|
271
|
- |
|
-
|
-
|
An open redirect vulnerability existed in MISP UsersController::routeafterlogin() because the value stored in the pre_login_requested_url session key was used as the post-login redirect destination w…
New
|
CWE-601
Open Redirect
|
CVE-2026-10861
|
2026-06-5 00:19 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272
|
- |
|
-
|
-
|
A logic error in the MISP CRUD component delete handler allowed validation failures to be bypassed when requests used the HTTP DELETE method. Due to missing parentheses in the delete condition, the e…
New
|
CWE-863
Incorrect Authorization
|
CVE-2026-10860
|
2026-06-5 00:19 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273
|
- |
|
-
|
-
|
A security issue was fixed in the correlations over-correlation endpoint where the order query parameter was accepted from user-controlled named request parameters. This allowed an authenticated user…
New
|
CWE-20
Improper Input Validation
|
CVE-2026-10863
|
2026-06-5 00:19 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
274
|
- |
|
-
|
-
|
A vulnerability in the MISP dashboard widgets allowed an authenticated user to manipulate the fields option and influence which fields were returned by the New Users and New Organisations widgets. In…
New
|
CWE-200
Information Exposure
|
CVE-2026-10864
|
2026-06-5 00:19 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
275
|
- |
|
-
|
-
|
Version 3.0.7 of the Securly Chrome Extension downloads config.json over HTTP and compiles server-provided patterns as JavaScript regular expressions via new RegExp() without complexity validation. A…
New
|
-
|
CVE-2026-8888
|
2026-06-5 00:18 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276
|
- |
|
-
|
-
|
Version 3.0.7 of the Securly Chrome Extension uses deprecated SHA-1 hashing for IWF CSAM URL matching (25,020 hashes) and CIPA blocklist matching (12,352 hashes).
New
|
-
|
CVE-2026-8889
|
2026-06-5 00:18 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277
|
7.5 |
HIGH
Network
|
-
|
-
|
It is possible for an unauthenticated adjacent attacker to download log files of the controller, which may disclose some restricted information.
New
|
CWE-200
Information Exposure
|
CVE-2026-41032
|
2026-06-5 00:16 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278
|
9.8 |
CRITICAL
Network
|
-
|
-
|
An unauthenticated remote attacker can recover a default, hard coded password from a firmware image and thus gain full access to all affected devices.
New
|
CWE-1393
Use of Default Password
|
CVE-2026-35075
|
2026-06-5 00:16 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279
|
8.1 |
HIGH
Network
|
-
|
-
|
The bac-scanresult method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input.
New
|
CWE-73
External Control of File Name or Path
|
CVE-2026-35076
|
2026-06-5 00:16 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280
|
8.1 |
HIGH
Network
|
-
|
-
|
The ugw-delete-file method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input.
New
|
CWE-73
External Control of File Name or Path
|
CVE-2026-35077
|
2026-06-5 00:16 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|