|
751
|
7.5 |
HIGH
Network
|
-
|
-
|
When OIDC authentication is enabled in configuration, clients may set specific values in the "mechanism" parameter of the "authenticate" command that lead to server crash. The authenticate command is…
Update
|
CWE-1287
Improper Validation of Specified Type of Input
|
CVE-2026-9742
|
2026-06-11 04:43 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
752
|
6.5 |
MEDIUM
Network
|
-
|
-
|
In MongoDB Server 8.0, an aggregation stage can leave its _subPipeline field null during processing of certain pipelines. If a getMore is subsequently issued on the same cursor, the server may derefe…
Update
|
CWE-476
NULL Pointer Dereference
|
CVE-2026-9743
|
2026-06-11 04:43 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
753
|
6.5 |
MEDIUM
Network
|
-
|
-
|
When using $changestreams and $_requestReshardingResumeToken with the exchange option the server hits an invariant which causes the server to crash. There are no special privileges needed. The user m…
Update
|
CWE-617
Reachable Assertion
|
CVE-2026-9746
|
2026-06-11 04:43 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
754
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Adding fromRouter:true and runtimeConstants.userRoles could cause aggregations to crash mongodb server.
Update
|
CWE-617
Reachable Assertion
|
CVE-2026-9747
|
2026-06-11 04:43 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
755
|
6.5 |
MEDIUM
Network
|
-
|
-
|
The $_internalConvertBucketIndexStats stage used PauseExecution as a way to signal "skip this document" when an index stats conversion failed. But PauseExecution is not a general purpose skip mechani…
Update
|
CWE-617
Reachable Assertion
|
CVE-2026-9748
|
2026-06-11 04:43 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
756
|
6.5 |
MEDIUM
Network
|
-
|
-
|
This issue can occur when running an aggregation pipeline that uses the internal $exchange stage configured with key-range partitioning and order-preserving delivery. If a single key range produces e…
Update
|
CWE-617
Reachable Assertion
|
CVE-2026-9749
|
2026-06-11 04:43 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
757
|
6.5 |
MEDIUM
Network
|
-
|
-
|
An authenticated user can cause a MongoDB server to crash or return incorrect results by creating documents that interfere with internal metadata processing during query execution. This stems from in…
Update
|
CWE-617
Reachable Assertion
|
CVE-2026-9750
|
2026-06-11 04:43 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
758
|
5.5 |
MEDIUM
Local
|
-
|
-
|
The ldapQueryPassword parameter, when set through the runtime setParameter command, will log the new password to the mongod.log file in plain text.
Update
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2026-9751
|
2026-06-11 04:43 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
759
|
6.5 |
MEDIUM
Network
|
-
|
-
|
An authorized user could trigger a server crash by running a query with a 2dsphere index on a field that stores a GeoJSON GeometryCollection containing a Polygon with a strict-winding CRS.
Strict-wi…
Update
|
CWE-476
NULL Pointer Dereference
|
CVE-2026-9752
|
2026-06-11 04:43 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
760
|
8.1 |
HIGH
Network
|
-
|
-
|
The $_internalApplyOplogUpdate aggregation pipeline stage can be used to execute a document diff containing a malformed binary diff to return memory out-of-bounds or crash the server. $_internalApply…
Update
|
CWE-1287
Improper Validation of Specified Type of Input
|
CVE-2026-9753
|
2026-06-11 04:43 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
761
|
6.5 |
MEDIUM
Network
|
-
|
-
|
An authenticated user with the read role may read limited amounts of uninitialized stack memory via specially-crafted issuances of the filemd5 command
Update
|
CWE-457
Use of Uninitialized Variable
|
CVE-2026-9754
|
2026-06-11 04:43 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
762
|
5.4 |
MEDIUM
Network
|
microsoft
|
sharepoint_server
|
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
Update
|
CWE-79
Cross-site Scripting
|
CVE-2026-45479
|
2026-06-11 04:42 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
763
|
6.1 |
MEDIUM
Network
|
-
|
-
|
