|
1851
|
6.5 |
MEDIUM
Network
|
google
|
chrome
|
Inappropriate implementation in MHTML in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to leak cross-origin data via a crafted …
|
CWE-346 CWE-352
Origin Validation Error Origin Validation Error
|
CVE-2026-11195
|
2026-06-10 21:32 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1852
|
6.5 |
MEDIUM
Network
|
google
|
chrome
|
Inappropriate implementation in Network in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
|
CWE-346 CWE-352
Origin Validation Error Origin Validation Error
|
CVE-2026-11194
|
2026-06-10 21:31 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1853
|
6.5 |
MEDIUM
Network
|
google
|
chrome
|
Inappropriate implementation in SVG in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Medium)
|
CWE-200
Information Exposure
|
CVE-2026-11182
|
2026-06-10 21:29 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1854
|
5.3 |
MEDIUM
Network
|
google
|
chrome
|
Out of bounds read in ANGLE in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from proc…
|
CWE-125
Out-of-bounds Read
|
CVE-2026-11005
|
2026-06-10 21:26 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1855
|
- |
-
|
-
|
-
|
An HTML injection vulnerability in the "fetch links" email sent by Thinkst Applied Research Canarytokens, enabling Interface Manipulation, Cross-Site Scripting (XSS) in emails clients that render HTM…
|
CWE-74
Injection
|
CVE-2026-11859
|
2026-06-10 21:16 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1856
|
- |
-
|
-
|
-
|
NLnet Labs ldns 1.2.0 up to and including versions 1.9.0, when used in applications as (stub) resolver over UDP, lacks matching the query destination address and port with the response source address…
|
CWE-346
Origin Validation Error
|
CVE-2026-10846
|
2026-06-10 21:16 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1857
|
- |
-
|
-
|
-
|
A NETGEAR security issue that could allow an attacker with ability to intercept and tamper with traffic between the router and the Internet to run commands on your device when the device administrato…
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2026-0409
|
2026-06-10 21:16 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1858
|
9.1 |
CRITICAL
Network
|
-
|
-
|
The Schema & Structured Data for WP & AMP WordPress plugin before 1.60 does not check user capabilities on its frontend AJAX file-upload handlers and does not validate the actual content of uploaded …
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2026-9067
|
2026-06-10 20:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1859
|
3.5 |
LOW
Network
|
-
|
-
|
The Store Locator WordPress plugin before 1.6.6 does not sanitize and escape one of its settings before storing it and outputting it on the Store Locator WordPress plugin before 1.6.6 admin page, all…
|
CWE-79
Cross-site Scripting
|
CVE-2026-9060
|
2026-06-10 20:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1860
|
8.8 |
HIGH
Network
|
-
|
-
|
The Anti-Spam by CleanTalk. Spam protection WordPress plugin before 6.79 does not properly sanitize content within a custom shortcode used in its email-encoding feature, allowing unauthenticated atta…
|
CWE-79
Cross-site Scripting
|
CVE-2026-8071
|
2026-06-10 20:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1861
|
8.6 |
HIGH
Network
|
-
|
-
|
The Xstore WordPress theme before 9.7.3 does not properly sanitise and escape a parameter before using it in a SQL statement via an AJAX action available to unauthenticated users, leading to a SQL in…
|
CWE-89
SQL Injection
|
CVE-2026-3326
|
2026-06-10 20:16 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1862
|
4.3 |
MEDIUM
Network
|
7-zip
|
7-zip
|
7-Zip is a file archiver with a high compression ratio. Versions 9.11 through 26.00 contain a heap out-of-bounds read of up to 3 bytes in the UDF disc image handler's File Identifier Descriptor parse…
|
CWE-125
Out-of-bounds Read
|
CVE-2026-48102
|
2026-06-10 19:45 |
2026-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1863
|
- |
-
|
-
|
-
|
Debusine is an integrated solution to build, distribute and maintain a Debian-based distribution. Debian source packages (.dsc) and upload artifacts (.changes) are manifest files that name the files …
|
-
|
CVE-2026-11853
|
2026-06-10 19:16 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1864
