|
21
|
10.0 |
CRITICAL
Network
|
-
|
-
|
Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, AuthenticationFilter in Kestra OSS uses request.getPath().endsWith("/configs") to whitelist the public confi…
New
|
CWE-78 CWE-184 CWE-287 CWE-918
OS Command Incomplete Blacklist Improper Authentication Server-Side Request Forgery (SSRF)
|
CVE-2026-49869
|
2026-06-30 03:51 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
22
|
7.7 |
HIGH
Network
|
-
|
-
|
Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.23, the local internal-storage backend validates user-supplied paths for .. traversal before it converts Windows…
New
|
CWE-22 CWE-180 CWE-200
Path Traversal Incorrect Behavior Order: Validate Before Canonicalize Information Exposure
|
CVE-2026-49984
|
2026-06-30 03:51 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
23
|
10.0 |
CRITICAL
Network
|
-
|
-
|
Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, the authentication filter for the REST API (@Filter("/api/v1/**")) treats any request whose path ends in /co…
New
|
CWE-94 CWE-288
Code Injection Authentication Bypass Using an Alternate Path or Channel
|
CVE-2026-53576
|
2026-06-30 03:51 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
24
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Kestra is an open-source, event-driven orchestration platform. Prior to 1.0.45 and 1.3.21, the previewFileFromExecution endpoint (GET /api/v1/{tenant}/executions/{executionId}/file/preview) contains …
New
|
CWE-863
Incorrect Authorization
|
CVE-2026-53577
|
2026-06-30 03:51 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
25
|
8.7 |
HIGH
Network
|
-
|
-
|
Kestra is an open-source, event-driven orchestration platform. Prior to 1.3.24, this vulnerability exists in the BasicAuth authentication component of the Kestra OSS workflow orchestration platform. …
New
|
CWE-916
Use of Password Hash With Insufficient Computational Effort
|
CVE-2026-55069
|
2026-06-30 03:51 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
26
|
7.7 |
HIGH
Local
|
-
|
-
|
HCL Traveler for Microsoft Outlook (HTMO) is susceptible to vulnerabilities due to .NET Framework 4.5 being out of service. Since .NET Framework 4.5 has reached end-of-life and no longer receives se…
New
|
CWE-1104
Use of Unmaintained Third Party Components
|
CVE-2023-37524
|
2026-06-30 03:51 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
27
|
5.5 |
MEDIUM
Local
|
-
|
-
|
HCL Traveler for Microsoft Outlook (HTMO) is susceptible to a sensitive data exposure vulnerability which could allow an attacker to exploit application information to then attempt additional attacks…
New
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2025-59868
|
2026-06-30 03:51 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
28
|
9.8 |
CRITICAL
Network
|
-
|
-
|
The Joomla extension JoomCCK exposes a front-end controller task, that builds two SQL statements by directly concatenating a user-supplied request parameter into the query string without escaping or …
New
|
CWE-89
SQL Injection
|
CVE-2026-49048
|
2026-06-30 03:51 |
2026-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
29
|
6.8 |
MEDIUM
Local
|
-
|
-
|
A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a raw pointer to a parent partition entry in…
New
|
CWE-416
Use After Free
|
CVE-2026-13595
|
2026-06-30 03:51 |
2026-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
30
|
5.1 |
MEDIUM
Local
|
-
|
-
|
A flaw was found in spice-vdagent. A malicious or compromised SPICE host can trigger an integer overflow by sending a specially crafted message. This vulnerability can lead to a heap buffer overflow,…
New
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2026-57965
|
2026-06-30 03:51 |
2026-06-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|