Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

Количество 389 227

Количество 389 227

nvd логотип

CVE-2026-5794

4 месяца назад

A vulnerability affecting the detailed versions of Cryptobox allows a legitimate user to prevent another to login by triggering an account lockout via sending a specially crafted request.

EPSS: Низкий
nvd логотип

CVE-2026-57949

2 месяца назад

ruoyi-vue-pro through 2026.05, fixed in commit c779a47, contains a missing authorization vulnerability in the CRM module's GET /admin-api/crm/follow-up-record/get endpoint that allows authenticated users to read any follow-up record by iterating sequential numeric IDs. Attackers can exploit this by sending requests with arbitrary ID parameters to access other users' follow-up notes, file attachments, scheduling information, and business entity references without proper authorization checks.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-57948

2 месяца назад

Pinpoint through version 3.1.0 contains an insecure session management vulnerability that allows attackers to access the pinpointJwt session cookie due to missing HttpOnly and Secure attributes, enabling JavaScript access via document.cookie and cleartext transmission over HTTP. Attackers can exploit stored or reflected cross-site scripting vulnerabilities to exfiltrate the session token or intercept it through network sniffing to perform session hijacking.

CVSS3: 6.8
EPSS: Низкий
nvd логотип

CVE-2026-57947

2 месяца назад

Pinpoint through 3.1.0 contains a server-side request forgery vulnerability in the webhook registration endpoint that allows authenticated users to register internal URLs due to missing SSRF protection. Attackers can trigger alarm threshold breaches to force the server to issue POST requests to internal hosts and metadata endpoints, enabling unauthorized access to internal network resources.

CVSS3: 8.5
EPSS: Низкий
nvd логотип

CVE-2026-57946

2 месяца назад

Invidious before version 2.20260626.0 contains a broken access control vulnerability that allows unauthenticated attackers to retrieve private playlist contents by accessing the RSS feed playlist endpoint without authentication. Attackers can supply a playlist ID to the feed endpoint to obtain the full playlist contents, owner email address, and associated video entries without any authentication.

CVSS3: 3.7
EPSS: Низкий
nvd логотип

CVE-2026-57945

2 месяца назад

PhotoPrism before 260601-a7d098548 contains a broken access control vulnerability that allows authenticated non-admin users to modify other users' profile information by sending requests to arbitrary user endpoints. Attackers can exploit the missing session-to-user identifier validation in the PUT users API endpoint to overwrite another user's profile details without authorization.

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2026-57944

19 дней назад

AVideo through commit 9c39d8c8 contains a cross-site request forgery vulnerability in channelToGallery.json.php that allows attackers to modify site-wide Gallery configuration by performing unauthorized writes to plugin data. Attackers can craft a cross-site GET request carrying an administrator's session cookie to promote arbitrary channels to the front page or delete curated sections without token validation.

CVSS3: 5.4
EPSS: Низкий
nvd логотип

CVE-2026-57943

2 месяца назад

LibrePhotos before 1.0.0 contains a broken object level authorization vulnerability in the SetPhotosShared endpoint that allows authenticated users to grant themselves access to other users' private photos by bypassing ownership validation. Attackers can manipulate shared_to relations without proper owner checks to read arbitrary private photos belonging to other users.

CVSS3: 5.9
EPSS: Низкий
nvd логотип

CVE-2026-57942

2 месяца назад

LibreTranslate through 1.9.7, fixed in commit 397fd22, contains an IP spoofing vulnerability in the get_remote_address() function that allows unauthenticated attackers to spoof client IP addresses by injecting arbitrary values into the X-Forwarded-For header without trusted proxy validation. Attackers can bypass per-IP rate limiting and flood bans by supplying forged addresses in the X-Forwarded-For header to enable unlimited API abuse.

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2026-57940

3 месяца назад

HTMLy 3.1.1 contains a Server-Side Request Forgery (SSRF) vulnerability in the RSS feed import functionality. The function get_feed() in system/admin/admin.php passes user-supplied $feed_url directly to file_get_contents() without any validation. An authenticated attacker with administrative privileges can exploit this by entering a crafted URL (e.g., http://dnslog.example.com, file:///etc/passwd, or http://169.254.169.254 in cloud contexts) via Tools -> Import RSS. The server will then make a request to the attacker-controlled target.

