|
771
|
9.9 |
CRITICAL
Network
|
-
|
-
|
Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, two distinct authorization defects in the team settings allowed any authenticated panel user to take over the RBAC system. Settings/Team/…
|
CWE-269 CWE-285
Improper Privilege Management Improper Authorization
|
CVE-2026-47744
|
2026-05-30 05:17 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
772
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, the admin tables for PaymentMethods, Currencies and Carriers exposed inline toggles and per-record actions (enable, disable, edit, delete…
|
CWE-862
Missing Authorization
|
CVE-2026-47745
|
2026-05-30 05:17 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
773
|
5.3 |
MEDIUM
Network
|
-
|
-
|
Casdoor versions 2.362.0 and earlier contain a logic flaw in the social‑login binding flow that allows users to bypass configured MFA requirements. The binding‑rule code path in controllers/auth.go c…
|
-
|
CVE-2026-9091
|
2026-05-30 05:16 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
774
|
9.1 |
CRITICAL
Network
|
-
|
-
|
Casdoor versions 2.362.0 and earlier contain a vulnerability that allows an attacker to bypass authentication by supplying an arbitrary signing certificate. The buildSpCertificateStore function extra…
|
-
|
CVE-2026-9090
|
2026-05-30 05:16 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
775
|
7.1 |
HIGH
Network
|
-
|
-
|
In JetBrains TeamCity before 2026.1.1 reflected XSS in the keyword filter was possible
|
CWE-79
Cross-site Scripting
|
CVE-2026-49371
|
2026-05-30 05:11 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
776
|
7.5 |
HIGH
Network
|
-
|
-
|
In JetBrains TeamCity before 2026.1,
2025.11.5 unauthenticated SSRF via build status was possible
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-49372
|
2026-05-30 05:11 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
777
|
7.1 |
HIGH
Network
|
-
|
-
|
In JetBrains TeamCity before 2026.1 remote code execution was possible via Perforce connection settings
|
CWE-88
Argument Injection
|
CVE-2026-49373
|
2026-05-30 05:11 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
778
|
7.6 |
HIGH
Network
|
-
|
-
|
In JetBrains TeamCity before 2026.1 improper permission checks exposed build configuration parameters
|
CWE-862
Missing Authorization
|
CVE-2026-49374
|
2026-05-30 05:11 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
779
|
6.1 |
MEDIUM
Network
|
-
|
-
|
In JetBrains TeamCity before 2026.1,
2025.11.5 reflected XSS was possible on the repository download page
|
CWE-79
Cross-site Scripting
|
CVE-2026-49375
|
2026-05-30 05:11 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
780
|
6.5 |
MEDIUM
Network
|
-
|
-
|
In JetBrains TeamCity before 2026.1 insufficient username validation in the SAML plugin
|
CWE-863
Incorrect Authorization
|
CVE-2026-49376
|
2026-05-30 05:11 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|