|
1931
|
9.3 |
CRITICAL
Network
|
apache
|
apisix
|
Cross-Site Request Forgery (CSRF) vulnerability in the cas-auth plugin under default configurations.
This defect allows a remote attacker that manages to send a victim to a webpage controlled by the…
|
CWE-352
Origin Validation Error
|
CVE-2026-49871
|
2026-06-24 00:20 |
2026-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1932
|
8.1 |
HIGH
Network
|
apache
|
apisix
|
Improper Authentication vulnerability in Apache APISIX.
When the cas-auth plugin is used in a route, an attacker can possibly authenticate itself with credentials from a different source.
This issue…
|
CWE-287
Improper Authentication
|
CVE-2026-49872
|
2026-06-24 00:18 |
2026-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1933
|
5.4 |
MEDIUM
Network
|
apache
|
apisix
|
Authentication Bypass by Spoofing vulnerability in opa plugin.
An attacker could relay spoofed identity headers to upstream capitalising on non-default configuration in opa plugin.
This could allow…
|
CWE-290
Authentication Bypass by Spoofing
|
CVE-2026-49231
|
2026-06-24 00:18 |
2026-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1934
|
9.1 |
CRITICAL
Network
|
apache
|
apisix
|
Improper Validation of Integrity Check Value vulnerability in Apache APISIX.
The jwe-decrypt plugin under default configuration is vulnerable to authentication bypass.
This issue affects Apache API…
|
CWE-354
Improper Validation of Integrity Check Value
|
CVE-2026-49230
|
2026-06-24 00:17 |
2026-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1935
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Gophish through 0.12.1 contains a denial of service vulnerability that allows authenticated users with the User role to exhaust server memory by uploading a crafted Office document as an email templa…
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2026-39904
|
2026-06-24 00:17 |
2026-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1936
|
7.2 |
HIGH
Network
|
apache
|
apisix
|
URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Apache APISIX.
The attacker could manipulate some client headers to perform an open-redirect, to potentially expose the session t…
|
CWE-601
Open Redirect
|
CVE-2026-48895
|
2026-06-24 00:17 |
2026-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1937
|
9.1 |
CRITICAL
Network
|
-
|
-
|
Mojolicious::Plugin::Web::Auth::OAuth2 versions through 0.17 for Perl have an insecure default state parameter.
When no state generator is specified in the constructor, the module defaults to using …
|
CWE-338 CWE-340
Use of Cryptographically Weak Pseudo-Random Number Generator (PRNG) Generation of Predictable Numbers or Identifiers
|
CVE-2026-9733
|
2026-06-24 00:16 |
2026-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1938
|
5.3 |
MEDIUM
Network
|
-
|
-
|
IBM Watson Speech Services Cartridge is vulnerable to Server-Side Request Forgery (SSRF) in Sterling File Gateway, due to a flaw which may allow an authenticated attacker to send unauthorized request…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-7253
|
2026-06-24 00:16 |
2026-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1939
|
8.8 |
HIGH
Network
|
misp-project
|
misp
|
MISP core contained multiple broken access-control flaws where authorization checks were performed against the wrong entity, or where ownership/editability checks were missing on write paths. In affe…
|
CWE-639 CWE-862 CWE-863
Authorization Bypass Through User-Controlled Key Missing Authorization Incorrect Authorization
|
CVE-2026-56424
|
2026-06-24 00:16 |
2026-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1940
|
8.8 |
HIGH
Network
|
misp-project
|
misp
|
MISP Core contained broken access-control checks in the bulk deletion flows for Event Reports and Sharing Groups. The affected deleteSelection handlers authorized deletion using broad role-level perm…
|
CWE-862
Missing Authorization
|
CVE-2026-56423
|
2026-06-24 00:16 |
2026-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|