Total
403846 CVE
| CVE | Vendors | Products | Updated | CVSS v2 | CVSS v3 |
|---|---|---|---|---|---|
| CVE-2026-26885 | 1 Oretnom23 | 1 Simple Online Men\'s Salon Management System | 2026-06-17 | N/A | 2.7 LOW |
| Sourcecodester Online Men's Salon Management System v1.0 is vulnerable to SQL Injection in /classes/Master.php?f=delete_service. | |||||
| CVE-2026-26884 | 1 Oretnom23 | 1 Simple Online Men\'s Salon Management System | 2026-06-17 | N/A | 2.7 LOW |
| Sourcecodester Online Men's Salon Management System v1.0 is vulnerable to SQL Injection in /msms/admin/appointments/view_appointment.php. | |||||
| CVE-2026-26883 | 1 Oretnom23 | 1 Simple Online Men\'s Salon Management System | 2026-06-17 | N/A | 2.7 LOW |
| Sourcecodester Online Men's Salon Management System v1.0 is vulnerable to SQL Injection in /msms/classes/Master.php?f=delete_appointment. | |||||
| CVE-2026-26862 | 1 Clevertap | 1 Clevertap Web Sdk | 2026-06-17 | N/A | 8.3 HIGH |
| CleverTap Web SDK version 1.15.2 and earlier is vulnerable to DOM-based Cross-Site Scripting (XSS) via window.postMessage in the Visual Builder module. The origin validation in src/modules/visualBuilder/pageBuilder.js (lines 56-60) uses the includes() method to verify the originUrl contains "dashboard.clevertap.com", which can be bypassed by an attacker using a crafted subdomain | |||||
| CVE-2026-26861 | 1 Clevertap | 1 Clevertap Web Sdk | 2026-06-17 | N/A | 8.3 HIGH |
| CleverTap Web SDK version 1.15.2 and earlier is vulnerable to Cross-Site Scripting (XSS) via window.postMessage. The handleCustomHtmlPreviewPostMessageEvent function in src/util/campaignRender/nativeDisplay.js performs insufficient origin validation using the includes() method, which can be bypassed by an attacker using a subdomain | |||||
| CVE-2026-26833 | 1 Mmahrous | 1 Thumbler | 2026-06-17 | N/A | 9.8 CRITICAL |
| thumbler through 1.1.2 allows OS command injection via the input, output, time, or size parameter in the thumbnail() function because user input is concatenated into a shell command string passed to child_process.exec() without proper sanitization or escaping. | |||||
| CVE-2026-26832 | 1 Zapolnoch | 1 Tesseract Ocr | 2026-06-17 | N/A | 9.8 CRITICAL |
| node-tesseract-ocr is an npm package that provides a Node.js wrapper for Tesseract OCR. In all versions through 2.2.1, the recognize() function in src/index.js is vulnerable to OS Command Injection. The file path parameter is concatenated into a shell command string and passed to child_process.exec() without proper sanitization | |||||
| CVE-2026-26831 | 1 Dbashford | 1 Textract | 2026-06-17 | N/A | 9.8 CRITICAL |
| textract through 2.5.0 is vulnerable to OS Command Injection via the file path parameter in multiple extractors. When processing files with malicious filenames, the filePath is passed directly to child_process.exec() in lib/extractors/doc.js, rtf.js, dxf.js, images.js, and lib/util.js with inadequate sanitization | |||||
| CVE-2026-26830 | 1 Pdf-image Project | 1 Pdf-image | 2026-06-17 | N/A | 9.8 CRITICAL |
| pdf-image (npm package) through version 2.0.0 allows OS command injection via the pdfFilePath parameter. The constructGetInfoCommand and constructConvertCommandForPage functions use util.format() to interpolate user-controlled file paths into shell command strings that are executed via child_process.exec() | |||||
| CVE-2026-26829 | 2026-06-17 | N/A | 7.5 HIGH | ||
| A NULL pointer dereference in the safe_atou64 function (src/misc.c) of owntone-server through commit c4d57aa allows attackers to cause a Denial of Service (DoS) via sending a series of crafted HTTP requests to the server. | |||||
| CVE-2026-26828 | 2026-06-17 | N/A | 7.5 HIGH | ||
| A NULL pointer dereference in the daap_reply_playlists function (src/httpd_daap.c) of owntone-server commit 3d1652d allows attackers to cause a Denial of Service (DoS) via sending a crafted DAAP request to the server | |||||