Ellucian Banner Self-Service before the April T2 release (2025-04-23) contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to execute arbitrary JavaScript in …
Update
|
CWE-79
Cross-site Scripting
|
CVE-2026-32856
|
2026-06-11 04:41 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
764
|
5.4 |
MEDIUM
Network
|
-
|
-
|
Evoluted PHP Directory Listing Script through 4.0.5 contains a reflected cross-site scripting vulnerability in index.php where the dir parameter value is reflected without HTML encoding inside the HT…
Update
|
CWE-79
Cross-site Scripting
|
CVE-2026-25557
|
2026-06-11 04:41 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
765
|
6.1 |
MEDIUM
Network
|
-
|
-
|
OSCAL-GUI contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to execute arbitrary JavaScript in a victim's browser by injecting malicious input through the …
Update
|
CWE-79
Cross-site Scripting
|
CVE-2026-34416
|
2026-06-11 04:41 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
766
|
6.1 |
MEDIUM
Network
|
-
|
-
|
OpenClinic GA 5.351.19 contains a reflected cross-site scripting vulnerability in the DICOM image upload handler that allows attackers to execute arbitrary JavaScript in a victim's browser by embeddi…
Update
|
CWE-79
Cross-site Scripting
|
CVE-2026-25860
|
2026-06-11 04:41 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
767
|
6.1 |
MEDIUM
Network
|
-
|
-
|
OSCAL-GUI contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to execute arbitrary JavaScript in a victim's browser by injecting malicious content through th…
Update
|
CWE-79
Cross-site Scripting
|
CVE-2026-34417
|
2026-06-11 04:41 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
768
|
7.8 |
HIGH
Local
|
microsoft
|
windows_10_1809 windows_10_21h2 windows_10_22h2 windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2019 windows_server_2022 windows_server_2025
|
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.
Update
|
CWE-362 CWE-416
Race Condition Use After Free
|
CVE-2026-42978
|
2026-06-11 04:38 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
769
|
7.0 |
HIGH
Local
|
microsoft
|
windows_10_1809 windows_10_21h2 windows_10_22h2 windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2019 windows_server_2022 windows_server_2025
|
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
Update
|
CWE-416
Use After Free
|
CVE-2026-42984
|
2026-06-11 04:37 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
770
|
7.5 |
HIGH
Network
|
apache f5 debian
|
http_server nginx debian_linux
|
Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service via malicious HTTP requests.
This issue affects Apache HTTP Server: from 2.4.17 …
Update
|
CWE-789
Memory Allocation with Excessive Size Value
|
CVE-2026-49975
|
2026-06-11 04:36 |
2026-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
771
|
7.3 |
HIGH
Network
|
apache
|
http_server
|
Use After Free vulnerability in Apache HTTP Server module mod_http2 when file handles are already exhausted.
This issue affects Apache HTTP Server: from 2.4.55 through 2.4.67.
Update
|
CWE-416
Use After Free
|
CVE-2026-48913
|
2026-06-11 04:31 |
2026-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
772
|
8.8 |
HIGH
Network
|
hcltech
|
digital_experience digital_experience_compose
|
HCL Digital Experience is affected by an OS command injection vulnerability in the Digital Asset Management API. An attacker may execute arbitrary operating system commands, typically inheriting the…
Update
|
CWE-78
OS Command
|
CVE-2026-21837
|
2026-06-11 04:25 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
773
|
6.1 |
MEDIUM
Network
|
hcltech
|
digital_experience_compose digital_experience
|
HCL Digital Experience and HCL Digital Experience Compose could be susceptible to Host header injection. An attacker can manipulate the Host header and cause the application to behave in unexpected …
Update
|
CWE-601
Open Redirect
|
CVE-2026-21826
|
2026-06-11 04:24 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
774
|
6.1 |
MEDIUM
Network
|
hcltech
|
digital_experience_compose digital_experience
|
HCL Digital Experience Compose is affected by a reflected cross-site scripting (XSS) vulnerability in the search center. An attacker could execute arbitrary JavaScript in the victim's browser.
