|
721
|
8.1 |
HIGH
Network
|
n8n
|
n8n
|
n8n is an open source workflow automation platform. Prior to 1.123.43, 2.22.1, and 2.20.7, the OAuth1 and OAuth2 credential reconnect endpoints authorized access using credential:read rather than cre…
New
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-45732
|
2026-06-27 05:17 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
722
|
8.8 |
HIGH
Network
|
quest
|
netvault_backup
|
Quest NetVault Backup viewclient Cross-Site Scripting Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of Quest NetVa…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-7569
|
2026-06-27 05:16 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
723
|
8.8 |
HIGH
Network
|
unraid
|
unraid
|
Unraid Web Server ToggleState Command Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Unraid. Authenti…
New
|
CWE-78
OS Command
|
CVE-2026-9773
|
2026-06-27 05:15 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
724
|
7.4 |
HIGH
Network
|
yt-dlp_project
|
yt-dlp
|
yt-dlp is a command-line audio/video downloader. From 2023.09.24 until 2026.06.09, if curl is used as an external downloader for yt-dlp, cookies may be leaked to an unintended host upon HTTP redirect…
New
|
CWE-200
Information Exposure
|
CVE-2026-50019
|
2026-06-27 05:12 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
725
|
9.6 |
CRITICAL
Network
|
yt-dlp_project
|
yt-dlp
|
yt-dlp is a command-line audio/video downloader. Prior to 2026.06.09, a vulnerability exists in yt-dlp that allows a remote attacker to write arbitrary OS-shortcut files (such as .desktop, .url, .web…
New
|
CWE-641
Improper Restriction of Names for Files and Other Resources
|
CVE-2026-50023
|
2026-06-27 05:12 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
726
|
9.6 |
CRITICAL
Network
|
yt-dlp_project
|
yt-dlp
|
yt-dlp is a command-line audio/video downloader. Prior to 2026.06.09, if aria2c is used as an external downloader for a fragmented manifest format (such as an HLS/DASH stream), yt-dlp passes insuffic…
New
|
CWE-74
Injection
|
CVE-2026-50574
|
2026-06-27 05:11 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
727
|
6.5 |
MEDIUM
Network
|
ultrajson_project
|
ultrajson
|
UltraJSON is a fast JSON encoder and decoder written in pure C with bindings for Python 3.7+. Prior to 5.13.0, ujson.dumps() (or ujson.dump() or ujson.encode()) have a reject_bytes=False option. When…
New
|
CWE-20
Improper Input Validation
|
CVE-2026-54911
|
2026-06-27 05:10 |
2026-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
728
|
5.4 |
MEDIUM
Network
|
authlib
|
authlib
|
Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to 1.6.10 and 1.7.1, Authlib's OAuth 2.0 authorization endpoint can be turned into an unauthenticated open redirect wh…
New
|
CWE-601
Open Redirect
|
CVE-2026-41479
|
2026-06-27 05:10 |
2026-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
729
|
5.8 |
MEDIUM
Network
|
phpseclib
|
phpseclib
|
phpseclib is a PHP secure communications library. From 0.1.1 until 1.0.30, 2.0.55, and 3.0.54, when an application validates an untrusted X.509 certificate with phpseclib, X509::validateSignature() r…
New
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-55599
|
2026-06-27 05:10 |
2026-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
730
|
6.1 |
MEDIUM
Network
|
fabricjs
|
fabric.js
|
Fabric.js is a Javascript HTML5 canvas library. Prior to 7.4.0, a potential Cross-Site Scripting (XSS) vulnerability exists in Fabric.js due to improper escaping of user-controlled input during SVG s…
New
|
CWE-79 CWE-116
Cross-site Scripting Improper Encoding or Escaping of Output
|
CVE-2026-44311
|
2026-06-27 05:09 |
2026-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|