| CVE-2026-26801 | 1 Pdfmake | 1 Pdfmake | 2026-06-17 | N/A | 7.5 HIGH |
| Server-Side Request Forgery (SSRF) vulnerability in pdfmake versions 0.3.0-beta.2 through 0.3.5 allows a remote attacker to obtain sensitive information via the src/URLResolver.js component. The fix was released in version 0.3.6 which introduces the setUrlAccessPolicy() method allowing server operators to define URL access rules. A warning is now logged when pdfmake is used server-side without a policy configured. | |||||
| CVE-2026-26795 | 1 Gl-inet | 2 Ar300m16, Ar300m16 Firmware | 2026-06-17 | N/A | 9.8 CRITICAL |
| GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a command injection vulnerability via the module parameter in the M.get_system_log function. This vulnerability allows attackers to execute arbitrary commands via a crafted input. | |||||
| CVE-2026-26794 | 1 Gl-inet | 2 Ar300m16, Ar300m16 Firmware | 2026-06-17 | N/A | 8.8 HIGH |
| GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a SQL injection vulnerability via the add_group() function. This vulnerability allows attackers to execute arbitrary SQL database operations via a crafted HTTP request. | |||||
| CVE-2026-26793 | 1 Gl-inet | 2 Ar300m16, Ar300m16 Firmware | 2026-06-17 | N/A | 9.8 CRITICAL |
| GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a command injection vulnerability via the set_config function. This vulnerability allows attackers to execute arbitrary commands via a crafted input. | |||||
| CVE-2026-26792 | 1 Gl-inet | 2 Ar300m16, Ar300m16 Firmware | 2026-06-17 | N/A | 9.8 CRITICAL |
| GL-iNet GL-AR300M16 v4.3.11 was discovered to contain multiple command injection vulnerabilities in the set_upgrade function via the modem_url, target_version, current_version, firmware_upload, hash_type, hash_value, and upgrade_type parameters. These vulnerabilities allow attackers to execute arbitrary commands via a crafted input. | |||||
| CVE-2026-26791 | 1 Gl-inet | 2 Ar300m16, Ar300m16 Firmware | 2026-06-17 | N/A | 9.8 CRITICAL |
| GL-iNet GL-AR300M16 v4.3.11 was discovered to contain a command injection vulnerability via the string port parameter in the enable_echo_server function. This vulnerability allows attackers to execute arbitrary commands via a crafted input. | |||||
| CVE-2026-26747 | 1 Monicahq | 1 Monica | 2026-06-17 | N/A | 9.1 CRITICAL |
| A Host Header Poisoning vulnerability exists in Monica 4.1.2 due to improper handling of the HTTP Host header in app/Providers/AppServiceProvider.php, combined with the default misconfiguration where the "app.force_url" is not set and default is "false". The application generates absolute URLs (such as those used in password reset emails) using the user-supplied Host header. This allows remote attackers to poison the password reset link sent to a victim, | |||||
| CVE-2026-26746 | 1 Opensourcepos | 1 Open Source Point Of Sale | 2026-06-17 | N/A | 8.8 HIGH |
| OpenSourcePOS 3.4.1 contains a Local File Inclusion (LFI) vulnerability in the Sales.php::getInvoice() function. An attacker can read arbitrary files on the web server by manipulating the Invoice Type configuration. This issue can be chained with the file upload functionality to achieve Remote Code Execution (RCE). | |||||
| CVE-2026-26745 | 1 Opensourcepos | 1 Open Source Point Of Sale | 2026-06-17 | N/A | 5.3 MEDIUM |
| OpenSourcePOS 3.4.1 has a second order SQL Injection vulnerability in the handling of the currency_symbol configuration field. Although the input is initially stored without immediate execution, it is later concatenated into a dynamically constructed SQL query without proper sanitization or parameter binding. This allows an attacker with access to modify the currency_symbol value to inject arbitrary SQL expressions, which are executed when the affected query is subsequently processed. | |||||