|
- |
-
|
-
|
-
|
Debusine is an integrated solution to build, distribute and maintain a Debian-based distribution. Files managed by debusine are organized into artifacts. The endpoints that create and delete relation…
|
-
|
CVE-2026-11852
|
2026-06-10 19:16 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1865
|
- |
-
|
-
|
-
|
Concrete CMS below 9.5.2 is vulnerable to PHP Object Injection via unserialize() calls in the in Permission, Cache, and Search components. An unauthenticated attacker may trigger arbitrary PHP objec…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-10721
|
2026-06-10 17:16 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1866
|
- |
-
|
-
|
-
|
A vulnerability has been found in some Dahua products could
allow an unauthenticated remote attacker to send a specially crafted packet,
triggering an exception that causes the system to reboot unexp…
|
CWE-617
Reachable Assertion
|
CVE-2026-29116
|
2026-06-10 16:16 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1867
|
- |
-
|
-
|
-
|
A vulnerability has been found in some Dahua products could allow an authenticated remote attacker to send a specially crafted packet, triggering an exception that causes the system to reboot unexpec…
|
CWE-617
Reachable Assertion
|
CVE-2026-29115
|
2026-06-10 16:16 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1868
|
- |
-
|
-
|
-
|
A vulnerability has been found in some Dahua products. An attacker
may obtain the device’s CA root certificate. If that CA is installed and
trusted on client systems, the attacker could issue fraudul…
|
CWE-538
File and Directory Information Exposure
|
CVE-2026-29114
|
2026-06-10 16:16 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1869
|
- |
-
|
-
|
-
|
An attacker who intercepts and tampers with traffic between the client application and the API Gateway server could potentially deserialize arbitrary objects. This vulnerability could lead to broken …
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-11815
|
2026-06-10 16:16 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1870
|
7.3 |
HIGH
Local
|
-
|
-
|
A local privilege escalation vulnerability was found in the ansible.posix authorized_key module. The module's keyfile() function uses os.chown() instead of os.lchown() and opens files without O_NOFOL…
|
CWE-59
Link Following
|
CVE-2026-11837
|
2026-06-10 14:16 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1871
|
2.4 |
LOW
Network
|
-
|
-
|
A weakness has been identified in FluentCMS 0.0.5. The impacted element is an unknown function of the file /admin/blocks of the component Blocks Plugin. This manipulation causes cross site scripting.…
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-11434
|
2026-06-10 14:16 |
2026-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1872
|
- |
-
|
-
|
-
|
A cross-site request forgery (CSRF) vulnerability has been reported to affect Notification Center. The remote attackers can then exploit the vulnerability to gain privileges or hijack user identities…
|
CWE-352
Origin Validation Error
|
CVE-2025-58468
|
2026-06-10 12:16 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1873
|
5.4 |
MEDIUM
Network
|
-
|
-
|
WordPress Popup Builder 3.49 contains a persistent cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by breaking out of option tags in the post_title …
|
CWE-79
Cross-site Scripting
|
CVE-2019-25744
|
2026-06-10 11:16 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1874
|
5.4 |
MEDIUM
Network
|
-
|
-
|
WordPress Soliloquy Lite 2.5.6 contains a persistent cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by inserting script tags in the post title fiel…
|
CWE-79
Cross-site Scripting
|
CVE-2019-25743
|
2026-06-10 11:16 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1875
|
5.4 |
MEDIUM
Network
|
-
|
-
|
WordPress Theme Zoner Real Estate 4.1.1 contains a persistent cross-site scripting vulnerability that allows authenticated agents to inject malicious scripts through the Address input field when crea…
|
CWE-79
Cross-site Scripting
|
CVE-2019-25742
|
2026-06-10 11:16 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1876
|
5.4 |
MEDIUM
Network
|
-
|
-
|
