|
51
|
7.8 |
HIGH
Local
|
microsoft
|
365_apps excel microsoft_365 office_2019 office_2021 office_2024 office_online_server
|
Integer underflow (wrap or wraparound) in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
New
|
CWE-125
Out-of-bounds Read
|
CVE-2026-44820
|
2026-06-12 03:38 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
52
|
8.2 |
HIGH
Network
|
microsoft
|
365_apps excel microsoft_365 office_2019 office_2021 office_2024 office_online_server
|
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.
New
|
CWE-125
Out-of-bounds Read
|
CVE-2026-44822
|
2026-06-12 03:38 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
53
|
3.3 |
LOW
Local
|
microsoft
|
365_apps microsoft_365 office_2021 office_2024
|
Protection mechanism failure in Microsoft Office Excel allows an unauthorized attacker to bypass a security feature locally.
New
|
CWE-693
Protection Mechanism Failure
|
CVE-2026-45459
|
2026-06-12 03:38 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
54
|
7.8 |
HIGH
Local
|
microsoft
|
365_apps excel microsoft_365 office_2019 office_2021 office_2024 office_online_server
|
Integer underflow (wrap or wraparound) in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
New
|
CWE-122 CWE-191
Heap-based Buffer Overflow Integer Underflow (Wrap or Wraparound)
|
CVE-2026-45469
|
2026-06-12 03:37 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
55
|
3.3 |
LOW
Local
|
microsoft
|
365_apps microsoft_365 office_2016 office_2019 office_2021 office_2024 sharepoint_server
|
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
New
|
CWE-125
Out-of-bounds Read
|
CVE-2026-45485
|
2026-06-12 03:37 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
56
|
7.8 |
HIGH
Local
|
microsoft
|
windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2016 windows_server_2019 w…
|
Out-of-bounds read in Windows Hyper-V allows an unauthorized attacker to execute code locally.
New
|
CWE-125
Out-of-bounds Read
|
CVE-2026-45607
|
2026-06-12 03:37 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
57
|
7.8 |
HIGH
Local
|
microsoft
|
365_apps microsoft_365 office_2021 office_2024
|
Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally.
New
|
CWE-416
Use After Free
|
CVE-2026-45486
|
2026-06-12 03:37 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
58
|
7.8 |
HIGH
Local
|
microsoft
|
365_apps microsoft_365 office_2021 office_2024
|
Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally.
New
|
CWE-822
Untrusted Pointer Dereference
|
CVE-2026-45643
|
2026-06-12 03:37 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
59
|
7.8 |
HIGH
Local
|
x.org redhat
|
x_server xwayland enterprise_linux
|
A use-after-free flaw was found in the X.Org X server and Xwayland in FreeCounter(). A client that sets up multiple SyncCounters and awaits on those triggers can trigger a use-after-free when destroy…
Update
|
CWE-416
Use After Free
|
CVE-2026-50260
|
2026-06-12 03:36 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
60
|
8.4 |
HIGH
Local
|
microsoft
|
office_2024
|
Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.
New
|
CWE-122
Heap-based Buffer Overflow
|
CVE-2026-47635
|
2026-06-12 03:36 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
61
|
8.1 |
HIGH
Network
|
microsoft
|
windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2012 windows_server_2016 w…
|
Use after free in Universal Plug and Play (upnp.dll) allows an unauthorized attacker to execute code over a network.
New
|
CWE-843 CWE-416
Type Confusion Use After Free
|
CVE-2026-45635
|
2026-06-12 03:36 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
62
|
7.8 |
HIGH
Local
|
microsoft
|
windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2012 windows_server_2016 w…
|
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.
