|
901
|
7.5 |
HIGH
Network
|
-
|
-
|
Shenzhen Tenda Technology Co., Ltd Tenda G0 v15.11.0.5 was discovered to contain a buffer overflow in the portalAuth parameter of the formPortalAuth function. This vulnerability allows attackers to c…
|
CWE-120
Classic Buffer Overflow
|
CVE-2026-36799
|
2026-06-11 05:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
902
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Shenzhen Tenda Technology Co., Ltd Tenda G0 v15.11.0.5 was discovered to contain multiple stack overflows in the formSetDebugCfgr function via the enable, level, and module parameters. These vulnerab…
|
CWE-121
Stack-based Buffer Overflow
|
CVE-2026-36798
|
2026-06-11 05:16 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
903
|
7.5 |
HIGH
Network
|
-
|
-
|
Shenzhen Tenda Technology Co., Ltd Tenda G0 v15.11.0.5 was discovered to contain a stack overflow in the IPMacBindRuleIp parameter of the formIPMacBindModify function. This vulnerability allows attac…
|
CWE-120
Classic Buffer Overflow
|
CVE-2026-36797
|
2026-06-11 05:16 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
904
|
7.5 |
HIGH
Network
|
-
|
-
|
Shenzhen Tenda Technology Co., Ltd Tenda G0 v15.11.0.5 was discovered to contain a stack overflow in the picCropName parameter of the formCropAndSetWewifiPic function. This vulnerability allows attac…
|
CWE-120
Classic Buffer Overflow
|
CVE-2026-36796
|
2026-06-11 05:16 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
905
|
7.5 |
HIGH
Network
|
-
|
-
|
Shenzhen Tenda Technology Co., Ltd Tenda O3 Wireless Router v1.0.0.5(4180) was discovered to contain a stack overflow in the domain parameter of the fromNetToolGet function. This vulnerability allows…
|
CWE-121
Stack-based Buffer Overflow
|
CVE-2026-36783
|
2026-06-11 05:16 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
906
|
9.8 |
CRITICAL
Network
|
-
|
-
|
An issue was discovered in bitbank2 AnimatedGIF v2.2.0. A buffer overflow in the DecodeLZW function allows remote attackers to cause a denial of service (crash) or potentially execute arbitrary code …
|
CWE-120
Classic Buffer Overflow
|
CVE-2026-30141
|
2026-06-11 05:16 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
907
|
6.5 |
MEDIUM
Network
|
-
|
-
|
An uncaught exception in the /application/job/update/{id} endpoint of FastapiAdmin v2.2.0 allows authenticated attackers with the module_task:job:update permission to cause a Denial of Service (DoS) …
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2026-36724
|
2026-06-11 05:15 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
908
|
6.1 |
MEDIUM
Network
|
-
|
-
|
A markdown based cross-site scripting (XSS) vulnerability in the /system/notice/create endpoint of FastapiAdmin v2.2.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafte…
|
CWE-79
Cross-site Scripting
|
CVE-2026-36725
|
2026-06-11 05:15 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
909
|
5.4 |
MEDIUM
Network
|
-
|
-
|
A markdown based cross-site scripting (XSS) vulnerability in the AI assistant chat function of FastapiAdmin v2.2.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted pa…
|
CWE-79
Cross-site Scripting
|
CVE-2026-36728
|
2026-06-11 05:15 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
910
|
- |
-
|
-
|
-
|
A flaw exists in the FlashArray Purity management interface where an authenticated low-privileged user may, under specific conditions, access functionality beyond their assigned privileges.
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-6444
|
2026-06-11 05:13 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
911
|
- |
-
|
-
|
-
|
A flaw exists in FlashArray Purity where insufficient filtering of certain data paths could expose sensitive information to an authenticated user with low privileges.
|
CWE-939
Improper Authorization in Handler for Custom URL Scheme
|
CVE-2026-6445
|
2026-06-11 05:13 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
912
|
- |
-
|
-
|
-
|
CleanWipe Removal Tool (macOS), prior to 16.0.0.65, may be susceptible to an Local Privilege Escalation vulnerability, which is a type of issue whereby an attacker with limited privilege access on an…
|
CWE-250
Execution with Unnecessary Privileges
|
CVE-2026-11626
|
2026-06-11 05:13 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
913
|
7.8 |
HIGH
Local
|
microsoft
|
windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2025
|
Access of resource using incompatible type ('type confusion') in Windows Kernel-Mode Drivers allows an authorized attacker to elevate privileges locally.
