|
2001
|
8.8 |
HIGH
Network
|
-
|
-
|
Hermes WebUI before version 0.51.311 contains a remote code execution vulnerability that allows authenticated attackers to execute arbitrary commands by placing malicious executable Git configuration…
|
CWE-78
OS Command
|
CVE-2026-49959
|
2026-06-10 02:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2002
|
5.0 |
MEDIUM
Local
|
-
|
-
|
Hermes WebUI before version 0.51.303 contains a time-of-check time-of-use (TOCTOU) race condition vulnerability in the git_discard function within api/workspace_git.py that allows attackers to delete…
|
CWE-367
Time-of-check Time-of-use (TOCTOU) Race Condition
|
CVE-2026-49958
|
2026-06-10 02:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2003
|
5.3 |
MEDIUM
Network
|
-
|
-
|
Hermes WebUI before version 0.51.270 contains a resource exhaustion vulnerability that allows unauthenticated remote attackers to degrade service availability by repeatedly calling the passkey option…
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2026-49955
|
2026-06-10 02:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2004
|
9.8 |
CRITICAL
Network
|
-
|
-
|
External control of file name or path in Azure Stack Edge allows an unauthorized attacker to execute code over a network.
|
CWE-73
External Control of File Name or Path
|
CVE-2026-47643
|
2026-06-10 02:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2005
|
7.0 |
HIGH
Local
|
-
|
-
|
Use after free in Microsoft Office Click-To-Run allows an authorized attacker to elevate privileges locally.
|
CWE-416
Use After Free
|
CVE-2026-47293
|
2026-06-10 02:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2006
|
7.2 |
HIGH
Network
|
-
|
-
|
md-fileserver allows for local viewing of markdown files in a browser. Prior to version 1.10.3, a cross-site scripting (XSS) vulnerability exists in the application’s Markdown rendering logic. When u…
|
CWE-80 CWE-87
Basic XSS Improper Neutralization of Alternate XSS Syntax
|
CVE-2026-46492
|
2026-06-10 02:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2007
|
7.1 |
HIGH
Local
|
-
|
-
|
Improper access control in Office for Android allows an unauthorized attacker to perform spoofing locally.
|
CWE-284
Improper Access Control
|
CVE-2026-45649
|
2026-06-10 02:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2008
|
5.5 |
MEDIUM
Local
|
-
|
-
|
Time-of-check time-of-use (toctou) race condition in Microsoft Defender for Endpoint allows an authorized attacker to elevate privileges locally.
|
CWE-367
Time-of-check Time-of-use (TOCTOU) Race Condition
|
CVE-2026-45647
|
2026-06-10 02:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2009
|
7.8 |
HIGH
Local
|
-
|
-
|
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
|
CWE-822
Untrusted Pointer Dereference
|
CVE-2026-45645
|
2026-06-10 02:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2010
|
8.0 |
HIGH
Network
|
-
|
-
|
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Live Share Canvas SDK allows an authorized attacker to elevate privileges over a network.
|
CWE-79
Cross-site Scripting
|
CVE-2026-45644
|
2026-06-10 02:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2011
|
7.5 |
HIGH
Network
|
-
|
-
|
Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.
|
CWE-125
Out-of-bounds Read
|
CVE-2026-45639
|
2026-06-10 02:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2012
|
7.5 |
HIGH
Network
|
-
|
-
|
Uncontrolled resource consumption in ASP.NET Core allows an unauthorized attacker to deny service over a network.
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2026-45591
|
2026-06-10 02:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2013
|
7.5 |
HIGH
Network
|
-
|
-
|
Improper control of generation of code ('code injection') in Microsoft Exchange Server allows an unauthorized attacker to execute code over a network.
|
CWE-94
Code Injection
|
CVE-2026-45583
|
2026-06-10 02:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2014
|
6.1 |
MEDIUM
Network
|
-
|
-
|
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
|
CWE-79
Cross-site Scripting
|
CVE-2026-45500
|
2026-06-10 02:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2015
|
6.2 |
MEDIUM
Local
|
-
|
-
|
Improper link resolution before file access ('link following') in .NET allows an unauthorized attacker to perform tampering locally.
|
CWE-59
Link Following
|
CVE-2026-45491
|
2026-06-10 02:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2016
|
7.8 |
HIGH
Local
|
-
|
-
|
Improper authorization in .NET allows an authorized attacker to elevate privileges locally.
|
CWE-285
Improper Authorization
|
CVE-2026-45490
|
2026-06-10 02:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2017
|
4.6 |
MEDIUM
Network
|
-
|
-
|
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office Project Server allows an authorized attacker to perform spoofing over a network.
|
CWE-79
Cross-site Scripting
|
CVE-2026-45483
|
2026-06-10 02:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2018
|
8.4 |
HIGH
Local
|
-
|
-
|
Improper limitation of a pathname to a restricted directory ('path traversal') in GitHub Copilot and Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.
