|
271
|
8.1 |
HIGH
Network
|
-
|
-
|
The affected products insufficiently verify authorization when deleting user accounts. An authenticated, low-privileged remote user can exploit this vulnerability to delete other users, including tho…
New
|
CWE-863
Incorrect Authorization
|
CVE-2026-8046
|
2026-05-26 17:16 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272
|
7.8 |
HIGH
Local
|
-
|
-
|
The affected product extracts installation files to a temporary directory with incorrect default permissions during administrative installation. A low-privileged local attacker can exploit a TOCTOU r…
New
|
CWE-276
Incorrect Default Permissions
|
CVE-2026-44469
|
2026-05-26 17:16 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273
|
7.8 |
HIGH
Local
|
-
|
-
|
The affected product creates a directory with insecure default permissions during administrative installation. This allows a low-privileged local attacker to modify a temporary file defining the comp…
New
|
CWE-276
Incorrect Default Permissions
|
CVE-2026-44468
|
2026-05-26 17:16 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
274
|
5.3 |
MEDIUM
Network
|
-
|
-
|
Missing Authorization vulnerability in TeconceTheme Mayosis Core allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects Mayosis Core: from n/a through 5.4.7.
New
|
CWE-862
Missing Authorization
|
CVE-2026-39655
|
2026-05-26 17:16 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
275
|
4.6 |
MEDIUM
Physics
|
-
|
-
|
Missing password field masking vulnerability in Hitachi Ops Center Analyzer (Hitachi Ops Center Analyzer detail view, Hitachi Ops Center Analyzer probe modules), Hitachi Ops Center Analyzer viewpoint…
New
|
CWE-549
Missing Password Field Masking
|
CVE-2026-3314
|
2026-05-26 16:16 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276
|
3.3 |
LOW
Local
|
-
|
-
|
A security flaw has been discovered in GNU LibreDWG up to 0.14. The affected element is the function match_BLOCK_HEADER of the file dwggrep.c of the component Dwggrep Utility. Performing a manipulati…
New
|
CWE-404 CWE-476
Improper Resource Shutdown or Release NULL Pointer Dereference
|
CVE-2026-9529
|
2026-05-26 14:16 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277
|
7.3 |
HIGH
Network
|
-
|
-
|
A vulnerability was identified in itsourcecode Electronic Judging System 1.0. Impacted is an unknown function of the file /admin/delete_judge.php. Such manipulation of the argument judge_id leads to …
New
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-9528
|
2026-05-26 14:16 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278
|
4.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was determined in itsourcecode Electronic Judging System 1.0. This issue affects some unknown processing of the file /admin/judges.php. This manipulation of the argument fname causes …
New
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-9527
|
2026-05-26 14:16 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279
|
7.3 |
HIGH
Network
|
-
|
-
|
A vulnerability was found in itsourcecode Electronic Judging System 1.0. This vulnerability affects unknown code of the file /admin/edit_team.php. The manipulation of the argument num_id results in s…
New
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-9526
|
2026-05-26 14:16 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280
|
- |
|
-
|
-
|
Archive::Tar versions before 3.10 for Perl allow memory exhaustion via attacker controlled entry size field in tar header.
_read_tar() reads each entry's payload with $handle->read($$data, $block), …
New
|
CWE-789
Memory Allocation with Excessive Size Value
|
CVE-2026-9538
|
2026-05-26 13:16 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|