Update
|
CWE-79
Cross-site Scripting
|
CVE-2026-21825
|
2026-06-11 04:24 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
775
|
8.8 |
HIGH
Network
|
google
|
chrome
|
Out of bounds read in DevTools in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)
Update
|
CWE-125
Out-of-bounds Read
|
CVE-2026-11279
|
2026-06-11 04:22 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
776
|
6.5 |
MEDIUM
Network
|
google
|
chrome
|
Inappropriate implementation in CustomTabs in Google Chrome on Android prior to 149.0.7827.53 allowed a local attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: …
Update
|
CWE-346
Origin Validation Error
|
CVE-2026-11278
|
2026-06-11 04:19 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
777
|
- |
-
|
-
|
-
|
bz2.BZ2Decompressor objects could be reused after a decompression error. If an application caught the resulting OSError and retried with the same decompressor, crafted input could cause the decompres…
Update
|
CWE-121
Stack-based Buffer Overflow
|
CVE-2026-9669
|
2026-06-11 04:16 |
2026-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
778
|
- |
-
|
-
|
-
|
An unauthenticated user on the local network can gain control of the router and make unauthorized changes to its operation.
Update
|
CWE-20
Improper Input Validation
|
CVE-2026-9211
|
2026-06-11 04:16 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
779
|
- |
-
|
-
|
-
|
Insufficient input validation vulnerability in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification of router software and fu…
Update
|
CWE-20
Improper Input Validation
|
CVE-2026-9210
|
2026-06-11 04:16 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
780
|
7.5 |
HIGH
Network
|
securly
|
securly
|
Version 3.0.7 of the Securly Chrome Extension uses deprecated SHA-1 hashing for IWF CSAM URL matching (25,020 hashes) and CIPA blocklist matching (12,352 hashes).
Update
|
CWE-407
Inefficient Algorithmic Complexity
|
CVE-2026-8889
|
2026-06-11 04:16 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
781
|
- |
-
|
-
|
-
|
tarfile.data_filter could be bypassed using crafted link entries, including symlinks with empty or directory-like names, to redirect later archive members outside the intended extraction directory. T…
Update
|
CWE-22
Path Traversal
|
CVE-2026-7774
|
2026-06-11 04:16 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
782
|
- |
-
|
-
|
-
|
Unauthenticated users on the local network can cause the router to become unavailable by sending specially crafted requests.
Update
|
CWE-787
Out-of-bounds Write
|
CVE-2026-3088
|
2026-06-11 04:16 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
783
|
7.5 |
HIGH
Network
|
-
|
-
|
Shenzhen Tenda Technology Co., Ltd Tenda G0 v15.11.0.5 was discovered to contain a buffer overflow in the IPMacBindIndex parameter of the formIPMacBindDel function. This vulnerability allows attacker…
Update
|
CWE-120
Classic Buffer Overflow
|
CVE-2026-36800
|
2026-06-11 04:16 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
784
|
7.5 |
HIGH
Network
|
-
|
-
|
Shenzhen Tenda Technology Co., Ltd Tenda W3 Wireless Router v1.0.0.3(2204) was discovered to contain a stack overflow in the wl_radio parameter of the formWifiRadioSet function. This vulnerability al…
Update
|
CWE-121
Stack-based Buffer Overflow
|
CVE-2026-36792
|
2026-06-11 04:16 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
785
|
7.5 |
HIGH
Network
|
-
|
-
|
Shenzhen Tenda Technology Co., Ltd Tenda O3 Wireless Router v1.0.0.5(4180) was discovered to contain a stack overflow in the ip parameter of the fromNetToolGet function. This vulnerability allows att…
Update
|
CWE-121
Stack-based Buffer Overflow
|
CVE-2026-36784
|
2026-06-11 04:16 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
786
|
7.5 |
HIGH
Network
|
-
|
-
|
Shenzhen Tenda Technology Co., Ltd Tenda O3 Wireless Router v1.0.0.5(4180) was discovered to contain multiple stack overflows in the fromVirtualSer function via the puVar2, puVar1, __s2, __s1_00, and…
Update
|
CWE-121
Stack-based Buffer Overflow
|
CVE-2026-36779
|
2026-06-11 04:16 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
787
|
9.1 |
CRITICAL
Network
|
-
|
-
|
An insecure authentication vulnerability in the /api/social-sign-in endpoint of bookcars v8.3 allows attackers to bypass authentication via a forged JWT token.