|
CWE-22
Path Traversal
|
CVE-2026-45482
|
2026-06-10 02:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2019
|
8.2 |
HIGH
Local
|
-
|
-
|
Use after free in Linux MANA Driver allows an authorized attacker to elevate privileges locally.
|
CWE-416
Use After Free
|
CVE-2026-45476
|
2026-06-10 02:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2020
|
7.8 |
HIGH
Local
|
-
|
-
|
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
|
CWE-122
Heap-based Buffer Overflow
|
CVE-2026-45475
|
2026-06-10 02:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2021
|
8.4 |
HIGH
Local
|
-
|
-
|
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
|
CWE-416
Use After Free
|
CVE-2026-45474
|
2026-06-10 02:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2022
|
8.4 |
HIGH
Local
|
-
|
-
|
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
|
CWE-416
Use After Free
|
CVE-2026-45472
|
2026-06-10 02:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2023
|
7.8 |
HIGH
Local
|
-
|
-
|
Untrusted pointer dereference in Microsoft Office Word allows an unauthorized attacker to execute code locally.
|
CWE-822
Untrusted Pointer Dereference
|
CVE-2026-45471
|
2026-06-10 02:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2024
|
3.3 |
LOW
Local
|
-
|
-
|
Heap-based buffer overflow in Microsoft Office Word allows an unauthorized attacker to disclose information locally.
|
CWE-122
Heap-based Buffer Overflow
|
CVE-2026-45466
|
2026-06-10 02:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2025
|
8.4 |
HIGH
Local
|
-
|
-
|
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
|
CWE-121 CWE-191
Stack-based Buffer Overflow Integer Underflow (Wrap or Wraparound)
|
CVE-2026-45463
|
2026-06-10 02:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2026
|
8.4 |
HIGH
Local
|
-
|
-
|
Heap-based buffer overflow in Microsoft Office allows an unauthorized attacker to execute code locally.
|
CWE-416
Use After Free
|
CVE-2026-45461
|
2026-06-10 02:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2027
|
4.7 |
MEDIUM
Local
|
-
|
-
|
Out-of-bounds read in Microsoft Office allows an unauthorized attacker to disclose information locally.
|
CWE-126
Buffer Over-read
|
CVE-2026-45460
|
2026-06-10 02:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2028
|
3.3 |
LOW
Local
|
-
|
-
|
Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information over a network.
|
CWE-125
Out-of-bounds Read
|
CVE-2026-45455
|
2026-06-10 02:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2029
|
7.8 |
HIGH
Local
|
-
|
-
|
Integer underflow (wrap or wraparound) in Microsoft Office Excel allows an unauthorized attacker to execute code locally.
|
CWE-197 CWE-416
Numeric Truncation Error Use After Free
|
CVE-2026-44823
|
2026-06-10 02:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2030
|
7.8 |
HIGH
Local
|
-
|
-
|
Integer overflow or wraparound in Windows Win32K - GRFX allows an unauthorized attacker to execute code locally.
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2026-44812
|
2026-06-10 02:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2031
|
7.8 |
HIGH
Local
|
-
|
-
|
Integer overflow or wraparound in Windows Win32K - GRFX allows an unauthorized attacker to execute code locally.
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2026-44803
|
2026-06-10 02:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2032
|
7.5 |
HIGH
Network
|
-
|
-
|
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
|
CWE-362 CWE-416
Race Condition Use After Free
|
CVE-2026-42913
|
2026-06-10 02:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2033
|
7.5 |
HIGH
Network
|
-
|
-
|
Out-of-bounds read in Windows RDP allows an unauthorized attacker to disclose information over a network.
|
CWE-125
Out-of-bounds Read
|
CVE-2026-42908
|
2026-06-10 02:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2034
|
8.4 |
HIGH
Network
|
-
|
-
|
Improper neutralization of input during web page generation ('cross-site scripting') in Azure Stack Edge allows an authorized attacker to perform spoofing over a network.
|
CWE-79
Cross-site Scripting
|
CVE-2026-41098
|
2026-06-10 02:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2035
|
8.8 |
HIGH
Network
|
-
|
-
|
Improper handling of insufficient permissions or privileges in Microsoft Dynamics 365 (on-premises) allows an authorized attacker to elevate privileges over a network.
|
CWE-280
Improper Handling of Insufficient Permissions or Privileges
|
CVE-2026-40371
|
2026-06-10 02:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2036
|
8.8 |
HIGH
Local
|
-
|
-
|
Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Azure Kubernetes Service allows an authorized attacker to execute code locally.
|
CWE-22
Path Traversal
|
CVE-2026-32193
|
2026-06-10 02:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2037
|
4.8 |
MEDIUM
Adjacent
|
-
|
-
|
A vulnerability in which an attacker can provide a crafted external URL that may redirect a user to an unintended website.
