|
151
|
4.1 |
MEDIUM
Local
|
-
|
-
|
IBM Security QRadar EDR 3.12 through 3.12.24 stores user credentials in plain text which can be read by a local privileged user.
New
|
CWE-256
Plaintext Storage of a Password
|
CVE-2024-45636
|
2026-06-12 01:16 |
2026-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
152
|
9.6 |
CRITICAL
Adjacent
|
microsoft
|
windows_10_21h2 windows_10_22h2 windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2022 windows_server_2025
|
Heap-based buffer overflow in Windows TCP/IP allows an unauthorized attacker to elevate privileges over an adjacent network.
New
|
CWE-122
Heap-based Buffer Overflow
|
CVE-2026-42904
|
2026-06-12 01:15 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
153
|
7.8 |
HIGH
Local
|
microsoft
|
windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2012 windows_server_2016 w…
|
Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.
New
|
CWE-416
Use After Free
|
CVE-2026-42905
|
2026-06-12 01:14 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
154
|
5.5 |
MEDIUM
Local
|
microsoft
|
windows_10_21h2 windows_10_22h2 windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2022 windows_server_2025
|
Exposure of sensitive information to an unauthorized actor in Windows Shell allows an authorized attacker to disclose information locally.
New
|
CWE-200
Information Exposure
|
CVE-2026-42906
|
2026-06-12 01:13 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
155
|
6.1 |
MEDIUM
Network
|
vmware
|
spring_framework
|
Due to incorrect escaping, the use of JavaScriptUtils.javaScriptEscape() may lead to JavaScript code injection in the browser, potentially resulting in a cross-site scripting (XSS) vulnerability.
Af…
Update
|
CWE-79
Cross-site Scripting
|
CVE-2026-41845
|
2026-06-12 01:12 |
2026-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
156
|
6.1 |
MEDIUM
Network
|
vmware
|
spring_framework
|
Spring MVC applications which accept user-supplied values in the cssClass, cssErrorClass, or cssStyle attributes of JSP form tags allow arbitrary HTML/JavaScript code injection, potentially resulting…
Update
|
CWE-79
Cross-site Scripting
|
CVE-2026-41846
|
2026-06-12 01:10 |
2026-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
157
|
5.3 |
MEDIUM
Network
|
vmware
|
spring_framework
|
Spring WebFlux applications may be vulnerable to a security bypass when using the Kotlin Router DSL.
Affected versions:
Spring Framework 5.3.0 through 5.3.48.
Update
|
CWE-284 NVD-CWE-noinfo
Improper Access Control
|
CVE-2026-41847
|
2026-06-12 01:08 |
2026-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
158
|
7.8 |
HIGH
Local
|
microsoft
|
windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2012 windows_server_2016 w…
|
Use after free in Microsoft Graphics Component allows an authorized attacker to elevate privileges locally.
New
|
CWE-416
Use After Free
|
CVE-2026-42986
|
2026-06-12 01:02 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
159
|
8.1 |
HIGH
Network
|
microsoft
|
windows_server_2012 windows_server_2016 windows_server_2019 windows_server_2022 windows_server_2025
|
Use after free in Windows Deployment Services allows an unauthorized attacker to execute code over a network.
New
|
CWE-416
Use After Free
|
CVE-2026-42987
|
2026-06-12 00:46 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
160
|
7.5 |
HIGH
Network
|
vmware
|
spring_framework
|
Applications may be vulnerable to a Regular Expression Denial of Service (ReDoS) attack if an attacker is able to provide a pattern which is then directly or indirectly supplied to one of the followi…
Update
|
CWE-1333
Inefficient Regular Expression Complexity
|
CVE-2026-41848
|
2026-06-12 00:45 |
2026-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
161
|
7.8 |
HIGH
Local
|
microsoft
|
windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2012 windows_server_2016 w…
|
Improper link resolution before file access ('link following') in Winlogon allows an authorized attacker to elevate privileges locally.
New
|
CWE-59
Link Following
|
CVE-2026-42989
|
2026-06-12 00:45 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
162
|
7.8 |
HIGH
Local
|
microsoft
|
windows_10_1809 windows_10_21h2 windows_10_22h2 windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2019 windows_server_2022 windows_server_2025
|
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.
