|
241
|
5.4 |
MEDIUM
Network
|
-
|
-
|
Missing Authorization vulnerability in Elementor Elementor Website Builder allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects Elementor Website Builder: from…
New
|
CWE-862
Missing Authorization
|
CVE-2026-49782
|
2026-06-2 23:43 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
242
|
8.8 |
HIGH
Network
|
openstack
|
keystone
|
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone RBAC policy enforcer in enforce_call unconditionally merges the raw JSON request body into the policy enforcement dictionary …
Update
|
CWE-863
Incorrect Authorization
|
CVE-2026-42999
|
2026-06-2 23:41 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
243
|
8.1 |
HIGH
Network
|
-
|
-
|
AI Tensor Engine for ROCm (AITER) through 0.1.14 contains an unauthenticated remote code execution vulnerability in the MessageQueue.recv() function within shm_broadcast.py that allows unauthenticate…
New
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-49121
|
2026-06-2 23:40 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
244
|
4.3 |
MEDIUM
Adjacent
|
-
|
-
|
Dräger Infinity Delta, Delta XL, and Kappa patient monitors contain an information disclosure vulnerability that allows unauthenticated network attackers to access log files over a network connection…
New
|
CWE-538
File and Directory Information Exposure
|
CVE-2019-25717
|
2026-06-2 23:40 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245
|
8.6 |
HIGH
Network
|
-
|
-
|
Dräger Infinity Acute Care System and Standalone Infinity M540 patient monitors running software versions VG4.1.1, VG4.0.3, and lower contain network message handling vulnerabilities that allow netwo…
New
|
CWE-924
Improper Enforcement of Message Integrity During Transmission in a Communication Channel
|
CVE-2019-25719
|
2026-06-2 23:40 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246
|
8.8 |
HIGH
Network
|
openstack
|
keystone
|
An issue was discovered in OpenStack Keystone before 29.0.2. When combined with an application credential impersonation vulnerability, an attacker with the member role on a project can escalate to ad…
Update
|
CWE-863
Incorrect Authorization
|
CVE-2026-43000
|
2026-06-2 23:38 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247
|
9.8 |
CRITICAL
Network
|
-
|
-
|
CWE-284: Improper Access Control in web services in Progress Sitefinity 15.4.8623 before 15.4.8630 allows a remote unauthenticated attacker to access content that should be restricted, resulting in f…
New
|
CWE-284
Improper Access Control
|
CVE-2026-7198
|
2026-06-2 23:37 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248
|
8.8 |
HIGH
Network
|
-
|
-
|
CWE-639: Authorization Bypass Through User-Controlled Key in web services in Progress Sitefinity 15.2.x before 15.2.8441, 15.3.x before 15.3.8531, and 15.4.x before 15.4.8630 allows a remote authenti…
New
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-7201
|
2026-06-2 23:37 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249
|
10.0 |
CRITICAL
Network
|
-
|
-
|
CWE‑522: Insufficiently Protected Credentials in web services in Progress Sitefinity version from 14.0.7700 to 14.4.8152, and 15.0.8200 to 15.0.8234, and 15.1.8300 to 15.1.8335, 15.2.8400 to 15.2.844…
New
|
-
|
CVE-2026-7312
|
2026-06-2 23:37 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250
|
8.7 |
HIGH
Network
|
-
|
-
|
CWE‑522: Insufficiently Protected Credentials in web services in Progress Sitefinity version from 8.0.5700 to 13.3.7652 allows a remote authenticated attacker to obtain plain-text credentials used co…
New
|
-
|
CVE-2026-7313
|
2026-06-2 23:37 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|