|
291
|
- |
|
-
|
-
|
Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory.
_make_special_file() passes the tar header's linkname to symlink() with…
New
|
CWE-59
Link Following
|
CVE-2026-42496
|
2026-05-26 11:16 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292
|
- |
|
-
|
-
|
The GDPR cookies module for Backdrop CMS (before
1.x-1.3.5) doesn't sufficiently protect visitors from Cross Site Scripting (XSS) if a malicious value has been provided for the optional 'Info conte…
New
|
CWE-80
Basic XSS
|
CVE-2025-71310
|
2026-05-26 11:16 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293
|
7.3 |
HIGH
Network
|
-
|
-
|
A vulnerability was determined in hemant6488 CodeIgniter-StudentManagementSystem. The affected element is an unknown function of the file /index.php/students/addStudentView of the component Student M…
New
|
CWE-266 CWE-284
Incorrect Privilege Assignment Improper Access Control
|
CVE-2026-9517
|
2026-05-26 09:16 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294
|
5.4 |
MEDIUM
Network
|
webmin
|
webmin
|
Webmin before 2.641 contains a stored cross-site scripting vulnerability in the email template description field of the System and Server Status module that allows low-privileged authenticated attack…
Update
|
CWE-79
Cross-site Scripting
|
CVE-2026-22678
|
2026-05-26 09:16 |
2026-05-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
295
|
8.5 |
HIGH
Network
|
-
|
-
|
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Unlimited Elements For Elementor allows Blind SQL Injection.
This issue affects Unlimited Elemen…
New
|
CWE-89
SQL Injection
|
CVE-2026-48837
|
2026-05-26 08:16 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
296
|
7.5 |
HIGH
Network
|
-
|
-
|
Missing Authorization vulnerability in WebToffee Smart Coupons for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects Smart Coupons for WooCommer…
New
|
CWE-862
Missing Authorization
|
CVE-2026-45438
|
2026-05-26 08:16 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
297
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Melapress WP Activity Log allows DOM-Based XSS.
This issue affects WP Activity Log: from n/a thr…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-45435
|
2026-05-26 08:16 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
298
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Authentication Bypass Using an Alternate Path or Channel vulnerability in ThemeHigh Stripe Payment Gateway for WooCommerce allows Password Recovery Exploitation.
This issue affects Stripe Payment Ga…
New
|
CWE-288
Authentication Bypass Using an Alternate Path or Channel
|
CVE-2026-45217
|
2026-05-26 08:16 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
299
|
8.8 |
HIGH
Network
|
-
|
-
|
Incorrect Privilege Assignment vulnerability in StoreApps Smart Manager allows Privilege Escalation.
This issue affects Smart Manager: from n/a through 8.85.0.
New
|
CWE-266
Incorrect Privilege Assignment
|
CVE-2026-45216
|
2026-05-26 08:16 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
300
|
7.5 |
HIGH
Network
|
-
|
-
|
Missing Authorization vulnerability in edward_plainview MyCryptoCheckout allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects MyCryptoCheckout: from n/a throug…
New
|
CWE-862
Missing Authorization
|
CVE-2026-45209
|
2026-05-26 08:16 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|