|
1301
|
7.5 |
HIGH
Network
|
imagemagick
|
imagemagick
|
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2.23 and 6.9.13-48, due to a missing check in the MIFF decoder, a crafted file cou…
|
CWE-400 CWE-835
Uncontrolled Resource Consumption Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2026-46522
|
2026-06-12 03:41 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1302
|
7.5 |
HIGH
Network
|
imagemagick
|
imagemagick
|
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-23, when reading multiple images with different dimensions an out …
|
CWE-122 CWE-787
Heap-based Buffer Overflow Out-of-bounds Write
|
CVE-2026-46520
|
2026-06-12 03:41 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1303
|
5.3 |
MEDIUM
Network
|
imagemagick
|
imagemagick
|
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-47 and 7.1.2-22, because of a missing check in the MNG coder it would be possib…
|
CWE-400 CWE-407 CWE-674
Uncontrolled Resource Consumption Inefficient Algorithmic Complexity Uncontrolled Recursion
|
CVE-2026-45664
|
2026-06-12 03:41 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1304
|
5.1 |
MEDIUM
Local
|
imagemagick
|
imagemagick
|
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-47 and 7.1.2-22, when performing a polynomial distortion an out of bounds over-…
|
CWE-125 CWE-129
Out-of-bounds Read Improper Validation of Array Index
|
CVE-2026-45624
|
2026-06-12 03:41 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1305
|
5.7 |
MEDIUM
Local
|
imagemagick
|
imagemagick
|
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-22, an invalid connected-components:keep-top value could result in…
|
CWE-125 CWE-129
Out-of-bounds Read Improper Validation of Array Index
|
CVE-2026-45359
|
2026-06-12 03:41 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1306
|
5.3 |
MEDIUM
Network
|
imagemagick
|
imagemagick
|
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-47 and 7.1.2-22, an off by one in the meta encoder could result in an out of bo…
|
CWE-125 CWE-193
Out-of-bounds Read Off-by-one Error
|
CVE-2026-45358
|
2026-06-12 03:41 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1307
|
6.1 |
MEDIUM
Network
|
svelte
|
svelte
|
Svelte is a performance oriented web framework. Prior to version 5.55.7, when using spread syntax to render attributes from untrusted data, event handler properties are included in the rendered HTML …
|
CWE-79
Cross-site Scripting
|
CVE-2026-42599
|
2026-06-12 03:41 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1308
|
5.3 |
MEDIUM
Network
|
imagemagick
|
imagemagick
|
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-47 and 7.1.2-22, due to a missing check in the PSD decoder it would be possible…
|
CWE-400 CWE-770
Uncontrolled Resource Consumption Allocation of Resources Without Limits or Throttling
|
CVE-2026-45031
|
2026-06-12 03:41 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1309
|
5.1 |
MEDIUM
Local
|
imagemagick
|
imagemagick
|
ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-47 and 7.1.2-22, when writing an IPTC output file a malicious input file could …
|
CWE-125 CWE-191
Out-of-bounds Read Integer Underflow (Wrap or Wraparound)
|
CVE-2026-42326
|
2026-06-12 03:41 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1310
|
5.5 |
MEDIUM
Local
|
microsoft
|
windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2025
|
Out-of-bounds read in Windows Application Identity (AppID) Subsystem allows an authorized attacker to disclose information locally.
|
CWE-125
Out-of-bounds Read
|
CVE-2026-45604
|
2026-06-12 03:40 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1311
|
8.4 |
HIGH
Local
|
microsoft
|
365_apps microsoft_365 office_2016 office_2019 office_2021 office_2024 sharepoint_server
|
Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.
|
CWE-843
Type Confusion
|
CVE-2026-45456
|
2026-06-12 03:40 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1312
|
7.8 |
HIGH
Local
|
microsoft
|
365_apps microsoft_365 office_2016 office_2019 office_2021 office_2024 sharepoint_server
|
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
|
CWE-122
Heap-based Buffer Overflow
|
CVE-2026-44824
|
2026-06-12 03:40 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1313
|
5.5 |
MEDIUM
Local
|
microsoft
|
365_apps microsoft_365 office_2016 office_2019 office_2021 office_2024 sharepoint_server
|
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
|
CWE-125
Out-of-bounds Read
|
CVE-2026-44821
|
2026-06-12 03:40 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1314
|
7.8 |
HIGH
Local
|
microsoft
|
windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2016 windows_server_2019 w…
|
Use after free in Windows Bluetooth Service allows an authorized attacker to elevate privileges locally.
