|
981
|
5.3 |
MEDIUM
Network
|
-
|
-
|
Russh is a Rust SSH client & server library. From version 0.34.0-beta.1 to before version 0.61.0, russh did not enforce the SSH identification-string rules as deliberately as OpenSSH. In particular, …
|
CWE-20
Improper Input Validation
|
CVE-2026-48108
|
2026-06-12 00:24 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
982
|
- |
|
-
|
-
|
Cerebrate before version 1.37 contains a mass-assignment vulnerability in the generic CRUD add path. The add() handler attempted to remove an attacker-supplied id from $params before normalizing the …
|
CWE-20
Improper Input Validation
|
CVE-2026-53901
|
2026-06-12 00:24 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
983
|
- |
|
-
|
-
|
Cerebrate before version 1.37 allowed the id primary key field to be supplied through request input during CRUD edit operations and certain custom entity patching flows. In affected entities that did…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-53911
|
2026-06-12 00:24 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
984
|
- |
|
-
|
-
|
Cerebrate before version 1.37 exposed credential material from self-registration requests. The self-registration workflow stored the registrant’s hashed password in the inbox message data payload. Th…
|
CWE-200
Information Exposure
|
CVE-2026-53912
|
2026-06-12 00:24 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
985
|
- |
|
-
|
-
|
A Missing Authorization vulnerability in the playbook import functionality in Dialogflow CX on Google Cloud Platform allows an authenticated user with specific roles to escalate privileges and potent…
|
CWE-862
Missing Authorization
|
CVE-2026-4764
|
2026-06-12 00:22 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
986
|
4.3 |
MEDIUM
Network
|
-
|
-
|
Easy Twitter Feeds before 1.2.13 contains a cross-site request forgery vulnerability in the duplicate_post action handler that lacks nonce verification. Attackers can trick an authenticated user into…
|
CWE-352
Origin Validation Error
|
CVE-2026-53736
|
2026-06-12 00:22 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
987
|
6.1 |
MEDIUM
Network
|
-
|
-
|
Juicer through 1.12.18 fails to escape remote feed API response fields before rendering them on the admin settings page. Attackers controlling the connected feed data can inject script that executes …
|
CWE-79
Cross-site Scripting
|
CVE-2026-53737
|
2026-06-12 00:22 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
988
|
8.1 |
HIGH
Network
|
-
|
-
|
Copy & Delete Posts through 1.5.4 lets any plugin-enabled non-admin role invoke every operation in the cdp_action_handling AJAX handler. Attackers with an enabled role can delete posts or overwrite p…
|
CWE-863
Incorrect Authorization
|
CVE-2026-53738
|
2026-06-12 00:22 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
989
|
4.3 |
MEDIUM
Network
|
-
|
-
|
Yoast Duplicate Post through 4.6 contains a cross-site request forgery vulnerability in the duplicate_post_dismiss_notice handler, which verifies no nonce or capability. Attackers can trick any authe…
|
CWE-352
Origin Validation Error
|
CVE-2026-53739
|
2026-06-12 00:22 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
990
|
5.4 |
MEDIUM
Network
|
-
|
-
|
Yoast Duplicate Post through 4.6 inserts an unescaped post title and permalink into the Classic Editor scheduled republish notice. Attackers can schedule a republish copy with a crafted title to exec…
|
CWE-79
Cross-site Scripting
|
CVE-2026-53740
|
2026-06-12 00:22 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|