|
201
|
3.1 |
LOW
Network
|
-
|
-
|
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.0 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions could have allowed an authen…
New
|
CWE-863
Incorrect Authorization
|
CVE-2026-3553
|
2026-06-12 00:22 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
202
|
- |
-
|
-
|
-
|
A Missing Authorization vulnerability in the playbook import functionality in Dialogflow CX on Google Cloud Platform allows an authenticated user with specific roles to escalate privileges and potent…
New
|
CWE-862
Missing Authorization
|
CVE-2026-4764
|
2026-06-12 00:22 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
203
|
5.4 |
MEDIUM
Network
|
-
|
-
|
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.10 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions could have allowed an authe…
New
|
CWE-863
Incorrect Authorization
|
CVE-2026-6269
|
2026-06-12 00:22 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
204
|
4.3 |
MEDIUM
Network
|
-
|
-
|
Easy Twitter Feeds before 1.2.13 contains a cross-site request forgery vulnerability in the duplicate_post action handler that lacks nonce verification. Attackers can trick an authenticated user into…
New
|
CWE-352
Origin Validation Error
|
CVE-2026-53736
|
2026-06-12 00:22 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
205
|
6.1 |
MEDIUM
Network
|
-
|
-
|
Juicer through 1.12.18 fails to escape remote feed API response fields before rendering them on the admin settings page. Attackers controlling the connected feed data can inject script that executes …
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-53737
|
2026-06-12 00:22 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
206
|
8.1 |
HIGH
Network
|
-
|
-
|
Copy & Delete Posts through 1.5.4 lets any plugin-enabled non-admin role invoke every operation in the cdp_action_handling AJAX handler. Attackers with an enabled role can delete posts or overwrite p…
New
|
CWE-863
Incorrect Authorization
|
CVE-2026-53738
|
2026-06-12 00:22 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
207
|
4.3 |
MEDIUM
Network
|
-
|
-
|
Yoast Duplicate Post through 4.6 contains a cross-site request forgery vulnerability in the duplicate_post_dismiss_notice handler, which verifies no nonce or capability. Attackers can trick any authe…
New
|
CWE-352
Origin Validation Error
|
CVE-2026-53739
|
2026-06-12 00:22 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
208
|
5.4 |
MEDIUM
Network
|
-
|
-
|
Yoast Duplicate Post through 4.6 inserts an unescaped post title and permalink into the Classic Editor scheduled republish notice. Attackers can schedule a republish copy with a crafted title to exec…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-53740
|
2026-06-12 00:22 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
209
|
5.4 |
MEDIUM
Network
|
-
|
-
|
Simple Link Directory through 9.0.4 interpolates the sld_no_results_found option into a JavaScript string literal without encoding. Because sanitize_text_field leaves quotes intact, a stored payload …
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-53741
|
2026-06-12 00:22 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
210
|
5.4 |
MEDIUM
Network
|
-
|
-
|
Simple Link Directory through 9.0.4 echoes embed shortcode attributes into HTML data attributes without escaping in the embedder template. Attackers with contributor access can craft a shortcode attr…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-53742
|
2026-06-12 00:22 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
211
|
7.5 |
HIGH
Network
|
-
|
-
|
kafka-python prior to 2.3.2 contains a denial-of-service vulnerability in the protocol parser that allows a malicious broker or machine-in-the-middle attacker to exhaust memory or hang connections by…
New
|
CWE-789
Memory Allocation with Excessive Size Value
|
CVE-2026-10142
|
2026-06-12 00:22 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212
|
7.5 |
HIGH
Network
|
-
|
-
|
kafka-python prior to 2.3.2 contains a denial-of-service vulnerability in SCRAM authentication handling that allows a malicious or machine-in-the-middle broker to freeze the client event loop by supp…
New
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2026-10143
|
2026-06-12 00:22 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213
|
- |
-
|
-
|
-
|
A cross-site scripting (XSS) vulnerability in Palo Alto Networks PAN-OS® software enables a malicious authenticated administrator to store a JavaScript payload using the web interface.
This issue i…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-0266
|
2026-06-12 00:21 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
214
|
- |
-
|
-
|
-
|
An information exposure vulnerability in the Palo Alto Networks GlobalProtect app on macOS enables a local user to learn the configured passcodes for disabling, disconnecting, or uninstalling the Glo…
New
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2026-0267
|
2026-06-12 00:21 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
215
|
- |
-
|
-
|
-
|
A security control bypass vulnerability in Prisma Access Agent for Linux allows a local attacker to route network traffic outside the VPN tunnel.