|
CWE-416
Use After Free
|
CVE-2026-45605
|
2026-06-12 03:39 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1315
|
7.8 |
HIGH
Local
|
microsoft
|
365_apps microsoft_365 office_2016 office_2019 office_2021 office_2024 sharepoint_server
|
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
|
CWE-122
Heap-based Buffer Overflow
|
CVE-2026-44819
|
2026-06-12 03:39 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1316
|
5.5 |
MEDIUM
Local
|
microsoft
|
windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2012 windows_server_2016 w…
|
Out-of-bounds read in Microsoft UxTheme Library (uxtheme.dll) allows an authorized attacker to deny service locally.
|
CWE-125
Out-of-bounds Read
|
CVE-2026-45606
|
2026-06-12 03:38 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1317
|
7.8 |
HIGH
Local
|
microsoft
|
365_apps microsoft_365 office_2021 office_2024
|
Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally.
|
CWE-125
Out-of-bounds Read
|
CVE-2026-45457
|
2026-06-12 03:38 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1318
|
7.8 |
HIGH
Local
|
microsoft
|
365_apps excel microsoft_365 office_2019 office_2021 office_2024 office_online_server
|
Integer underflow (wrap or wraparound) in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
|
CWE-843
Type Confusion
|
CVE-2026-44817
|
2026-06-12 03:38 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1319
|
7.0 |
HIGH
Local
|
microsoft
|
365_apps excel microsoft_365 office_2019 office_2021 office_2024 office_online_server
|
Integer underflow (wrap or wraparound) in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
|
CWE-362
Race Condition
|
CVE-2026-44818
|
2026-06-12 03:38 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1320
|
7.8 |
HIGH
Local
|
microsoft
|
365_apps excel microsoft_365 office_2019 office_2021 office_2024 office_online_server
|
Integer underflow (wrap or wraparound) in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
|
CWE-125
Out-of-bounds Read
|
CVE-2026-44820
|
2026-06-12 03:38 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1321
|
8.2 |
HIGH
Network
|
microsoft
|
365_apps excel microsoft_365 office_2019 office_2021 office_2024 office_online_server
|
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.
|
CWE-125
Out-of-bounds Read
|
CVE-2026-44822
|
2026-06-12 03:38 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1322
|
3.3 |
LOW
Local
|
microsoft
|
365_apps microsoft_365 office_2021 office_2024
|
Protection mechanism failure in Microsoft Office Excel allows an unauthorized attacker to bypass a security feature locally.
|
CWE-693
Protection Mechanism Failure
|
CVE-2026-45459
|
2026-06-12 03:38 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1323
|
7.8 |
HIGH
Local
|
microsoft
|
365_apps excel microsoft_365 office_2019 office_2021 office_2024 office_online_server
|
Integer underflow (wrap or wraparound) in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
|
CWE-122 CWE-191
Heap-based Buffer Overflow Integer Underflow (Wrap or Wraparound)
|
CVE-2026-45469
|
2026-06-12 03:37 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1324
|
3.3 |
LOW
Local
|
microsoft
|
365_apps microsoft_365 office_2016 office_2019 office_2021 office_2024 sharepoint_server
|
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
|
CWE-125
Out-of-bounds Read
|
CVE-2026-45485
|
2026-06-12 03:37 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1325
|
7.8 |
HIGH
Local
|
microsoft
|
windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2016 windows_server_2019 w…
|
Out-of-bounds read in Windows Hyper-V allows an unauthorized attacker to execute code locally.
|
CWE-125
Out-of-bounds Read
|
CVE-2026-45607
|
2026-06-12 03:37 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1326
|
7.8 |
HIGH
Local
|
microsoft
|
365_apps microsoft_365 office_2021 office_2024
|
Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally.
|
CWE-416
Use After Free
|
CVE-2026-45486
|
2026-06-12 03:37 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1327
|
7.8 |
HIGH
Local
|
microsoft
|
365_apps microsoft_365 office_2021 office_2024
|
Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally.