New
|
CWE-362 CWE-416
Race Condition Use After Free
|
CVE-2026-42991
|
2026-06-12 00:43 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
163
|
5.3 |
MEDIUM
Network
|
vmware
|
spring_framework
|
A vulnerability in Spring Expression Language (SpEL) evaluation logic allows for arbitrary zero-argument method invocation, even within restricted or read-only contexts, which may allow an attacker t…
Update
|
CWE-863
Incorrect Authorization
|
CVE-2026-41852
|
2026-06-12 00:43 |
2026-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
164
|
7.5 |
HIGH
Network
|
-
|
-
|
TDengine is an open source, time-series database optimized for Internet of Things devices. In versions 3.4.0.0 through 3.4.1.5, an unauthenticated remote attacker can crash the taosd server process b…
New
|
CWE-191
Integer Underflow (Wrap or Wraparound)
|
CVE-2026-42542
|
2026-06-12 00:37 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
165
|
7.5 |
HIGH
Network
|
-
|
-
|
vLLM versions 0.8.0 and later are vulnerable to an Out-of-Memory (OOM) Denial of Service (DoS) attack due to unbounded frame count processing in the `VideoMediaIO.load_base64()` method. When processi…
New
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2026-5497
|
2026-06-12 00:37 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
166
|
8.4 |
HIGH
Local
|
microsoft
|
365_apps microsoft_365 office_2019 office_2021 office_2024 sharepoint_server word
|
Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.
New
|
CWE-416
Use After Free
|
CVE-2026-45458
|
2026-06-12 00:37 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
167
|
- |
-
|
-
|
-
|
Plonky3 is a toolkit for polynomial IOPs (PIOPs). Prior to versions 0.4.3 and 0.5.3, an attacker controlling prover-side observations can craft distinct transcripts that produce identical challenges,…
New
|
CWE-345 CWE-1240
Insufficient Verification of Data Authenticity Use of a Cryptographic Primitive with a Risky Implementation
|
CVE-2026-46654
|
2026-06-12 00:36 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
168
|
- |
-
|
-
|
-
|
Kanidm is an identity management platform. Prior to version 1.9.3, a single unauthenticated GET to any /scim/v1/... endpoint with a ?filter= query string of a few thousand nested parentheses (≈ 4–12 …
New
|
CWE-248 CWE-400 CWE-674
Uncaught Exception Uncontrolled Resource Consumption Uncontrolled Recursion
|
CVE-2026-46689
|
2026-06-12 00:36 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
169
|
5.4 |
MEDIUM
Network
|
apache
|
answer
|
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache Answer.
This issue affects Apache Answer: through 2.0.0.
User-supplied content was included in …
Update
|
CWE-80 CWE-79
Basic XSS Cross-site Scripting
|
CVE-2026-34033
|
2026-06-12 00:35 |
2026-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
170
|
- |
-
|
-
|
-
|
SpiceDB is an open source database system for creating and managing security-critical application permissions. From version 1.15.0 to before version 1.52.0, caveat structures with nested lists can re…
New
|
CWE-285
Improper Authorization
|
CVE-2026-46668
|
2026-06-12 00:35 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
171
|
- |
-
|
-
|
-
|
Allocation of Resources Without Limits or Throttling vulnerability in membraneframework membrane_mp4_plugin allows unauthenticated denial-of-service via BEAM atom table exhaustion.
The MP4 box heade…
New
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2026-53423
|
2026-06-12 00:35 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
172
|
7.0 |
HIGH
Local
|
microsoft
|
windows_10_21h2 windows_10_22h2 windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2022 windows_server_2025
|
Time-of-check time-of-use (TOCTOU) race condition in Program Compatibility Assistant Service allows an authorized attacker to elevate privileges locally.
