5 |
MEDIUM
Network
|
-
|
-
|
A security vulnerability has been detected in jsbroks COCO Annotator up to 0.11.1. Affected by this vulnerability is an unknown functionality of the file backend/webserver/api/datasets.py of the comp…
|
CWE-285 CWE-639
Improper Authorization Authorization Bypass Through User-Controlled Key
|
CVE-2026-7681
|
2026-05-6 04:13 |
2026-05-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1598
|
5.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was found in eyeo Adblock Plus up to 4.36.2 on Chrome. Affected by this vulnerability is the function postMessage of the file premium.preload.js of the component Legacy Premium Activa…
|
CWE-266 CWE-284
Incorrect Privilege Assignment Improper Access Control
|
CVE-2026-7686
|
2026-05-6 04:13 |
2026-05-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1599
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was determined in langflow-ai langflow up to 1.8.4. Affected by this issue is the function CodeParser.parse_callable_details of the file src/lfx/src/lfx/custom/code_parser/code_parser…
|
CWE-74 CWE-77
Injection Command Injection
|
CVE-2026-7687
|
2026-05-6 04:13 |
2026-05-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1600
|
7.3 |
HIGH
Network
|
-
|
-
|
A flaw has been found in Acrel Electrical ECEMS Enterprise Microgrid Energy Efficiency Management System 1.3.0. The impacted element is an unknown function of the file /SubstationWEBV2/main/elecMaxMi…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-7694
|
2026-05-6 04:13 |
2026-05-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|