|
CWE-822
Untrusted Pointer Dereference
|
CVE-2026-45643
|
2026-06-12 03:37 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1328
|
7.8 |
HIGH
Local
|
x.org redhat
|
x_server xwayland enterprise_linux
|
A use-after-free flaw was found in the X.Org X server and Xwayland in FreeCounter(). A client that sets up multiple SyncCounters and awaits on those triggers can trigger a use-after-free when destroy…
|
CWE-416
Use After Free
|
CVE-2026-50260
|
2026-06-12 03:36 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1329
|
8.4 |
HIGH
Local
|
microsoft
|
office_2024
|
Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.
|
CWE-122
Heap-based Buffer Overflow
|
CVE-2026-47635
|
2026-06-12 03:36 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1330
|
8.1 |
HIGH
Network
|
microsoft
|
windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2012 windows_server_2016 w…
|
Use after free in Universal Plug and Play (upnp.dll) allows an unauthorized attacker to execute code over a network.
|
CWE-843 CWE-416
Type Confusion Use After Free
|
CVE-2026-45635
|
2026-06-12 03:36 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1331
|
7.8 |
HIGH
Local
|
microsoft
|
windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2012 windows_server_2016 w…
|
Heap-based buffer overflow in Windows NTFS allows an unauthorized attacker to execute code locally.
|
CWE-20 CWE-122
Improper Input Validation Heap-based Buffer Overflow
|
CVE-2026-45636
|
2026-06-12 03:33 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1332
|
6.5 |
MEDIUM
Adjacent
|
lldpd_project
|
lldpd
|
lldpd is an implementation of IEEE 802.1ab (LLDP). Prior to version 1.0.22, lldpd_decode() in src/daemon/lldpd.c strips 802.1Q VLAN tags from received Ethernet frames by calling memmove() to shift th…
|
CWE-125
Out-of-bounds Read
|
CVE-2026-46433
|
2026-06-12 03:29 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1333
|
7.8 |
HIGH
Local
|
microsoft
|
windows_10_1809 windows_10_21h2 windows_10_22h2 windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2019 windows_server_2022 windows_server_2025
|
Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
|
CWE-416
Use After Free
|
CVE-2026-45637
|
2026-06-12 03:24 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1334
|
7.8 |
HIGH
Local
|
microsoft
|
windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2012 windows_server_2016 w…
|
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
|
CWE-122
Heap-based Buffer Overflow
|
CVE-2026-45638
|
2026-06-12 03:23 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1335
|
8.7 |
HIGH
Network
|
open-emr
|
openemr
|
OpenEMR is a free and open source electronic health records and medical practice management application. Prior to version 8.0.0.1, a stored cross-site scripting vulnerability in the prescription CSS/…
|
CWE-79 CWE-862
Cross-site Scripting Missing Authorization
|
CVE-2026-46518
|
2026-06-12 03:23 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1336
|
7.0 |
HIGH
Local
|
microsoft
|
windows_10_21h2 windows_10_22h2 windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2022 windows_server_2025
|
Use after free in Windows Bluetooth Port Driver allows an authorized attacker to elevate privileges locally.