New
|
CWE-367
Time-of-check Time-of-use (TOCTOU) Race Condition
|
CVE-2026-45487
|
2026-06-12 00:35 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
173
|
6.1 |
MEDIUM
Local
|
-
|
-
|
bit7z is a cross-platform C++ static library that allows the compression/extraction of archive files. Prior to version 4.0.12, there is an arbitrary file overwrite vulnerability via symlink attack on…
New
|
CWE-59 CWE-377
Link Following Insecure Temporary File
|
CVE-2026-45384
|
2026-06-12 00:35 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
174
|
7.8 |
HIGH
Local
|
-
|
-
|
GIMP HDR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User inte…
New
|
CWE-122
Heap-based Buffer Overflow
|
CVE-2026-2049
|
2026-06-12 00:34 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
175
|
7.0 |
HIGH
Network
|
-
|
-
|
Fedify is a TypeScript library for building federated server apps powered by ActivityPub. Prior to versions 1.9.11, 1.10.10, 2.0.18, 2.1.14, and 2.2.3, an attacker can make use of JSON-LD features to…
New
|
CWE-180 CWE-347 CWE-436 CWE-1289
Incorrect Behavior Order: Validate Before Canonicalize Improper Verification of Cryptographic Signature Interpretation Conflict Improper Validation of Unsafe Equivalence in Input
|
CVE-2026-42462
|
2026-06-12 00:34 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
176
|
- |
-
|
-
|
-
|
Boruta is a standalone authorization server that aims to implement OAuth 2.0 and Openid Connect up to decentralized identity specifications. Prior to version 0.9.1, boruta session cookies and the ide…
New
|
CWE-614
Sensitive Cookie in HTTPS Session Without 'Secure' Attribute
|
CVE-2026-53661
|
2026-06-12 00:34 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
177
|
5.8 |
MEDIUM
Network
|
-
|
-
|
Guzzle Services provides an implementation of the Guzzle Command library that uses Guzzle service descriptions to describe web services, serialize requests, and parse responses into easy to use model…
New
|
CWE-20 CWE-91
Improper Input Validation Blind XPath Injection
|
CVE-2026-53723
|
2026-06-12 00:34 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
178
|
7.8 |
HIGH
Local
|
microsoft
|
windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2012 windows_server_2016 w…
|
Improper link resolution before file access ('link following') in Windows Collaborative Translation Framework allows an authorized attacker to elevate privileges locally.
New
|
CWE-59
Link Following
|
CVE-2026-45586
|
2026-06-12 00:33 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
179
|
- |
-
|
-
|
-
|
A HTTP request smuggling and desynchronization vulnerability affects Kong Gateway Enterprise 3.4, 3.10, 3.11, 3.12, 3.13, and 3.14 series. The vulnerability is caused by a parsing flaw in Kong’s HTTP…
New
|
CWE-444
HTTP Request Smuggling
|
CVE-2026-6338
|
2026-06-12 00:32 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
180
|
7.7 |
HIGH
Network
|
-
|
-
|
Sharp is a content management framework built for Laravel as a package. Prior to version 9.22.0, Sharp exposes a generic download endpoint that authorizes access only to the supplied Sharp entity ins…
New
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-44692
|
2026-06-12 00:31 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
181
|
4.3 |
MEDIUM
Network
|
-
|
-
|
Sharp is a content management framework built for Laravel as a package. From version 9.0.0 to before version 9.22.3, the create and store endpoints of the Quick Creation Command feature did not enfor…
New
|
CWE-862
Missing Authorization
|
CVE-2026-53634
|
2026-06-12 00:31 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
182
|
7.6 |
HIGH
Network
|
-
|
-
|
Xibo is an open source digital signage platform with a web content management system and Windows display player software. Prior to 4.4.2, a vulnerability chain consisting of Stored XSS and Iframe San…
New
|
CWE-79 CWE-116 CWE-346
Cross-site Scripting Improper Encoding or Escaping of Output Origin Validation Error
|
CVE-2026-42558
|
2026-06-12 00:30 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
183
|
4.3 |
MEDIUM
Network
|
-
|
-
|
Yamcs is a mission control framework. Prior to versions 5.13.0 and 5.12.7, an LDAP injection vulnerability exists in `org.yamcs.security.LdapAuthModule` when constructing search filters. The username…
New
|
CWE-90
LDAP Injection
|
CVE-2026-42568
|
2026-06-12 00:30 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
184
|
4.3 |
MEDIUM
Network
|
-
|
-
|
SQLAdmin is a flexible Admin interface for SQLAlchemy models. Prior to version 0.25.1, the ajax_lookup endpoint in application.py bypasses the is_accessible() access control check that all other endp…
New
|
CWE-862
Missing Authorization
|
CVE-2026-46645
|
2026-06-12 00:30 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
185
|
7.8 |
HIGH
Local
|
-
|
-
|
A local privilege escalation vulnerability exists in Check Point Identity Agent Full for Windows OS. An authenticated local user may be able to execute arbitrary code with SYSTEM privileges due to im…
New
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2026-10847
|
2026-06-12 00:30 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
186
|
6.6 |
MEDIUM
Local
|
-
|
-
|
Authentication bypass by primary weakness vulnerability in ABB Freelance.
This issue affects Freelance: through 2013, 2013 SP1, 2016, 2016 SP1, 2019, 2019 SP1, 2019 SP1 FP1, 2024.