|
CWE-843
Type Confusion
|
CVE-2026-45600
|
2026-06-11 05:03 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
914
|
7.8 |
HIGH
Local
|
microsoft
|
windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2016 windows_server_2019 w…
|
Trust boundary violation in Windows Attestation allows an authorized attacker to elevate privileges locally.
|
CWE-501
Trust Boundary Violation
|
CVE-2026-33828
|
2026-06-11 05:00 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
915
|
7.0 |
HIGH
Local
|
microsoft
|
windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2012 windows_server_2016 w…
|
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
|
CWE-416
Use After Free
|
CVE-2026-34335
|
2026-06-11 04:59 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
916
|
7.8 |
HIGH
Local
|
microsoft
|
windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2012 windows_server_2016 w…
|
Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability
|
CWE-122 CWE-197
Heap-based Buffer Overflow Numeric Truncation Error
|
CVE-2026-40404
|
2026-06-11 04:58 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
917
|
7.8 |
HIGH
Local
|
microsoft
|
windows_10_1809 windows_10_21h2 windows_10_22h2 windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2019 windows_server_2022 windows_server_2025
|
Buffer over-read in Windows Projected File System Filter Driver allows an authorized attacker to elevate privileges locally.
|
CWE-126
Buffer Over-read
|
CVE-2026-42828
|
2026-06-11 04:56 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
918
|
5.5 |
MEDIUM
Local
|
microsoft
|
windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2012 windows_server_2016 w…
|
Exposure of sensitive information to an unauthorized actor in Windows Hyper-V allows an authorized attacker to disclose information locally.
|
CWE-200
Information Exposure
|
CVE-2026-42972
|
2026-06-11 04:55 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
919
|
5.5 |
MEDIUM
Local
|
microsoft
|
windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2016 windows_server_2019 w…
|
Use of uninitialized resource in Windows Push Notifications allows an authorized attacker to disclose information locally.
|
CWE-200
Information Exposure
|
CVE-2026-42973
|
2026-06-11 04:54 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
920
|
8.1 |
HIGH
Network
|
microsoft
|
windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2022 windows_server_2025
|
Integer underflow (wrap or wraparound) in Windows Performance Monitor allows an unauthorized attacker to execute code over a network.
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2026-42974
|
2026-06-11 04:53 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
921
|
7.8 |
HIGH
Local
|
microsoft
|
windows_10_1809 windows_10_21h2 windows_10_22h2 windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2019 windows_server_2022 windows_server_2025
|
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.
|
CWE-362
Race Condition
|
CVE-2026-42977
|
2026-06-11 04:49 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
922
|
5.5 |
MEDIUM
Local
|
-
|
-
|
MongoDB server may log authentication parameters, including credentials, to the server log during SASL authentication. When connection health metric logging is enabled, the full authentication parame…
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2026-9735
|
2026-06-11 04:43 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
923
|
7.5 |
HIGH
Network
|
-
|
-
|
A vulnerability in MongoDB Server's BSON validation logic allows an unauthenticated user to crash the mongod process by sending a specially crafted message. The BSON validator's handling of certain n…
|
CWE-674
Uncontrolled Recursion
|
CVE-2026-9740
|
2026-06-11 04:43 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
924
|
6.5 |
MEDIUM
Network
|
-
|
-
|
A bug in query analysis processing of the $vectorSearch aggregation stage for Queryable Encryption (QE) or Client-Side Field Level Encryption (CSFLE) results in literal values for encrypted fields w…
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2026-9741
|
2026-06-11 04:43 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
925
|
7.5 |
HIGH
Network
|
-
|
-
|
When OIDC authentication is enabled in configuration, clients may set specific values in the "mechanism" parameter of the "authenticate" command that lead to server crash. The authenticate command is…
|
CWE-1287
Improper Validation of Specified Type of Input
|
CVE-2026-9742
|
2026-06-11 04:43 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
926
|
6.5 |
MEDIUM
Network
|
-
|
-
|
In MongoDB Server 8.0, an aggregation stage can leave its _subPipeline field null during processing of certain pipelines. If a getMore is subsequently issued on the same cursor, the server may derefe…
|
CWE-476
NULL Pointer Dereference
|
CVE-2026-9743
|
2026-06-11 04:43 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
927
|
6.5 |
MEDIUM
Network
|
-
|
-
|
When using $changestreams and $_requestReshardingResumeToken with the exchange option the server hits an invariant which causes the server to crash. There are no special privileges needed. The user m…
|
CWE-617
Reachable Assertion
|
CVE-2026-9746
|
2026-06-11 04:43 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
928
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Adding fromRouter:true and runtimeConstants.userRoles could cause aggregations to crash mongodb server.
