|
4811
|
5.3 |
MEDIUM
Network
|
-
|
-
|
Missing Authorization vulnerability in Magepeople inc. Taxi Booking Manager for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects Taxi Booking M…
|
CWE-862
Missing Authorization
|
CVE-2026-25426
|
2026-05-27 05:19 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4812
|
4.3 |
MEDIUM
Network
|
-
|
-
|
Missing Authorization vulnerability in Magepeople inc. WpBookingly allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects WpBookingly: from n/a through 1.2.9.
|
CWE-862
Missing Authorization
|
CVE-2026-25444
|
2026-05-27 05:19 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4813
|
6.3 |
MEDIUM
Network
|
-
|
-
|
Missing Authorization vulnerability in Magepeople inc. WpTravelly allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects WpTravelly: from n/a through 2.1.5.
|
CWE-862
Missing Authorization
|
CVE-2026-27331
|
2026-05-27 05:19 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4814
|
7.3 |
HIGH
Network
|
-
|
-
|
A flaw has been found in itsourcecode Student Transcript Processing System 1.0. This vulnerability affects unknown code of the file /admin/modules/student/trans.php. Executing a manipulation of the a…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-9574
|
2026-05-27 05:19 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4815
|
7.3 |
HIGH
Network
|
-
|
-
|
A vulnerability has been found in itsourcecode Student Transcript Processing System 1.0. This issue affects some unknown processing of the file /admin/modules/class/index.php?view=view. The manipulat…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-9575
|
2026-05-27 05:19 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4816
|
9.8 |
CRITICAL
Network
|
litespeedtech
|
litespeed_cpanel_plugin litespeed_whm_plugin
|
LiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalation (possibly to root), as exploited in the wild in May 2026. Detection is best done via a command line of grep -rE "cpanel_jsona…
|
CWE-266
Incorrect Privilege Assignment
|
CVE-2026-48172
|
2026-05-27 05:19 |
2026-05-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4817
|
7.5 |
HIGH
Network
|
-
|
-
|
D-Link DIR601 2.02NA contains a credential disclosure vulnerability that allows unauthenticated attackers to retrieve sensitive configuration data by manipulating the table_name parameter in POST req…
|
CWE-497
Exposure of Sensitive System Information to an Unauthorized Control Sphere
|
CVE-2018-25358
|
2026-05-27 05:16 |
2026-05-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4818
|
8.2 |
HIGH
Network
|
-
|
-
|
code100x contains an authentication bypass vulnerability in the Mobile API that allows unauthenticated attackers to impersonate arbitrary users by supplying a crafted JSON payload in the 'g' HTTP hea…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-8890
|
2026-05-27 05:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4819
|
- |
|
-
|
-
|
Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have been removed to prevent accid…
|
-
|
CVE-2026-8453
|
2026-05-27 05:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4820
|
3.1 |
LOW
Network
|
-
|
-
|
TypeBot is a chatbot builder tool. In versions 3.15.2 and prior, the bot engine's the findResult query does not filter results by typebotId, allowing an authenticated user to load result data (user a…
|
CWE-639 CWE-862
Authorization Bypass Through User-Controlled Key Missing Authorization
|
CVE-2026-39967
|
2026-05-27 05:16 |
2026-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|