GigToDo 1.3 contains a persistent cross-site scripting vulnerability that allows authenticated attackers to inject malicious JavaScript and HTML code through the proposal description field. Attackers…
|
CWE-79
Cross-site Scripting
|
CVE-2019-25739
|
2026-06-10 11:16 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1877
|
6.1 |
MEDIUM
Network
|
-
|
-
|
Live Chat Unlimited 2.8.3 contains a stored cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious scripts through the chat input field. Attackers can submit pay…
|
CWE-79
Cross-site Scripting
|
CVE-2019-25737
|
2026-06-10 11:16 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1878
|
6.1 |
MEDIUM
Network
|
-
|
-
|
Zuz Music 2.1 contains a persistent cross-site scripting vulnerability that allows unauthenticated attackers to inject malicious JavaScript by submitting crafted contact form data. Attackers can inje…
|
CWE-79
Cross-site Scripting
|
CVE-2019-25731
|
2026-06-10 11:16 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1879
|
- |
-
|
-
|
-
|
Frappe Learning Management System (LMS) is a learning system that helps users structure their content. Prior to version 2.53.0, an authenticated user could supply specially crafted content in certain…
|
CWE-74
Injection
|
CVE-2026-46546
|
2026-06-10 10:16 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1880
|
- |
-
|
-
|
-
|
SimpleBLE is a cross-platform library and bindings for Bluetooth Low Energy (BLE). Prior to version 0.14.0, there are multiple stack-based buffer overflow vulnerabilities in SimpleBLE. There is a sta…
|
CWE-121 CWE-787
Stack-based Buffer Overflow Out-of-bounds Write
|
CVE-2026-44634
|
2026-06-10 10:16 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1881
|
4.3 |
MEDIUM
Network
|
-
|
-
|
BuddyPress 14.4.0 contains an insecure direct object reference vulnerability in the friends REST API that allows any authenticated attacker to enumerate another user's complete friend list. Attackers…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-53675
|
2026-06-10 09:16 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1882
|
7.1 |
HIGH
Network
|
-
|
-
|
BuddyPress 14.4.0 contains a regular expression injection vulnerability in the activity mention resolver that, when username compatibility mode is enabled, allows attackers to manipulate a REGEXP dat…
|
CWE-943
Improper Neutralization of Special Elements in Data Query Logic
|
CVE-2026-53674
|
2026-06-10 09:16 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1883
|
8.1 |
HIGH
Network
|
-
|
-
|
BuddyPress 14.4.0 contains an insecure direct object reference vulnerability in the messages REST API that allows authenticated attackers to access arbitrary private message threads by supplying a us…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-53673
|
2026-06-10 09:16 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1884
|
6.8 |
MEDIUM
Network
|
-
|
-
|
SubjectDnX509PrincipalExtractor does not correctly handle certain malformed X.509 certificate CN values, which can lead to reading the wrong value for the username. In a carefully crafted certificate…
|
CWE-287
Improper Authentication
|
CVE-2026-47838
|
2026-06-10 09:16 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1885
|
7.5 |
HIGH
Network
|
-
|
-
|
Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to version 1.5.0, a remote, unauthenticated denial-of-service vulnerability in Me…
|
CWE-248
Uncaught Exception
|
CVE-2026-46545
|
2026-06-10 09:16 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1886
|
5.3 |
MEDIUM
Network
|
-
|
-
|
Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to version 1.5.0, a remote peer can crash any full node by sending a RequestBatch…
|
CWE-617
Reachable Assertion
|
CVE-2026-46543
|
2026-06-10 09:16 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1887
|
4.3 |
MEDIUM
Network
|
-
|
-
|
Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to version 1.4.0, a denial-of-service vulnerability exists in the Ed25519 multisi…
|
CWE-617
Reachable Assertion
|
CVE-2026-46542
|
2026-06-10 09:16 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1888
|
7.5 |
HIGH
Network
|
-
|
-
|
Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to version 1.4.0, iIn handle_dht_get(), the DhtResults accumulator is only initia…
|
CWE-754
Improper Check for Unusual or Exceptional Conditions
|
CVE-2026-46541
|
2026-06-10 09:16 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1889