New
|
CWE-20 CWE-122
Improper Input Validation Heap-based Buffer Overflow
|
CVE-2026-45636
|
2026-06-12 03:33 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
63
|
6.5 |
MEDIUM
Adjacent
|
lldpd_project
|
lldpd
|
lldpd is an implementation of IEEE 802.1ab (LLDP). Prior to version 1.0.22, lldpd_decode() in src/daemon/lldpd.c strips 802.1Q VLAN tags from received Ethernet frames by calling memmove() to shift th…
New
|
CWE-125
Out-of-bounds Read
|
CVE-2026-46433
|
2026-06-12 03:29 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
64
|
7.8 |
HIGH
Local
|
microsoft
|
windows_10_1809 windows_10_21h2 windows_10_22h2 windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2019 windows_server_2022 windows_server_2025
|
Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
New
|
CWE-416
Use After Free
|
CVE-2026-45637
|
2026-06-12 03:24 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
65
|
7.8 |
HIGH
Local
|
microsoft
|
windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2012 windows_server_2016 w…
|
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
New
|
CWE-122
Heap-based Buffer Overflow
|
CVE-2026-45638
|
2026-06-12 03:23 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
66
|
8.7 |
HIGH
Network
|
open-emr
|
openemr
|
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.1, a stored cross-site scripting vulnerability in the prescription CSS/…
New
|
CWE-79 CWE-862
Cross-site Scripting Missing Authorization
|
CVE-2026-46518
|
2026-06-12 03:23 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
67
|
7.0 |
HIGH
Local
|
microsoft
|
windows_10_21h2 windows_10_22h2 windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2022 windows_server_2025
|
Use after free in Windows Bluetooth Port Driver allows an authorized attacker to elevate privileges locally.
New
|
CWE-416
Use After Free
|
CVE-2026-45640
|
2026-06-12 03:22 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
68
|
6.5 |
MEDIUM
Adjacent
|
espressif
|
esp-idf
|
ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.2.7, 5.3.5, 5.4.4, 5.5.4, and 6.0.1, an out-of-bounds read flaw exists in the DHCP server option parser (parse_o…
New
|
CWE-125
Out-of-bounds Read
|
CVE-2026-45160
|
2026-06-12 03:22 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
69
|
10.0 |
CRITICAL
Network
|
-
|
-
|
MariaDB server is a community developed fork of MySQL server. Versions 10.6.1 through 10.6.26, 10.11.1 through 10.11.17, 11.4.1 through 11.4.11, 11.8.1 through 11.8.7, and 12.3.1 with `wsrep_notify_…
New
|
CWE-78
OS Command
|
CVE-2026-49261
|
2026-06-12 03:16 |
2026-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
70
|
7.3 |
HIGH
Network
|
-
|
-
|
KanaDojo before 0.1.18 contains a sandbox escape vulnerability that allows an attacker to execute arbitrary code by exploiting the explicit passing of the global require function into a Node.js vm.ru…
New
|
CWE-693
Protection Mechanism Failure
|
CVE-2026-48546
|
2026-06-12 03:16 |
2026-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
71
|
6.5 |
MEDIUM
Adjacent
|
-
|
-
|
aiograpi is an asynchronous Instagram API for Python. aiograpi versions before 0.9.10 accepted server-supplied signup challenge paths and used them to build request URLs before validating that the pa…
New
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-47157
|
2026-06-12 03:16 |
2026-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
72
|
5.3 |
MEDIUM
Network
|
-
|
-
|
Fediverse Embeds embeds fediverse posts on WordPress sites. Prior to version 1.5.9, Fediverse Embeds registered the unauthenticated AJAX action wp_ajax_nopriv_ftf_get_site_info (includes/Site_Info.ph…
New
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-46698
|
2026-06-12 03:16 |
2026-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
73
|
7.5 |
HIGH
Network
|
-
|
-
|
Fediverse Embeds embeds fediverse posts on WordPress sites. Prior to version 1.5.8, Fediverse Embeds registered an unauthenticated REST route ftf/media-proxy (includes/Media_Proxy.php) with permissio…
New
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-46697
|
2026-06-12 03:16 |
2026-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
74
|
7.5 |
HIGH
Network
|
-
|
-
|
Axios is a promise based HTTP client for the browser and Node.js. Axios versions before 0.32.0 on the 0.x line and before 1.16.0 on the 1.x line build a regular expression from the configured XSRF co…
New
|
CWE-400 CWE-1333
Uncontrolled Resource Consumption Inefficient Regular Expression Complexity
|
CVE-2026-44496
|
2026-06-12 03:16 |
2026-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
75
|
8.7 |
HIGH
Network
|
-
|
-
|
Axios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.16.0, the Axios library is vulnerable to a Prototype Pollution "Gadget" attack that allows any Object.prototyp…
New
|
CWE-441 CWE-1321
Confused Deputy Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
|
CVE-2026-44494
|
2026-06-12 03:16 |
2026-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
76
|
4.8 |
MEDIUM
Network
|
-
|
-
|
Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, axios exposes two read-side prototype-pollution gadgets. When Object.prototype is polluted by an upstream…
New
|
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
|
CVE-2026-44490
|
2026-06-12 03:16 |
2026-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
77
|
- |
-
|
-
|
-
|
A remote unauthenticated attacker may be able to conduct credential-guessing attacks against user accounts in Sonatype Nexus Repository via authentication endpoints.