|
CWE-416
Use After Free
|
CVE-2026-45640
|
2026-06-12 03:22 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1337
|
6.5 |
MEDIUM
Adjacent
|
espressif
|
esp-idf
|
ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.2.7, 5.3.5, 5.4.4, 5.5.4, and 6.0.1, an out-of-bounds read flaw exists in the DHCP server option parser (parse_o…
|
CWE-125
Out-of-bounds Read
|
CVE-2026-45160
|
2026-06-12 03:22 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1338
|
10.0 |
CRITICAL
Network
|
-
|
-
|
MariaDB server is a community developed fork of MySQL server. Versions 10.6.1 through 10.6.26, 10.11.1 through 10.11.17, 11.4.1 through 11.4.11, 11.8.1 through 11.8.7, and 12.3.1 with `wsrep_notify_…
|
CWE-78
OS Command
|
CVE-2026-49261
|
2026-06-12 03:16 |
2026-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1339
|
7.3 |
HIGH
Network
|
-
|
-
|
KanaDojo before 0.1.18 contains a sandbox escape vulnerability that allows an attacker to execute arbitrary code by exploiting the explicit passing of the global require function into a Node.js vm.ru…
|
CWE-693
Protection Mechanism Failure
|
CVE-2026-48546
|
2026-06-12 03:16 |
2026-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1340
|
6.5 |
MEDIUM
Adjacent
|
-
|
-
|
aiograpi is an asynchronous Instagram API for Python. aiograpi versions before 0.9.10 accepted server-supplied signup challenge paths and used them to build request URLs before validating that the pa…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-47157
|
2026-06-12 03:16 |
2026-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1341
|
5.3 |
MEDIUM
Network
|
-
|
-
|
Fediverse Embeds embeds fediverse posts on WordPress sites. Prior to version 1.5.9, Fediverse Embeds registered the unauthenticated AJAX action wp_ajax_nopriv_ftf_get_site_info (includes/Site_Info.ph…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-46698
|
2026-06-12 03:16 |
2026-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1342
|
7.5 |
HIGH
Network
|
-
|
-
|
Fediverse Embeds embeds fediverse posts on WordPress sites. Prior to version 1.5.8, Fediverse Embeds registered an unauthenticated REST route ftf/media-proxy (includes/Media_Proxy.php) with permissio…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-46697
|
2026-06-12 03:16 |
2026-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1343
|
- |
-
|
-
|
-
|
A remote unauthenticated attacker may be able to conduct credential-guessing attacks against user accounts in Sonatype Nexus Repository via authentication endpoints.
|
CWE-307
mproper Restriction of Excessive Authentication Attempts
|
CVE-2026-3329
|
2026-06-12 03:16 |
2026-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1344
|
4.9 |
MEDIUM
Network
|
-
|
-
|
A flaw was found in the admin-ui-ext component of Keycloak, which provides extended administrative user interface capabilities. The issue occurs because certain bulk role-removal endpoints fail to pe…
|
CWE-425
Direct Request ('Forced Browsing')
|
CVE-2026-11986
|
2026-06-12 03:16 |
2026-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1345
|
8.8 |
HIGH
Local
|
espressif
|
esp-idf
|
ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.4 and 6.0, the esp_tee component exposes secure-service wrappers in esp_secure_services.c and esp_secure_servi…
|
CWE-20 CWE-787
Improper Input Validation Out-of-bounds Write
|
CVE-2026-45328
|
2026-06-12 03:15 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1346
|
7.5 |
HIGH
Network
|
espressif
|
esp-idf
|
ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.2.6, 5.3.5, 5.4.4, 5.5.4, and 6.0, a NULL-pointer dereference exists in the WebSocket subprotocol-negotiation pa…
|
CWE-476
NULL Pointer Dereference
|
CVE-2026-45541
|
2026-06-12 03:05 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1347
|
6.5 |
MEDIUM
Local
|
espressif
|
esp-idf
|
ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.4 and 6.0, several ESP-TEE secure-service wrappers in esp_secure_services.c and esp_secure_services_iram.c val…
|
CWE-20 CWE-125 CWE-200
Improper Input Validation Out-of-bounds Read Information Exposure
|
CVE-2026-45329
|
2026-06-12 03:04 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1348
|
6.5 |
MEDIUM
Network
|
7-zip
|
7-zip
|
7-Zip is a file archiver with a high compression ratio. Versions 9.21 through 26.00 contain an An uninitialized memory disclosure vulnerability in the UEFI capsule (.scap) parser in 7-Zip. The OpenCa…
|
CWE-908
Use of Uninitialized Resource
|
CVE-2026-48101
|
2026-06-12 03:02 |
2026-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1349
|
7.8 |
HIGH
Local
|
microsoft
|
windows_10_21h2 windows_10_22h2 windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2022 windows_server_2025
|
Out-of-bounds read in Windows Hyper-V allows an unauthorized attacker to execute code locally.
|
CWE-843 CWE-125
Type Confusion Out-of-bounds Read
|
CVE-2026-45641
|
2026-06-12 02:42 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1350
|
7.1 |
HIGH
Adjacent
|
espressif
|
esp-idf
|
ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.2.6, 5.3.5, 5.4.4, 5.5.4, and 6.0, a heap buffer overflow exists in the Security Scheme 2 (SRP6a) session-setup …
|
CWE-122
Heap-based Buffer Overflow
|
CVE-2026-45542
|
2026-06-12 02:41 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|