EPSS: Низкий
nvd логотип

CVE-2026-5793

2 месяца назад

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Inrove Software and Internet Services BiEticaret allows Reflected XSS. This issue affects BiEticaret: before v3.3.57.

CVSS3: 6.1
EPSS: Низкий
nvd логотип

CVE-2026-5792

3 месяца назад

Authentication bypass by spoofing vulnerability in Hedef Media Promotion Interactive Media Marketing Inc. Related Marketing Cloud (RMC) allows Brute Force. This issue affects Related Marketing Cloud (RMC): through 12052026.

CVSS3: 6.5
EPSS: Низкий
nvd логотип

CVE-2026-57926

3 месяца назад

In JetBrains YouTrack before 2026.2.16593 the websandbox bridge was vulnerable to a prototype pollution attack

CVSS3: 2.6
EPSS: Низкий
nvd логотип

CVE-2026-57925

3 месяца назад

In JetBrains YouTrack before 2026.2.16593 improper access control allowed reading saved queries and tags

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2026-57924

3 месяца назад

In JetBrains YouTrack before 2026.2.16593 default role configuration exposed excessive user profile details

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2026-57923

3 месяца назад

In JetBrains YouTrack before 2026.2.16593 improper authorisation in the app configurations endpoint allowed modifying project settings

CVSS3: 5.3
EPSS: Низкий
nvd логотип

CVE-2026-57922

3 месяца назад

In JetBrains YouTrack before 2026.2.16593 project settings disclosure via the MCP was possible

CVSS3: 3.1
EPSS: Низкий
nvd логотип

CVE-2026-57921

3 месяца назад

In JetBrains YouTrack before 2026.2.16593 improper access control allowed reading users' private data via the comment templates endpoint

CVSS3: 4.3
EPSS: Низкий
nvd логотип

CVE-2026-57920

3 месяца назад

Peplink InControl 2 through 2.14.2 before 2026-06-03 allows use of a semicolon to bypass access-control rules for certain /rest/o/{orgId} endpoints.

CVSS3: 7.7
EPSS: Низкий
nvd логотип

CVE-2026-5791

4 месяца назад

Cross-Site request forgery (CSRF) vulnerability in DivvyDrive Information Technologies Inc. DivvyDrive allows Cross Site Request Forgery. This issue affects DivvyDrive: from 4.8.2.9 before 4.8.3.2.

CVSS3: 6.5
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2026-5794

A vulnerability affecting the detailed versions of Cryptobox allows a legitimate user to prevent another to login by triggering an account lockout via sending a specially crafted request.

0%
Низкий
4 месяца назад
nvd логотип
CVE-2026-57949

ruoyi-vue-pro through 2026.05, fixed in commit c779a47, contains a missing authorization vulnerability in the CRM module's GET /admin-api/crm/follow-up-record/get endpoint that allows authenticated users to read any follow-up record by iterating sequential numeric IDs. Attackers can exploit this by sending requests with arbitrary ID parameters to access other users' follow-up notes, file attachments, scheduling information, and business entity references without proper authorization checks.

CVSS3: 6.5
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-57948

Pinpoint through version 3.1.0 contains an insecure session management vulnerability that allows attackers to access the pinpointJwt session cookie due to missing HttpOnly and Secure attributes, enabling JavaScript access via document.cookie and cleartext transmission over HTTP. Attackers can exploit stored or reflected cross-site scripting vulnerabilities to exfiltrate the session token or intercept it through network sniffing to perform session hijacking.

CVSS3: 6.8
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-57947

Pinpoint through 3.1.0 contains a server-side request forgery vulnerability in the webhook registration endpoint that allows authenticated users to register internal URLs due to missing SSRF protection. Attackers can trigger alarm threshold breaches to force the server to issue POST requests to internal hosts and metadata endpoints, enabling unauthorized access to internal network resources.

CVSS3: 8.5
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-57946

Invidious before version 2.20260626.0 contains a broken access control vulnerability that allows unauthenticated attackers to retrieve private playlist contents by accessing the RSS feed playlist endpoint without authentication. Attackers can supply a playlist ID to the feed endpoint to obtain the full playlist contents, owner email address, and associated video entries without any authentication.

CVSS3: 3.7
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-57945

PhotoPrism before 260601-a7d098548 contains a broken access control vulnerability that allows authenticated non-admin users to modify other users' profile information by sending requests to arbitrary user endpoints. Attackers can exploit the missing session-to-user identifier validation in the PUT users API endpoint to overwrite another user's profile details without authorization.