Update
|
CWE-287
Improper Authentication
|
CVE-2026-36727
|
2026-06-11 04:16 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
788
|
5.4 |
MEDIUM
Network
|
google
|
chrome
|
Inappropriate implementation in TabGroups in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform UI spoofing via malicious network traffic. (Chromium security severity: Low)
Update
|
CWE-451
User Interface (UI) Misrepresentation of Critical Information
|
CVE-2026-11232
|
2026-06-11 04:11 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
789
|
8.8 |
HIGH
Network
|
google
|
chrome
|
Use after free in Extensions in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)
Update
|
CWE-416
Use After Free
|
CVE-2026-11230
|
2026-06-11 04:09 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
790
|
6.1 |
MEDIUM
Physics
|
google
|
chrome
|
Inappropriate implementation in Enterprise in Google Chrome prior to 149.0.7827.53 allowed a local attacker to perform privilege escalation via physical access to the device. (Chromium security sever…
Update
|
CWE-269
Improper Privilege Management
|
CVE-2026-11229
|
2026-06-11 04:09 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
791
|
8.8 |
HIGH
Network
|
-
|
-
|
In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, Splunk Cloud Platform versions below 10.3.2512.12, 10.2.2510.14, 10.1.2507.22, and 9.3.2411.132, and Splunk Secure Gateway vers…
New
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-20251
|
2026-06-11 03:36 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
792
|
7.6 |
HIGH
Network
|
-
|
-
|
In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, and Splunk Cloud Platform versions below 10.4.2604.3, 10.3.2512.12, 10.2.2510.14, 10.1.2507.22, and 9.3.2411.132, a low-privile…
New
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-20252
|
2026-06-11 03:36 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
793
|
9.8 |
CRITICAL
Network
|
-
|
-
|
In Splunk Enterprise versions below 10.2.4 and 10.0.7, and Splunk Cloud Platform versions below 10.4.2604.3 and 10.2.2510.14, an unauthenticated user could create or truncate arbitrary files through …
New
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2026-20253
|
2026-06-11 03:36 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
794
|
5.7 |
MEDIUM
Network
|
-
|
-
|
In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, and Splunk Cloud Platform versions below 10.3.2512.13, 10.2.2510.15, 10.1.2507.23, and 9.3.2411.132, a low-privileged user that…
New
|
CWE-20
Improper Input Validation
|
CVE-2026-20255
|
2026-06-11 03:36 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
795
|
7.1 |
HIGH
Network
|
-
|
-
|
In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, and Splunk Cloud Platform versions below 10.3.2512.11, 10.2.2510.15, 10.1.2507.23, and 9.3.2411.132, a low-privileged user that…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-20258
|
2026-06-11 03:36 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
796
|
5.5 |
MEDIUM
Network
|
-
|
-
|
In Splunk Enterprise versions below 10.2.4 and 10.0.7, and Splunk Cloud Platform versions below 10.4.2604.0, 10.3.2512.12, 10.2.2510.15, 10.1.2507.23, 10.0.2503.14, and 9.3.2411.131, a user who holds…
New
|
CWE-284
Improper Access Control
|
CVE-2026-20259
|
2026-06-11 03:36 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
797
|
4.3 |
MEDIUM
Network
|
-
|
-
|
In Splunk SOAR (Security Orchestration, Automation, and Response) versions below 8.5.0, an unauthenticated attacker could inject American National Standards Institute (ANSI) escape codes into SOAR ap…
New
|
CWE-117
Improper Output Neutralization for Logs
|
CVE-2026-20260
|
2026-06-11 03:36 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
798
|
5.7 |
MEDIUM
Network
|
-
|
-
|
In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, and Splunk Cloud Platform versions below 10.3.2512.13, 10.2.2510.15, 10.1.2507.23, and 9.3.2411.132, a low-privileged user that…
New
|
CWE-20
Improper Input Validation
|
CVE-2026-20254
|
2026-06-11 03:36 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
799
|
5.7 |
MEDIUM
Network
|
-
|
-
|
In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, and Splunk Cloud Platform versions below 10.3.2512.13, 10.2.2510.15, 10.1.2507.23, and 9.3.2411.132, a low-privileged user that…
New
|
CWE-20
Improper Input Validation
|
CVE-2026-20256
|
2026-06-11 03:36 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
800
|
5.7 |
MEDIUM
Network
|
-
|
-
|
In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, and Splunk Cloud Platform versions below 10.3.2512.13, 10.2.2510.15, 10.1.2507.23, and 9.3.2411.132, a low-privileged user that…
New
|
CWE-20
Improper Input Validation
|
CVE-2026-20257
|
2026-06-11 03:36 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|