|
271
|
9.9 |
CRITICAL
Network
|
-
|
-
|
Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, two distinct authorization defects in the team settings allowed any authenticated panel user to take over the RBAC system. Settings/Team/…
New
|
CWE-269 CWE-285
Improper Privilege Management Improper Authorization
|
CVE-2026-47744
|
2026-05-30 05:17 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272
|
5.3 |
MEDIUM
Network
|
-
|
-
|
Casdoor versions 2.362.0 and earlier contain a logic flaw in the social‑login binding flow that allows users to bypass configured MFA requirements. The binding‑rule code path in controllers/auth.go c…
Update
|
-
|
CVE-2026-9091
|
2026-05-30 05:16 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273
|
9.1 |
CRITICAL
Network
|
-
|
-
|
Casdoor versions 2.362.0 and earlier contain a vulnerability that allows an attacker to bypass authentication by supplying an arbitrary signing certificate. The buildSpCertificateStore function extra…
Update
|
-
|
CVE-2026-9090
|
2026-05-30 05:16 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
274
|
- |
|
-
|
-
|
StrongDM Desktop Application before 23.74.0 (Desktop Client before 53.77.0) on Microsoft Windows stores authentication state, including a JSON Web Token and asymmetric key material, in cleartext in a…
New
|
CWE-312 CWE-522
Cleartext Storage of Sensitive Information Insufficiently Protected Credentials
|
CVE-2026-4387
|
2026-05-30 05:16 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
275
|
- |
|
-
|
-
|
The TIFF decoder does not place a limit on the size of PackBits-compressed data. A maliciously-crafted image can exploit this to cause a small image (both in terms of pixel width/height and encoded s…
New
|
-
|
CVE-2026-46599
|
2026-05-30 05:16 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276
|
6.5 |
MEDIUM
Network
|
-
|
-
|
The brace-expansion library generates arbitrary strings containing a common prefix and suffix. From 5.0.0 to before 5.0.6, the max option was being applied too late. When expanding a single large num…
New
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2026-45149
|
2026-05-30 05:16 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277
|
5.3 |
MEDIUM
Network
|
-
|
-
|
Decoding a paletted BMP file with an out-of-range palette index results in a panic when accessing pixels in the invalid image.
New
|
-
|
CVE-2026-42500
|
2026-05-30 05:16 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278
|
7.8 |
HIGH
Local
|
-
|
-
|
In JetBrains IntelliJ IDEA before 2026.1.1 command injection was possible via filename completion
New
|
CWE-78
OS Command
|
CVE-2026-49366
|
2026-05-30 05:11 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279
|
8.0 |
HIGH
Network
|
-
|
-
|
In JetBrains IntelliJ IDEA before 2026.1.1 command execution was possible via the guest user account
New
|
CWE-862
Missing Authorization
|
CVE-2026-49367
|
2026-05-30 05:11 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280
|
8.7 |
HIGH
Network
|
-
|
-
|
In JetBrains YouTrack before 2026.1.13162 stored XSS in project notification templates was possible
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-49368
|
2026-05-30 05:11 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|