|
2011
|
8.3 |
HIGH
Adjacent
|
-
|
-
|
A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. WMCO establishes SSH connections to Windows worker nodes without verifying the remote server h…
|
CWE-295
Improper Certificate Validation
|
CVE-2026-54100
|
2026-06-23 14:17 |
2026-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2012
|
8.8 |
HIGH
Local
|
-
|
-
|
A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. The WICD CSR auto-approver validates that a Certificate Signing Request contains the organizat…
|
CWE-269
Improper Privilege Management
|
CVE-2026-54099
|
2026-06-23 14:17 |
2026-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2013
|
9.0 |
CRITICAL
Network
|
-
|
-
|
Two state-mutating endpoints in pgAdmin 4's SQL Editor blueprint -- DELETE /sqleditor/close/<trans_id> and POST /sqleditor/initialize/sqleditor/update_connection/<sgid>/<sid>/<did> -- were the only r…
|
CWE-306 CWE-502
Missing Authentication for Critical Function Deserialization of Untrusted Data
|
CVE-2026-12046
|
2026-06-23 14:17 |
2026-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2014
|
9.0 |
CRITICAL
Network
|
-
|
-
|
Read-only transaction bypass in the pgAdmin 4 AI Assistant allows an attacker who can influence database content that the assistant reads to execute arbitrary SQL with the privileges of the pgAdmin u…
|
CWE-77 CWE-89
Command Injection SQL Injection
|
CVE-2026-12045
|
2026-06-23 14:17 |
2026-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2015
|
4.8 |
MEDIUM
Network
|
-
|
-
|
Craft CMS from version 5.0.0-RC1 contains a stored cross-site scripting vulnerability in the User Permissions page where user group names are rendered without proper HTML escaping. Attackers with adm…
|
CWE-79
Cross-site Scripting
|
CVE-2026-56381
|
2026-06-23 13:17 |
2026-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2016
|
8.1 |
HIGH
Network
|
-
|
-
|
AVideo through 29.0 contains an authorization bypass vulnerability in the Meet plugin's uploadRecordedVideo.json.php endpoint that derives the target users_id from the uploaded filename without verif…
|
CWE-287
Improper Authentication
|
CVE-2026-56345
|
2026-06-23 13:17 |
2026-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2017
|
3.5 |
LOW
Network
|
-
|
-
|
Capgo before 12.128.2 contains an open redirect vulnerability in stripe_portal and stripe_checkout endpoints that accept unvalidated callbackUrl, successUrl, and cancelUrl parameters. Authenticated a…
|
CWE-601
Open Redirect
|
CVE-2026-56330
|
2026-06-23 13:17 |
2026-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2018
|
5.3 |
MEDIUM
Network
|
-
|
-
|
Capgo before 12.128.2 contains an information disclosure vulnerability in the unauthenticated /replication endpoint that exposes internal PostgreSQL replication telemetry including slot names and WAL…
|
CWE-200
Information Exposure
|
CVE-2026-56282
|
2026-06-23 13:17 |
2026-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2019
|
7.5 |
HIGH
Network
|
-
|
-
|
Capgo before 12.128.2 contains an improper access control vulnerability in the public.get_org_members RPC function that allows unauthenticated attackers to enumerate organization members. Attackers c…
|
CWE-284
Improper Access Control
|
CVE-2026-56253
|
2026-06-23 13:17 |
2026-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2020
|
5.3 |
MEDIUM
Network
|
-
|
-
|
Capgo before 12.128.2 fails to strip EXIF metadata including GPS geolocation data from uploaded images, allowing information disclosure. Attackers can download uploaded images and extract precise lat…
|
CWE-200
Information Exposure
|
CVE-2026-56218
|
2026-06-23 13:17 |
2026-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|