CVSS3: 4.3
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-57944

AVideo through commit 9c39d8c8 contains a cross-site request forgery vulnerability in channelToGallery.json.php that allows attackers to modify site-wide Gallery configuration by performing unauthorized writes to plugin data. Attackers can craft a cross-site GET request carrying an administrator's session cookie to promote arbitrary channels to the front page or delete curated sections without token validation.

CVSS3: 5.4
0%
Низкий
19 дней назад
nvd логотип
CVE-2026-57943

LibrePhotos before 1.0.0 contains a broken object level authorization vulnerability in the SetPhotosShared endpoint that allows authenticated users to grant themselves access to other users' private photos by bypassing ownership validation. Attackers can manipulate shared_to relations without proper owner checks to read arbitrary private photos belonging to other users.

CVSS3: 5.9
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-57942

LibreTranslate through 1.9.7, fixed in commit 397fd22, contains an IP spoofing vulnerability in the get_remote_address() function that allows unauthenticated attackers to spoof client IP addresses by injecting arbitrary values into the X-Forwarded-For header without trusted proxy validation. Attackers can bypass per-IP rate limiting and flood bans by supplying forged addresses in the X-Forwarded-For header to enable unlimited API abuse.

CVSS3: 5.3
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-57940

HTMLy 3.1.1 contains a Server-Side Request Forgery (SSRF) vulnerability in the RSS feed import functionality. The function get_feed() in system/admin/admin.php passes user-supplied $feed_url directly to file_get_contents() without any validation. An authenticated attacker with administrative privileges can exploit this by entering a crafted URL (e.g., http://dnslog.example.com, file:///etc/passwd, or http://169.254.169.254 in cloud contexts) via Tools -> Import RSS. The server will then make a request to the attacker-controlled target.

0%
Низкий
3 месяца назад
nvd логотип
CVE-2026-5793

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Inrove Software and Internet Services BiEticaret allows Reflected XSS. This issue affects BiEticaret: before v3.3.57.

CVSS3: 6.1
0%
Низкий
2 месяца назад
nvd логотип
CVE-2026-5792

Authentication bypass by spoofing vulnerability in Hedef Media Promotion Interactive Media Marketing Inc. Related Marketing Cloud (RMC) allows Brute Force. This issue affects Related Marketing Cloud (RMC): through 12052026.

CVSS3: 6.5
0%
Низкий
3 месяца назад
nvd логотип
CVE-2026-57926

In JetBrains YouTrack before 2026.2.16593 the websandbox bridge was vulnerable to a prototype pollution attack

CVSS3: 2.6
0%
Низкий
3 месяца назад
nvd логотип
CVE-2026-57925

In JetBrains YouTrack before 2026.2.16593 improper access control allowed reading saved queries and tags

CVSS3: 4.3
0%
Низкий
3 месяца назад
nvd логотип
CVE-2026-57924

In JetBrains YouTrack before 2026.2.16593 default role configuration exposed excessive user profile details

CVSS3: 4.3
0%
Низкий
3 месяца назад
nvd логотип
CVE-2026-57923

In JetBrains YouTrack before 2026.2.16593 improper authorisation in the app configurations endpoint allowed modifying project settings

CVSS3: 5.3
0%
Низкий
3 месяца назад
nvd логотип
CVE-2026-57922

In JetBrains YouTrack before 2026.2.16593 project settings disclosure via the MCP was possible

CVSS3: 3.1
0%
Низкий
3 месяца назад
nvd логотип
CVE-2026-57921

In JetBrains YouTrack before 2026.2.16593 improper access control allowed reading users' private data via the comment templates endpoint

CVSS3: 4.3
0%
Низкий
3 месяца назад
nvd логотип
CVE-2026-57920

Peplink InControl 2 through 2.14.2 before 2026-06-03 allows use of a semicolon to bypass access-control rules for certain /rest/o/{orgId} endpoints.

CVSS3: 7.7
0%
Низкий
3 месяца назад
nvd логотип
CVE-2026-5791

Cross-Site request forgery (CSRF) vulnerability in DivvyDrive Information Technologies Inc. DivvyDrive allows Cross Site Request Forgery. This issue affects DivvyDrive: from 4.8.2.9 before 4.8.3.2.

CVSS3: 6.5
0%
Низкий
4 месяца назад

Уязвимостей на страницу