|
1811
|
8.1 |
HIGH
Local
|
-
|
-
|
Insertion of Sensitive Information into Log File (CWE-532) in some Command Centre Service installers could lead to Service Account credentials exposure.
Mitigating Factor: Only sites that install Co…
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2026-25193
|
2026-05-27 05:24 |
2026-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1812
|
6.6 |
MEDIUM
Network
|
-
|
-
|
SQL Injection affecting the Access Manager role.
|
CWE-89
SQL Injection
|
CVE-2026-27768
|
2026-05-27 05:24 |
2026-05-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1813
|
7.5 |
HIGH
Network
|
-
|
-
|
In GNU SASL before 2.2.3, DIGEST-MD5 has a NULL pointer dereference affecting both clients and servers, via a known token with no accompanying = character. This occurs in lib/digest-md5/getsubopt.c.
|
CWE-476
NULL Pointer Dereference
|
CVE-2026-48829
|
2026-05-27 05:19 |
2026-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1814
|
- |
|
-
|
-
|
Wine ships a .desktop file that registers itself as a MIME handler for EXE files and several other Windows executable file types. In some configurations, handling of an EXE file causes that file to b…
|
CWE-669
Incorrect Resource Transfer Between Spheres
|
CVE-2026-48831
|
2026-05-27 05:19 |
2026-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1815
|
3.5 |
LOW
Network
|
-
|
-
|
action/cookie.php in ecrire in SPIP before 4.4.15 is prone to an open redirect vulnerability.
|
CWE-601
Open Redirect
|
CVE-2026-48832
|
2026-05-27 05:19 |
2026-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1816
|
4.3 |
MEDIUM
Network
|
-
|
-
|
Missing Authorization vulnerability in bPlugins Tiktok Feed allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects Tiktok Feed: from n/a through 1.0.24.
|
CWE-862
Missing Authorization
|
CVE-2026-24520
|
2026-05-27 05:19 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1817
|
5.3 |
MEDIUM
Network
|
-
|
-
|
Missing Authorization vulnerability in Magepeople inc. Taxi Booking Manager for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects Taxi Booking M…
|
CWE-862
Missing Authorization
|
CVE-2026-25426
|
2026-05-27 05:19 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1818
|
4.3 |
MEDIUM
Network
|
-
|
-
|
Missing Authorization vulnerability in Magepeople inc. WpBookingly allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects WpBookingly: from n/a through 1.2.9.
|
CWE-862
Missing Authorization
|
CVE-2026-25444
|
2026-05-27 05:19 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1819
|
6.3 |
MEDIUM
Network
|
-
|
-
|
Missing Authorization vulnerability in Magepeople inc. WpTravelly allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects WpTravelly: from n/a through 2.1.5.
|
CWE-862
Missing Authorization
|
CVE-2026-27331
|
2026-05-27 05:19 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1820
|
7.3 |
HIGH
Network
|
-
|
-
|
A flaw has been found in itsourcecode Student Transcript Processing System 1.0. This vulnerability affects unknown code of the file /admin/modules/student/trans.php. Executing a manipulation of the a…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-9574
|
2026-05-27 05:19 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|