|
CWE-617
Reachable Assertion
|
CVE-2026-9747
|
2026-06-11 04:43 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
929
|
6.5 |
MEDIUM
Network
|
-
|
-
|
The $_internalConvertBucketIndexStats stage used PauseExecution as a way to signal "skip this document" when an index stats conversion failed. But PauseExecution is not a general purpose skip mechani…
|
CWE-617
Reachable Assertion
|
CVE-2026-9748
|
2026-06-11 04:43 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
930
|
6.5 |
MEDIUM
Network
|
-
|
-
|
This issue can occur when running an aggregation pipeline that uses the internal $exchange stage configured with key-range partitioning and order-preserving delivery. If a single key range produces e…
|
CWE-617
Reachable Assertion
|
CVE-2026-9749
|
2026-06-11 04:43 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
931
|
6.5 |
MEDIUM
Network
|
-
|
-
|
An authenticated user can cause a MongoDB server to crash or return incorrect results by creating documents that interfere with internal metadata processing during query execution. This stems from in…
|
CWE-617
Reachable Assertion
|
CVE-2026-9750
|
2026-06-11 04:43 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
932
|
6.5 |
MEDIUM
Network
|
-
|
-
|
An authorized user could trigger a server crash by running a query with a 2dsphere index on a field that stores a GeoJSON GeometryCollection containing a Polygon with a strict-winding CRS.
Strict-wi…
|
CWE-476
NULL Pointer Dereference
|
CVE-2026-9752
|
2026-06-11 04:43 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
933
|
8.1 |
HIGH
Network
|
-
|
-
|
The $_internalApplyOplogUpdate aggregation pipeline stage can be used to execute a document diff containing a malformed binary diff to return memory out-of-bounds or crash the server. $_internalApply…
|
CWE-1287
Improper Validation of Specified Type of Input
|
CVE-2026-9753
|
2026-06-11 04:43 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
934
|
6.5 |
MEDIUM
Network
|
-
|
-
|
An authenticated user with the read role may read limited amounts of uninitialized stack memory via specially-crafted issuances of the filemd5 command
|
CWE-457
Use of Uninitialized Variable
|
CVE-2026-9754
|
2026-06-11 04:43 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
935
|
5.4 |
MEDIUM
Network
|
microsoft
|
sharepoint_server
|
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
|
CWE-79
Cross-site Scripting
|
CVE-2026-45479
|
2026-06-11 04:42 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
936
|
6.1 |
MEDIUM
Network
|
-
|
-
|
Ellucian Banner Self-Service before the April T2 release (2025-04-23) contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to execute arbitrary JavaScript in …
|
CWE-79
Cross-site Scripting
|
CVE-2026-32856
|
2026-06-11 04:41 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
937
|
5.4 |
MEDIUM
Network
|
-
|
-
|
Evoluted PHP Directory Listing Script through 4.0.5 contains a reflected cross-site scripting vulnerability in index.php where the dir parameter value is reflected without HTML encoding inside the HT…
|
CWE-79
Cross-site Scripting
|
CVE-2026-25557
|
2026-06-11 04:41 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
938
|
6.1 |
MEDIUM
Network
|
-
|
-
|
OSCAL-GUI contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to execute arbitrary JavaScript in a victim's browser by injecting malicious input through the …
|
CWE-79
Cross-site Scripting
|
CVE-2026-34416
|
2026-06-11 04:41 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
939
|
6.1 |
MEDIUM
Network
|
-
|
-
|
OpenClinic GA 5.351.19 contains a reflected cross-site scripting vulnerability in the DICOM image upload handler that allows attackers to execute arbitrary JavaScript in a victim's browser by embeddi…
|
CWE-79
Cross-site Scripting
|
CVE-2026-25860
|
2026-06-11 04:41 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
940
|
6.1 |
MEDIUM
Network
|
-
|
-
|
OSCAL-GUI contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to execute arbitrary JavaScript in a victim's browser by injecting malicious content through th…
|
CWE-79
Cross-site Scripting
|
CVE-2026-34417
|
2026-06-11 04:41 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
941
|
7.8 |
HIGH
Local
|
microsoft
|
windows_10_1809 windows_10_21h2 windows_10_22h2 windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2019 windows_server_2022 windows_server_2025
|
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.
