|
951
|
7.8 |
HIGH
Local
|
vim
|
vim
|
Vim is an open source, command line text editor. Prior to 9.2.0663, a Vimscript code injection vulnerability exists in s:NetrwLocalRmFile() in the netrw plugin (runtime/pack/dist/opt/netrw/autoload/n…
New
|
CWE-78 CWE-94
OS Command Code Injection
|
CVE-2026-55895
|
2026-06-26 14:16 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
952
|
7.4 |
HIGH
Network
|
-
|
-
|
Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.1, 8.4.4, 8.3.6, 8.2.6, 8.1.6, 8.0.7, and 7.10.13, Rocket.Chat's Apple Sign-In handler verifies JWT sig…
New
|
CWE-287 CWE-294
Improper Authentication Authentication Bypass by Capture-replay
|
CVE-2026-55759
|
2026-06-26 14:16 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
953
|
8.8 |
HIGH
Network
|
-
|
-
|
pnpm is a package manager. Prior to 10.34.2 and 11.5.3, pnpm can persist package-manager bootstrap metadata in the first YAML document of pnpm-lock.yaml. Before the patch, direct pnpm execution trust…
New
|
CWE-345 CWE-494 CWE-829
Insufficient Verification of Data Authenticity Download of Code Without Integrity Check Inclusion of Functionality from Untrusted Control Sphere
|
CVE-2026-55698
|
2026-06-26 14:16 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
954
|
7.5 |
HIGH
Network
|
-
|
-
|
pnpm is a package manager. Prior to 10.34.2 and 11.5.3, pnpm can install configDependencies declared in pnpm-workspace.yaml before command dispatch. Before the patch, a repository could declare pacqu…
New
|
CWE-78 CWE-494 CWE-829
OS Command Download of Code Without Integrity Check Inclusion of Functionality from Untrusted Control Sphere
|
CVE-2026-55697
|
2026-06-26 14:16 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
955
|
- |
|
-
|
-
|
Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.1, 8.4.4, 8.3.6, 8.2.6, 8.1.6, 8.0.7, and 7.10.13, in apps/meteor/app/apple/server/loginHandler.ts, han…
New
|
CWE-287 CWE-288
Improper Authentication Authentication Bypass Using an Alternate Path or Channel
|
CVE-2026-55666
|
2026-06-26 14:16 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
956
|
10.0 |
CRITICAL
Network
|
-
|
-
|
Gogs is an open source self-hosted Git service. Prior to 0.14.3, organization names containing path traversal sequences (../) are accepted by Gogs, and repositories under them are written to paths fo…
New
|
CWE-23
Relative Path Traversal
|
CVE-2026-52813
|
2026-06-26 14:16 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
957
|
- |
|
-
|
-
|
Gogs is an open source self-hosted Git service. Prior to 0.14.3, (*Repository).UploadRepoFiles checks for symlinks only on the leaf of the upload target (osx.IsSymlink(targetPath)). The siblings Upda…
New
|
CWE-22 CWE-59 CWE-61
Path Traversal Link Following UNIX Symbolic Link (Symlink) Following
|
CVE-2026-52811
|
2026-06-26 14:16 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
958
|
6.8 |
MEDIUM
Network
|
-
|
-
|
Gogs is an open source self-hosted Git service. Prior to 0.14.3, password-reset tokens are generated using conf.Auth.ActivateCodeLives (the account-activation lifetime), not conf.Auth.ResetPasswordCo…
New
|
CWE-324 CWE-613
Use of a Key Past its Expiration Date Insufficient Session Expiration
|
CVE-2026-52809
|
2026-06-26 14:16 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
959
|
9.9 |
CRITICAL
Network
|
-
|
-
|
Gogs is an open source self-hosted Git service. Prior to 0.14.3, Gogs allows authenticated users to achieve Remote Code Execution (RCE) on the server by creating a pull request with a specially craft…
New
|
CWE-77
Command Injection
|
CVE-2026-52806
|
2026-06-26 14:16 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
960
|
8.7 |
HIGH
Network
|
-
|
-
|
Gogs is an open source self-hosted Git service. Prior to 0.14.3, a Server-Side Request Forgery (SSRF) vulnerability exists in the repository migration functionality. The application validates only th…
New
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-52805
|
2026-06-26 14:16 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|