|
911
|
8.1 |
HIGH
Network
|
deno
|
deno
|
Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.7.10, Deno's node:child_process implementation provided an escapeShellArg() helper used when callers passed shell: true to spawn …
|
CWE-78
OS Command
|
CVE-2026-49402
|
2026-06-27 02:33 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
912
|
5.5 |
MEDIUM
Local
|
deno
|
deno
|
Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.7.12, when Deno was run in BYONM mode (nodeModulesDir: "manual"), the module resolver did not validate that a package's resolved …
|
CWE-22
Path Traversal
|
CVE-2026-49406
|
2026-06-27 02:29 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
913
|
6.5 |
MEDIUM
Local
|
deno
|
deno
|
Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.8.0, the Node.js compatibility TCP path checked the permission against the original hostname string before resolution and then di…
|
CWE-284 NVD-CWE-noinfo
Improper Access Control
|
CVE-2026-49411
|
2026-06-27 02:27 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
914
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Nil-pointer dereference in CreateCustomVolumeFromBackup in LXD up to version 6.8 and 5.21 on Linux allows an authenticated user with can_create_storage_volumes permissions to cause a denial of servic…
|
CWE-476
NULL Pointer Dereference
|
CVE-2026-9639
|
2026-06-27 02:16 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
915
|
9.8 |
CRITICAL
Network
|
-
|
-
|
An unauthenticated
stack-based buffer overflow vulnerability exists in vlsvr in GeoVision
GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerability is caused by
insufficient length validation wh…
|
CWE-121
Stack-based Buffer Overflow
|
CVE-2026-57881
|
2026-06-27 02:16 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
916
|
9.8 |
CRITICAL
Network
|
-
|
-
|
An unauthenticated
stack-based buffer overflow vulnerability exists in ssvr in GeoVision
GV-LPC2011 and GV-LPC2211 V1.12 and earlier. The vulnerability is caused by
insufficient bounds checking when …
|
CWE-121
Stack-based Buffer Overflow
|
CVE-2026-57879
|
2026-06-27 02:16 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
917
|
8.5 |
HIGH
Network
|
-
|
-
|
Contributor SQL Injection in Contest Gallery <= 30.0.0 versions.
|
CWE-89
SQL Injection
|
CVE-2026-57662
|
2026-06-27 02:16 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
918
|
5.9 |
MEDIUM
Network
|
-
|
-
|
Author Cross Site Scripting (XSS) in Hester Core <= 1.1.8 versions.
|
CWE-79
Cross-site Scripting
|
CVE-2026-57656
|
2026-06-27 02:16 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
919
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Contributor Cross Site Scripting (XSS) in Magazine Blocks <= 1.8.3 versions.
|
CWE-79
Cross-site Scripting
|
CVE-2026-57650
|
2026-06-27 02:16 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
920
|
8.5 |
HIGH
Network
|
-
|
-
|
Contributor SQL Injection in Restaurant Menu by MotoPress <= 2.4.10 versions.
|
CWE-89
SQL Injection
|
CVE-2026-57644
|
2026-06-27 02:16 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|