New
|
CWE-307
mproper Restriction of Excessive Authentication Attempts
|
CVE-2026-3329
|
2026-06-12 03:16 |
2026-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
78
|
4.9 |
MEDIUM
Network
|
-
|
-
|
A flaw was found in the admin-ui-ext component of Keycloak, which provides extended administrative user interface capabilities. The issue occurs because certain bulk role-removal endpoints fail to pe…
New
|
CWE-425
Direct Request ('Forced Browsing')
|
CVE-2026-11986
|
2026-06-12 03:16 |
2026-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
79
|
8.8 |
HIGH
Local
|
espressif
|
esp-idf
|
ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.4 and 6.0, the esp_tee component exposes secure-service wrappers in esp_secure_services.c and esp_secure_servi…
New
|
CWE-20 CWE-787
Improper Input Validation Out-of-bounds Write
|
CVE-2026-45328
|
2026-06-12 03:15 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
80
|
7.5 |
HIGH
Network
|
espressif
|
esp-idf
|
ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.2.6, 5.3.5, 5.4.4, 5.5.4, and 6.0, a NULL-pointer dereference exists in the WebSocket subprotocol-negotiation pa…
New
|
CWE-476
NULL Pointer Dereference
|
CVE-2026-45541
|
2026-06-12 03:05 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
81
|
6.5 |
MEDIUM
Local
|
espressif
|
esp-idf
|
ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.4 and 6.0, several ESP-TEE secure-service wrappers in esp_secure_services.c and esp_secure_services_iram.c val…
New
|
CWE-20 CWE-125 CWE-200
Improper Input Validation Out-of-bounds Read Information Exposure
|
CVE-2026-45329
|
2026-06-12 03:04 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
82
|
6.5 |
MEDIUM
Network
|
7-zip
|
7-zip
|
7-Zip is a file archiver with a high compression ratio. Versions 9.21 through 26.00 contain an An uninitialized memory disclosure vulnerability in the UEFI capsule (.scap) parser in 7-Zip. The OpenCa…
Update
|
CWE-908
Use of Uninitialized Resource
|
CVE-2026-48101
|
2026-06-12 03:02 |
2026-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
83
|
7.8 |
HIGH
Local
|
microsoft
|
windows_10_21h2 windows_10_22h2 windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2022 windows_server_2025
|
Out-of-bounds read in Windows Hyper-V allows an unauthorized attacker to execute code locally.
New
|
CWE-843 CWE-125
Type Confusion Out-of-bounds Read
|
CVE-2026-45641
|
2026-06-12 02:42 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
84
|
7.1 |
HIGH
Adjacent
|
espressif
|
esp-idf
|
ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.2.6, 5.3.5, 5.4.4, 5.5.4, and 6.0, a heap buffer overflow exists in the Security Scheme 2 (SRP6a) session-setup …
New
|
CWE-122
Heap-based Buffer Overflow
|
CVE-2026-45542
|
2026-06-12 02:41 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
85
|
3.9 |
LOW
Physics
|
microsoft
|
windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2012 windows_server_2016 w…
|
Improper input validation in Microsoft Azure Attestation service and Device Health Attestation Service allows an authorized attacker to perform spoofing with a physical attack.
