|
1501
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Contributor Sensitive Data Exposure in Elementor Website Builder <= 4.1.3 versions.
|
CWE-862
Missing Authorization
|
CVE-2026-57619
|
2026-06-26 00:16 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1502
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Contributor Broken Access Control in Slim SEO <= 4.6.2 versions.
|
CWE-862
Missing Authorization
|
CVE-2026-57429
|
2026-06-26 00:16 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1503
|
7.1 |
HIGH
Network
|
-
|
-
|
An arbitrary address write vulnerability was found in libaom, the reference AV1 codec implementation. A missing bounds check in the SVC (Scalable Video Coding) layer ID control function allows an att…
|
CWE-787
Out-of-bounds Write
|
CVE-2026-56209
|
2026-06-26 00:16 |
2026-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1504
|
7.6 |
HIGH
Network
|
-
|
-
|
A heap buffer overflow vulnerability was found in libaom, the reference AV1 codec implementation. A flaw in the AV1 encoder's Look-Ahead Processing (LAP) mode causes the first-pass stats ring buffer …
|
CWE-122
Heap-based Buffer Overflow
|
CVE-2026-56208
|
2026-06-26 00:16 |
2026-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1505
|
7.7 |
HIGH
Network
|
-
|
-
|
Subscriber Arbitrary File Deletion in JS Help Desk <= 3.1.1 versions.
|
CWE-22
Path Traversal
|
CVE-2026-56054
|
2026-06-26 00:16 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1506
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Improper Access Control vulnerability in Themeisle PPOM for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects PPOM for WooCommerce: from n/a thr…
|
CWE-284
Improper Access Control
|
CVE-2026-56050
|
2026-06-26 00:16 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1507
|
8.5 |
HIGH
Network
|
-
|
-
|
Contributor Remote Code Execution (RCE) in Post Snippets <= 4.0.19 versions.
|
CWE-94
Code Injection
|
CVE-2026-56049
|
2026-06-26 00:16 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1508
|
7.1 |
HIGH
Network
|
-
|
-
|
Unauthenticated Cross Site Scripting (XSS) in H5P <= 1.17.6 versions.
|
CWE-79
Cross-site Scripting
|
CVE-2026-56006
|
2026-06-26 00:16 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1509
|
7.1 |
HIGH
Network
|
-
|
-
|
Subscriber Cross Site Scripting (XSS) in WP Activity Log <= 5.6.3.1 versions.
|
CWE-79
Cross-site Scripting
|
CVE-2026-56005
|
2026-06-26 00:16 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1510
|
9.0 |
CRITICAL
Network
|
-
|
-
|
SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, it does not escape the untrusted fields (name, version, author, description) when they are serialized into the data-obj …
|
CWE-79 CWE-94 CWE-116
Cross-site Scripting Code Injection Improper Encoding or Escaping of Output
|
CVE-2026-55570
|
2026-06-26 00:16 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|