|
CWE-362 CWE-416
Race Condition Use After Free
|
CVE-2026-42978
|
2026-06-11 04:38 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
942
|
7.0 |
HIGH
Local
|
microsoft
|
windows_10_1809 windows_10_21h2 windows_10_22h2 windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2019 windows_server_2022 windows_server_2025
|
Use after free in Windows Kernel allows an authorized attacker to elevate privileges locally.
|
CWE-416
Use After Free
|
CVE-2026-42984
|
2026-06-11 04:37 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
943
|
7.5 |
HIGH
Network
|
apache f5 debian
|
http_server nginx debian_linux
|
Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service via malicious HTTP requests.
This issue affects Apache HTTP Server: from 2.4.17 …
|
CWE-789
Memory Allocation with Excessive Size Value
|
CVE-2026-49975
|
2026-06-11 04:36 |
2026-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
944
|
7.3 |
HIGH
Network
|
apache
|
http_server
|
Use After Free vulnerability in Apache HTTP Server module mod_http2 when file handles are already exhausted.
This issue affects Apache HTTP Server: from 2.4.55 through 2.4.67.
|
CWE-416
Use After Free
|
CVE-2026-48913
|
2026-06-11 04:31 |
2026-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
945
|
8.8 |
HIGH
Network
|
hcltech
|
digital_experience digital_experience_compose
|
HCL Digital Experience is affected by an OS command injection vulnerability in the Digital Asset Management API. An attacker may execute arbitrary operating system commands, typically inheriting the…
|
CWE-78
OS Command
|
CVE-2026-21837
|
2026-06-11 04:25 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
946
|
6.1 |
MEDIUM
Network
|
hcltech
|
digital_experience_compose digital_experience
|
HCL Digital Experience and HCL Digital Experience Compose could be susceptible to Host header injection. An attacker can manipulate the Host header and cause the application to behave in unexpected …
|
CWE-601
Open Redirect
|
CVE-2026-21826
|
2026-06-11 04:24 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
947
|
6.1 |
MEDIUM
Network
|
hcltech
|
digital_experience_compose digital_experience
|
HCL Digital Experience Compose is affected by a reflected cross-site scripting (XSS) vulnerability in the search center. An attacker could execute arbitrary JavaScript in the victim's browser.
|
CWE-79
Cross-site Scripting
|
CVE-2026-21825
|
2026-06-11 04:24 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
948
|
8.8 |
HIGH
Network
|
google
|
chrome
|
Out of bounds read in DevTools in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Low)
|
CWE-125
Out-of-bounds Read
|
CVE-2026-11279
|
2026-06-11 04:22 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
949
|
6.5 |
MEDIUM
Network
|
google
|
chrome
|
Inappropriate implementation in CustomTabs in Google Chrome on Android prior to 149.0.7827.53 allowed a local attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: …
|
CWE-346
Origin Validation Error
|
CVE-2026-11278
|
2026-06-11 04:19 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
950
|
- |
-
|
-
|
-
|
bz2.BZ2Decompressor objects could be reused after a decompression error. If an application caught the resulting OSError and retried with the same decompressor, crafted input could cause the decompres…
|
CWE-121
Stack-based Buffer Overflow
|
CVE-2026-9669
|
2026-06-11 04:16 |
2026-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|