New
|
CWE-305
Authentication Bypass by Primary Weakness
|
CVE-2025-7064
|
2026-06-12 00:28 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
187
|
- |
-
|
-
|
-
|
Golem OEE MES is vulnerable to an unauthenticated path traversal flaw. This vulnerability allows an attacker in the same local network to read arbitrary files from the server's operating system by ma…
New
|
CWE-22
Path Traversal
|
CVE-2026-8464
|
2026-06-12 00:28 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
188
|
5.3 |
MEDIUM
Network
|
-
|
-
|
Improper neutralization of special elements used in an expression language statement ('expression language injection') vulnerability in Soagen Informatics Technologies Software and Consulting Inc. Ap…
New
|
CWE-917
Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')
|
CVE-2026-11561
|
2026-06-12 00:28 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
189
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Unrestricted upload of file with dangerous type vulnerability in Limatek System Inc. LimRAD NAC allows Remote Code Inclusion.
This issue affects LimRAD NAC: before 5.5.7.3.9.
New
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2026-7852
|
2026-06-12 00:28 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
190
|
7.9 |
HIGH
Local
|
microsoft
|
windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2012 windows_server_2016 w…
|
Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.
New
|
CWE-693
Protection Mechanism Failure
|
CVE-2026-45588
|
2026-06-12 00:25 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
191
|
5.3 |
MEDIUM
Network
|
-
|
-
|
guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Versions prior to 2.10.2 contain improper Host header validation when parsing raw HTTP request messages and when deriving a serv…
New
|
CWE-20 CWE-918
Improper Input Validation Server-Side Request Forgery (SSRF)
|
CVE-2026-48998
|
2026-06-12 00:25 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
192
|
5.3 |
MEDIUM
Network
|
-
|
-
|
guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Versions prior to 2.10.2 did not reject ASCII control characters, whitespace, or DEL in first-party URI host components. A vulne…
New
|
CWE-20 CWE-93 CWE-113
Improper Input Validation CRLF Injection HTTP Response Splitting
|
CVE-2026-49214
|
2026-06-12 00:25 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
193
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Russh is a Rust SSH client & server library. From version 0.37.0 to before version 0.61.0, in the russh client keyboard-interactive authentication path, a malicious SSH server could send a USERAUTH_I…
New
|
CWE-20
Improper Input Validation
|
CVE-2026-48107
|
2026-06-12 00:24 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
194
|
5.3 |
MEDIUM
Network
|
-
|
-
|
Russh is a Rust SSH client & server library. From version 0.34.0-beta.1 to before version 0.61.0, russh did not enforce the SSH identification-string rules as deliberately as OpenSSH. In particular, …
New
|
CWE-20
Improper Input Validation
|
CVE-2026-48108
|
2026-06-12 00:24 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
195
|
- |
-
|
-
|
-
|
Cerebrate before version 1.37 contains a mass-assignment vulnerability in the generic CRUD add path. The add() handler attempted to remove an attacker-supplied id from $params before normalizing the …
New
|
CWE-20
Improper Input Validation
|
CVE-2026-53901
|
2026-06-12 00:24 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
196
|
- |
-
|
-
|
-
|
Cerebrate before version 1.37 allowed the id primary key field to be supplied through request input during CRUD edit operations and certain custom entity patching flows. In affected entities that did…
New
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-53911
|
2026-06-12 00:24 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
197
|
- |
-
|
-
|
-
|
Cerebrate before version 1.37 exposed credential material from self-registration requests. The self-registration workflow stored the registrant’s hashed password in the inbox message data payload. Th…
New
|
CWE-200
Information Exposure
|
CVE-2026-53912
|
2026-06-12 00:24 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
198
|
8.7 |
HIGH
Network
|
-
|
-
|
GitLab has remediated an issue in GitLab EE affecting all versions from 17.1 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions could have allowed an authentic…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-10087
|
2026-06-12 00:22 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
199
|
4.3 |
MEDIUM
Network
|
-
|
-
|
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.0 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that could have allowed an authenticated user to cause den…
New
|
CWE-1021
Improper Restriction of Rendered UI Layers or Frames
|
CVE-2026-10733
|
2026-06-12 00:22 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
200
|
6.5 |
MEDIUM
Network
|
-
|
-
|
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.10 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions could have allowed an authe…
New
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2026-1500
|
2026-06-12 00:22 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|