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to version 1.4.0, when LightBlockchain::rebranch() adopts a fork chain whose tip …
|
CWE-841
Improper Enforcement of Behavioral Workflow
|
CVE-2026-46540
|
2026-06-10 09:16 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1890
|
5.9 |
MEDIUM
Network
|
-
|
-
|
Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. Prior to version 1.4.0, a logic flaw in BlockInclusionProof::is_block_proven causes the…
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2026-46539
|
2026-06-10 09:16 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1891
|
8.6 |
HIGH
Network
|
-
|
-
|
SimpleSAMLphp-casserver is a CAS 1.0 and 2.0 compliant CAS server in the form of a SimpleSAMLphp module. Prior to version 7.0.3, simplesamlphp-module-casserver builds file paths for the file-based CA…
|
CWE-22
Path Traversal
|
CVE-2026-46491
|
2026-06-10 09:16 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1892
|
6.5 |
MEDIUM
Network
|
-
|
-
|
FlashMQ is a MQTT broker/server, designed for multi-CPU environments. Prior to version 1.26.2, authorized clients have the ability to exceed the permitted over-commit of their write buffer and trigge…
|
CWE-248
Uncaught Exception
|
CVE-2026-46411
|
2026-06-10 09:16 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1893
|
- |
-
|
-
|
-
|
Cloud Hypervisor is a Virtual Machine Monitor for Cloud workloads. From version 21.0 to before version 51.2, a guest can cause a use-after-free in the cloud-hypervisor process by submitting two virti…
|
CWE-416
Use After Free
|
CVE-2026-45782
|
2026-06-10 09:16 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1894
|
5.3 |
MEDIUM
Network
|
-
|
-
|
Nimiq is a Rust implementation of the Nimiq Proof-of-Stake protocol based on the Albatross consensus algorithm. network-libp2p handles kad get-record query progress in handle_dht_get (network-libp2p/…
|
CWE-755
Improper Handling of Exceptional Conditions
|
CVE-2026-44505
|
2026-06-10 09:16 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1895
|
5.3 |
MEDIUM
Network
|
-
|
-
|
Spring Data REST's Querydsl integration accepts arbitrary persistent property paths as request-parameter filter keys and does not consider Jackson customizations before handing them to Querydsl.
Aff…
|
CWE-284
Improper Access Control
|
CVE-2026-41837
|
2026-06-10 09:16 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1896
|
8.1 |
HIGH
Network
|
-
|
-
|
JsonPulsarHeaderMapper matched type headers against trusted packages using a prefix check, meaning that trusting any package implicitly trusted all of its subpackages. Additionally, an empty trusted-…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-41732
|
2026-06-10 09:16 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1897
|
8.1 |
HIGH
Network
|
-
|
-
|
JsonKafkaHeaderMapper and the deprecated DefaultKafkaHeaderMapper matched type headers against trusted packages using a prefix check, meaning that trusting any package implicitly trusted all of its s…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-41731
|
2026-06-10 09:16 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1898
|
5.3 |
MEDIUM
Network
|
-
|
-
|
Spring Data REST serializes the full exception cause chain into HTTP error response bodies, potentially exposing persistence-layer internals to HTTP clients.
Affected versions:
Spring Data REST 3.7.…
|
CWE-209
Information Exposure Through an Error Message
|
CVE-2026-41730
|
2026-06-10 09:16 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1899
|
8.1 |
HIGH
Network
|
-
|
-
|
Spring Data REST is vulnerable to SpEL expression injection through map-typed properties when processing JSON Patch (application/json-patch+json) requests. When a persistent entity exposes a Map-type…
|
CWE-917
Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')
|
CVE-2026-41729
|
2026-06-10 09:16 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1900
|
7.5 |
HIGH
Network
|
-
|
-
|
Spring Data REST's JSON Patch (application/json-patch+json) implementation does not apply the write-access filter to intermediate path segments when resolving a multi-segment JSON Pointer.
Affected …
|
CWE-284
Improper Access Control
|
CVE-2026-41728
|
2026-06-10 09:16 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|