New
|
CWE-20
Improper Input Validation
|
CVE-2026-45642
|
2026-06-12 02:39 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
86
|
4.3 |
MEDIUM
Network
|
gitlab
|
gitlab
|
GitLab has remediated an issue in GitLab EE affecting all versions from 13.9 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions could have allowed an authentic…
New
|
CWE-863
Incorrect Authorization
|
CVE-2026-6277
|
2026-06-12 02:36 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
87
|
8.7 |
HIGH
Network
|
gitlab
|
gitlab
|
GitLab has remediated an issue in GitLab EE affecting all versions from 15.5 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions could have allowed an authentic…
New
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-6552
|
2026-06-12 02:36 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
88
|
4.6 |
MEDIUM
Adjacent
|
espressif
|
esp-idf
|
ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.2.6, 5.3.5, 5.4.4, 5.5.3, and 6.0, an out-of-bounds read exists in the BlueDroid AVRCP vendor-command parser (av…
New
|
CWE-125
Out-of-bounds Read
|
CVE-2026-46532
|
2026-06-12 02:36 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
89
|
9.8 |
CRITICAL
Network
|
microsoft
|
windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2012 windows_server_2016 w…
|
Stack-based buffer overflow in Windows DHCP Client allows an unauthorized attacker to execute code over a network.
New
|
CWE-121
Stack-based Buffer Overflow
|
CVE-2026-44815
|
2026-06-12 02:35 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
90
|
3.7 |
LOW
Network
|
gitlab
|
gitlab
|
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.9 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions could have allowed an authen…
New
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-6976
|
2026-06-12 02:34 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
91
|
7.5 |
HIGH
Network
|
gitlab
|
gitlab
|
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.10 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions could have allowed an unaut…
New
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2026-7250
|
2026-06-12 02:34 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
92
|
4.3 |
MEDIUM
Network
|
gitlab
|
gitlab
|
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.9 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions, could have allowed an unaut…
New
|
CWE-153
Improper Neutralization of Substitution Characters
|
CVE-2026-9694
|
2026-06-12 02:32 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
93
|
6.1 |
MEDIUM
Network
|
adobe
|
experience_manager
|
Adobe Experience Manager Forms JEE versions LTS SP1, 6.5.24.0 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scr…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-34691
|
2026-06-12 02:29 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
94
|
6.5 |
MEDIUM
Network
|
gitlab
|
gitlab
|
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 18.10 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions could have allowed an authe…
New
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-9204
|
2026-06-12 02:28 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
95
|
8.7 |
HIGH
Network
|
gitlab
|
gitlab
|
GitLab has remediated an issue in GitLab EE affecting all versions from 13.1.4 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions could have allowed an authent…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-8589
|
2026-06-12 02:28 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
96
|
4.7 |
MEDIUM
Network
|
adobe
|
experience_manager
|
Adobe Experience Manager Forms JEE versions LTS SP1, 6.5.24.0 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this vulnerability to inject …
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-34693
|
2026-06-12 02:22 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
97
|
4.8 |
MEDIUM
Network
|
adobe
|
experience_manager
|
Adobe Experience Manager Forms JEE versions LTS SP1, 6.5.24.0 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to injec…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-34694
|
2026-06-12 02:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
98
|
9.1 |
CRITICAL
Network
|
-
|
-
|
The crypton-x509-validation Haskell library fails to enforce X.509 NameConstraints, allowing TLS clients to accept certificates whose Subject Alternative Names fall outside the issuing CA’s permitted…
New
|
-
|
CVE-2026-9648
|
2026-06-12 02:16 |
2026-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
99
|
8.1 |
HIGH
Network
|
-
|
-
|
Perry before 0.5.1159 contains a path traversal vulnerability that allows a malicious build server to write arbitrary content to any location writable by the running process by supplying unsanitized …
New
|
CWE-22
Path Traversal
|
CVE-2026-53777
|
2026-06-12 02:16 |
2026-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
100
|
8.2 |
HIGH
Network
|
-
|
-
|
tmp is a temporary file and directory creator for node.js. In version 0.2.6, the _assertPath guard added to tmp rejects only string values that contain the substring ... It is bypassed when prefix, p…
New
|
CWE-20 CWE-22
Improper Input Validation Path Traversal
|
CVE-2026-49982
|
2026-06-12 02:16 |
2026-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|