|
CWE-601
Open Redirect
|
CVE-2026-28301
|
2026-06-10 02:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2038
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Deserialization of untrusted data in Nuance PowerScribe allows an unauthorized attacker to execute code over a network.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-26142
|
2026-06-10 02:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2039
|
7.3 |
HIGH
Local
|
-
|
-
|
NVIDIA DALI contains a vulnerability in a component where an attacker could cause an improper index validation. A successful exploit of this vulnerability might lead to code execution, data tampering…
|
CWE-129
Improper Validation of Array Index
|
CVE-2026-24181
|
2026-06-10 02:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2040
|
7.3 |
HIGH
Local
|
-
|
-
|
NVIDIA DALI contains a vulnerability in a component where an attacker could cause a heap-based buffer overflow. A successful exploit of this vulnerability might lead to code execution, data tampering…
|
CWE-122
Heap-based Buffer Overflow
|
CVE-2026-24180
|
2026-06-10 02:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2041
|
8.1 |
HIGH
Network
|
-
|
-
|
Waves Central for macOS versions 13.0.9 through 16.5.5 contain a local privilege escalation vulnerability in the privileged helper service. The helper validates connecting XPC clients using the clien…
|
CWE-367
Time-of-check Time-of-use (TOCTOU) Race Condition
|
CVE-2026-24065
|
2026-06-10 02:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2042
|
7.8 |
HIGH
Local
|
-
|
-
|
Omnissa Workspace ONE® Assist for macOS contains a Local Privilege Escalation Vulnerability.
|
CWE-22
Path Traversal
|
CVE-2026-22926
|
2026-06-10 02:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2043
|
7.3 |
HIGH
Network
|
-
|
-
|
A security flaw has been discovered in imvks786 student_management_system up to 9599b560ad3c3b83e75d328b76bedcd489ef1f46. This impacts an unknown function of the file admin/admin_login.php of the com…
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-11531
|
2026-06-10 02:17 |
2026-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2044
|
4.3 |
MEDIUM
Network
|
-
|
-
|
A security vulnerability has been detected in TOTOLINK AC1200 T8 4.1.5cu.8611. This affects an unknown function of the file /etc/vsftpd.conf of the component vsftpd. The manipulation leads to least p…
|
CWE-266 CWE-272
Incorrect Privilege Assignment Least Privilege Violation
|
CVE-2026-11494
|
2026-06-10 02:17 |
2026-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2045
|
- |
-
|
-
|
-
|
Two endpoints in the Vault Service ScriptsController, shared by Altium Enterprise Server and Altium 365, accept file uploads where a user-supplied filename component is used to construct the destinat…
|
CWE-22 CWE-306
Path Traversal Missing Authentication for Critical Function
|
CVE-2026-11429
|
2026-06-10 02:17 |
2026-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2046
|
8.8 |
HIGH
Network
|
-
|
-
|
A security vulnerability has been detected in JingDong JD Cloud Box AX6600 4.5.3.r4546. The impacted element is the function set_macfilter of the file /sbin/jdcweb_rpc. The manipulation leads to stac…
|
CWE-119 CWE-121
Incorrect Access of Indexable Resource ('Range Error') Stack-based Buffer Overflow
|
CVE-2026-11413
|
2026-06-10 02:17 |
2026-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2047
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability has been found in tittuvarghese CollegeManagementSystem 3e476335cfbfb9a049e09f474c7ec885f69a9df3/a38852979f7e27ae67b610dce5979500ef8ebe01. Affected is an unknown function of the file …
|
CWE-266 CWE-285
Incorrect Privilege Assignment Improper Authorization
|
CVE-2026-11336
|
2026-06-10 02:17 |
2026-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2048
|
9.1 |
CRITICAL
Network
|
-
|
-
|
Arm C1-Ultra, C1-Premium, Neoverse V3 & V3AE, Neoverse V2, Neoverse V1, Neoverse-N2, Neoverse-N1, Cortex-X925, Cortex-X4, Cortex-X3, Cortex-X2, Cortex-X1 & X1C, Cortex-A710, Cortex-A78, A78AE & A78C,…
|
CWE-362
Race Condition
|
CVE-2025-10263
|
2026-06-10 02:16 |
2026-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2049
|
7.5 |
HIGH
Network
|
google
|
chrome
|
Use after free in TabStrip in Google Chrome prior to 149.0.7827.103 allowed a remote attacker who convinced a user to engage in specific UI gestures to execute arbitrary code via a crafted HTML page.…
|
CWE-416
Use After Free
|
CVE-2026-11632
|
2026-06-10 01:58 |
2026-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2050
|
8.8 |
HIGH
Network
|
google
|
chrome
|
Use after free in Bluetooth in Google Chrome on Mac prior to 149.0.7827.103 allowed a remote attacker to execute arbitrary code via a malicious peripheral. (Chromium security severity: Critical)
|
CWE-416
Use After Free
|
CVE-2026-11633
|
2026-06-10 01:57 |
2026-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|