|
601
|
6.5 |
MEDIUM
Network
|
artifex
|
mupdf
|
MuPDF before 1.27.0-rc1 contains an uncontrolled recursion vulnerability in the EPUB CSS rendering engine that allows remote attackers to cause a denial of service by supplying a maliciously crafted …
New
|
CWE-674
Uncontrolled Recursion
|
CVE-2025-71382
|
2026-06-27 03:17 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
602
|
9.8 |
CRITICAL
Network
|
-
|
-
|
An unauthenticated
stack-based buffer overflow vulnerability exists in ssvr in GeoVision
GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerability is caused by
insufficient bounds checking when …
New
|
CWE-121
Stack-based Buffer Overflow
|
CVE-2026-57880
|
2026-06-27 03:17 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
603
|
8.5 |
HIGH
Network
|
-
|
-
|
Contributor SQL Injection in Recipe Maker For Your Food Blog from Zip Recipes <= 8.2.7 versions.
New
|
CWE-89
SQL Injection
|
CVE-2026-57663
|
2026-06-27 03:17 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
604
|
4.3 |
MEDIUM
Network
|
-
|
-
|
Unauthenticated Cross Site Request Forgery (CSRF) in Gmail SMTP <= 1.2.3.19 versions.
New
|
CWE-352
Origin Validation Error
|
CVE-2026-57657
|
2026-06-27 03:17 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
605
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Contributor Cross Site Scripting (XSS) in Ghost Kit <= 3.6.0 versions.
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-57651
|
2026-06-27 03:17 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
606
|
8.1 |
HIGH
Network
|
-
|
-
|
newsletters_subscribers Broken Access Control in Newsletters <= 4.13 versions.
New
|
CWE-862
Missing Authorization
|
CVE-2026-57645
|
2026-06-27 03:17 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
607
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Contributor Cross Site Scripting (XSS) in Fluent Booking <= 2.1.0 versions.
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-57638
|
2026-06-27 03:17 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
608
|
5.4 |
MEDIUM
Network
|
-
|
-
|
Subscriber Broken Access Control in Email Marketing for WooCommerce by Omnisend <= 1.19.0 versions.
New
|
CWE-862
Missing Authorization
|
CVE-2026-57632
|
2026-06-27 03:17 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
609
|
7.6 |
HIGH
Network
|
-
|
-
|
Administrator SQL Injection in Popup box <= 6.0.1 versions.
New
|
CWE-89
SQL Injection
|
CVE-2026-57631
|
2026-06-27 03:17 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
610
|
4.3 |
MEDIUM
Network
|
-
|
-
|
Subscriber Broken Access Control in WPCafe <= 3.0.14 versions.
New
|
CWE-862
Missing Authorization
|
CVE-2026-57622
|
2026-06-27 03:17 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|