|
4581
|
7.8 |
HIGH
Local
|
-
|
-
|
Microsoft UFO open-source framework for intelligent automation across devices and platforms. Microsoft UFO tagged releases up to and including v3.0.0 contain an OS command injection vulnerability in …
|
CWE-78
OS Command
|
CVE-2026-45322
|
2026-05-29 03:56 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4582
|
6.3 |
MEDIUM
Network
|
-
|
-
|
Microsoft UFO open-source framework for intelligent automation across devices and platforms. In 3.0.1-4-ge2626659, Microsoft UFO creates one shared UFOWebSocketHandler instance and reuses it for mult…
|
CWE-284 CWE-488
Improper Access Control Exposure of Data Element to Wrong Session
|
CVE-2026-46416
|
2026-05-29 03:56 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4583
|
5.9 |
MEDIUM
Network
|
-
|
-
|
Microsoft UFO open-source framework for intelligent automation across devices and platforms. In 3.0.1-4-ge2626659, Microsoft UFO's constellation client tracks pending task responses by session_id onl…
|
CWE-294 CWE-345
Authentication Bypass by Capture-replay Insufficient Verification of Data Authenticity
|
CVE-2026-46538
|
2026-05-29 03:56 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4584
|
5.3 |
MEDIUM
Network
|
-
|
-
|
Microsoft UFO open-source framework for intelligent automation across devices and platforms. In 3.0.1-4-ge2626659, Microsoft UFO accepts client-supplied session_id values in WebSocket task messages a…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-46544
|
2026-05-29 03:56 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4585
|
- |
|
-
|
-
|
Cross Site Scripting vulnerability in Follet School Solutions Destiny before v22.0.1 AU1 allows a remote attacker to run arbitrary client-side code via the showSupportExpiredMessage parameter of hand…
|
CWE-79
Cross-site Scripting
|
CVE-2024-47096
|
2026-05-29 03:56 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4586
|
- |
|
-
|
-
|
Cross Site Scripting vulnerability in Follet School Solutions Destiny before v22.0.1 AU1 allows a remote attacker to run arbitrary client-side code via the site parameter of handleloginform.do.
|
CWE-79
Cross-site Scripting
|
CVE-2024-47097
|
2026-05-29 03:56 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4587
|
- |
|
-
|
-
|
The Mennekes Amtron series (firmware versions ≤ 5.22.3) is vulnerable to an authentication bypass. An unauthenticated remote attacker can change the password of the user account via a crafted POST re…
|
CWE-287
Improper Authentication
|
CVE-2026-8979
|
2026-05-29 03:56 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4588
|
- |
|
-
|
-
|
The Mennekes Amtron series (firmware versions ≤ 5.22.3) is vulnerable to privilege escalation. An authenticated low-privileged user can change the passwords of the admin (operator) and manufacturer a…
|
CWE-269
Improper Privilege Management
|
CVE-2026-8980
|
2026-05-29 03:56 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4589
|
7.5 |
HIGH
Network
|
-
|
-
|
phpMyFAQ before 4.1.3 contains an authentication bypass vulnerability in API v4.0 where the default empty api.apiClientToken allows unauthenticated users to create and modify FAQ entries. Attackers c…
|
CWE-1188
Insecure Default Initialization of Resource
|
CVE-2026-35672
|
2026-05-29 03:56 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4590
|
8.2 |
HIGH
Network
|
-
|
-
|
phpMyFAQ before 4.1.3 contains an unauthenticated password reset vulnerability in the user password update API endpoint that allows attackers to change account passwords without token validation. Att…
|
CWE-640
Weak Password Recovery Mechanism for Forgotten Password
|
CVE-2026-35676
|
2026-05-29 03:56 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|