|
341
|
6.5 |
MEDIUM
Network
|
-
|
-
|
An authentication bypass vulnerability exists in the OAuth2 TokenIntrospectionService in Apache CXF. Due to a missing 'throw' keyword in the security context check, the introspection endpoint (/servi…
New
|
CWE-287
Improper Authentication
|
CVE-2026-50623
|
2026-06-13 01:16 |
2026-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342
|
10.0 |
CRITICAL
Network
|
-
|
-
|
vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.4, VM2 suffers from a sandbox breakout vulnerability. This allows attackers to write code which can escape from the VM2 sandbox and…
New
|
CWE-913
Improper Control of Dynamically-Managed Code Resources
|
CVE-2026-47208
|
2026-06-13 01:16 |
2026-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343
|
- |
|
-
|
-
|
Quest Bot is an opensource Discord Bot. Prior to version 1.1.6, the automod add command trims user input but does not reject an empty result. Adding a rule containing only whitespace stores an empty …
New
|
CWE-20
Improper Input Validation
|
CVE-2026-47196
|
2026-06-13 01:16 |
2026-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344
|
8.8 |
HIGH
Network
|
-
|
-
|
ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 - #132, any authenticated user who can upload videos can add multiple subtitles from different files and change their ti…
New
|
CWE-89
SQL Injection
|
CVE-2026-45418
|
2026-06-13 01:16 |
2026-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345
|
1.8 |
LOW
Physics
|
-
|
-
|
A vulnerability was identified in Groww Stock, Mutual Fund, Gold App up to 20260805 on Android. This affects an unknown part of the component WebView URL Handler. The manipulation leads to improper a…
New
|
CWE-285 CWE-939
Improper Authorization Improper Authorization in Handler for Custom URL Scheme
|
CVE-2026-12065
|
2026-06-13 01:16 |
2026-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346
|
7.3 |
HIGH
Network
|
-
|
-
|
A security flaw has been discovered in PbootCMS up to 3.2.12. This vulnerability affects the function retrieve of the file apps/home/controller/MemberController.php of the component Password Handler.…
New
|
CWE-640
Weak Password Recovery Mechanism for Forgotten Password
|
CVE-2026-12066
|
2026-06-13 01:16 |
2026-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Improper authentication checks in the OAuth implementation allow account hijacking even when OAuth is not configured or enabled leading to unauthorized access in default installations.
New
|
CWE-287
Improper Authentication
|
CVE-2026-48611
|
2026-06-13 01:15 |
2026-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348
|
8.0 |
HIGH
Network
|
-
|
-
|
Improper state verification in the OAuth implementation could allow an attacker to manipulate the authentication flow and cause a victim’s account to be linked to an attacker-controlled account. This…
New
|
CWE-352
Origin Validation Error
|
CVE-2026-48612
|
2026-06-13 01:15 |
2026-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349
|
5.9 |
MEDIUM
Network
|
-
|
-
|
SQL injection vulnerability in phpBB profile field migration due to improper handling of user-supplied profile field data during migration, allowing execution of arbitrary SQL queries. Only applies t…
New
|
CWE-89
SQL Injection
|
CVE-2026-48613
|
2026-06-13 01:15 |
2026-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350
|
9.9 |
CRITICAL
Network
|
-
|
-
|
A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UID Enterprise Agent to execute a Command Injection on the host devic…
New
|
CWE-20
Improper Input Validation
|
CVE-2026-47367
|
2026-06-13 01:10 |
2026-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|