This does not impact Prisma Access Agent on Window…
New
|
CWE-424
Improper Protection of Alternate Path
|
CVE-2026-0268
|
2026-06-12 00:21 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
216
|
- |
-
|
-
|
-
|
A memory corruption vulnerability in the processing of tunnel traffic in Palo Alto Networks PAN-OS® software allows an authenticated user to initiate system reboots using a maliciously crafted packet…
New
|
CWE-754
Improper Check for Unusual or Exceptional Conditions
|
CVE-2026-0269
|
2026-06-12 00:21 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
217
|
- |
-
|
-
|
-
|
A path traversal vulnerability in Palo Alto Networks Cortex XSOAR engine software running on Linux allows an unauthenticated attacker on an adjacent network, with the ability to intercept and manipu…
New
|
CWE-22
Path Traversal
|
CVE-2026-0270
|
2026-06-12 00:21 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218
|
- |
-
|
-
|
-
|
A privilege escalation (PE) vulnerability in the Palo Alto Networks Prisma Access Agent app on Linux devices enables a local user to execute code with elevated privileges.
This does not impact Pri…
New
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2026-0271
|
2026-06-12 00:21 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219
|
- |
-
|
-
|
-
|
A privilege escalation vulnerability in Palo Alto Networks PAN-OS® software allows an authenticated administrator with access to the Command Line Interface (CLI) to perform actions on the device with…
New
|
CWE-862
Missing Authorization
|
CVE-2026-0272
|
2026-06-12 00:21 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
220
|
- |
-
|
-
|
-
|
A command injection vulnerability in Palo Alto Networks PAN-OS® software enables an authenticated administrator to bypass system restrictions and run arbitrary commands as a root user. To be able to …
New
|
CWE-78
OS Command
|
CVE-2026-0273
|
2026-06-12 00:21 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
221
|
- |
-
|
-
|
-
|
An improper validation of credentials vulnerability in the CommvaultSecurityIQ integration for Cortex XSOAR and Cortex XSIAM allows an unauthenticated attacker to access and modify protected resource…
New
|
CWE-1390
Weak Authentication
|
CVE-2026-0274
|
2026-06-12 00:21 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222
|
- |
-
|
-
|
-
|
An incorrect buffer size calculation in the epoch key generator in OpenVPN ovpn-dco-win version 2.0.0 through 2.8.3 allows a remote authenticated peer to trigger a heap-based buffer overflow and kern…
New
|
CWE-122 CWE-131 CWE-787
Heap-based Buffer Overflow Incorrect Calculation of Buffer Size Out-of-bounds Write
|
CVE-2026-11604
|
2026-06-12 00:21 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management). Supported versions that are affected are 8.61 and 8.62. Easily exploit…
New
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2026-35273
|
2026-06-12 00:21 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224
|
6.4 |
MEDIUM
Network
|
-
|
-
|
Applications that configure the WebFlowELExpressionParser are vulnerable to the use of malicious Unified EL expressions.
Affected versions:
Spring Web Flow 4.0.0; 3.0.0 through 3.0.1; 2.5.0 through …
New
|
CWE-917
Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')
|
CVE-2026-40985
|
2026-06-12 00:21 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
225
|
4.8 |
MEDIUM
Network
|
-
|
-
|
Spring Web Flow's JavaScript RemotingHandler renders the body of an error response as HTML even when the response is not "text/html", which can result in a scripting attack in the user's browser if t…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-40986
|
2026-06-12 00:21 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
226
|
7.1 |
HIGH
Network
|
-
|
-
|
A malicious or compromised FTP/SFTP/SMB server can write arbitrary files anywhere on the client filesystem (outside the configured local-directory) with attacker-controlled content.
Affected version…
New
|
CWE-22
Path Traversal
|
CVE-2026-40987
|
2026-06-12 00:21 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
227
|
5.0 |
MEDIUM
Adjacent
|
-
|
-
|
Spring Boot's Mail auto-configuration does not enable hostname verification. Applications that set the relevant JavaMail property, such as spring.mail.properties.mail.smtp.ssl.checkserveridentity=tru…
New
|
CWE-295
Improper Certificate Validation
|
CVE-2026-40992
|
2026-06-12 00:21 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
228
|
8.2 |
HIGH
Network
|
-
|
-
|
Wss4jSecurityInterceptor initialized its BSP (WS-I Basic Security Profile) compliance flag so that inbound validation disabled WSS4J BSP enforcement on RequestData. Services that validate WS-Security…
New
|
CWE-1188
Insecure Default Initialization of Resource
|
CVE-2026-40994
|
2026-06-12 00:21 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
229
|
5.4 |
MEDIUM
Network
|
-
|
-
|
X509AuthenticationProvider could issue a fully authenticated X509AuthenticationToken when a presented certificate mapped to UserDetails, without applying Spring Security's standard account lifecycle …
New
|
CWE-287
Improper Authentication
|
CVE-2026-40995
|
2026-06-12 00:21 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
230
|
4.8 |
MEDIUM
Network
|
-
|
-
|
Wss4jSecurityInterceptor defaulted allowRSA15KeyTransportAlgorithm to true, overriding Apache WSS4J's safer default for validation RequestData. Inbound WS-Security decryption could therefore accept R…
New
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2026-40996
|
2026-06-12 00:21 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
231
|
5.3 |
MEDIUM
Network
|
-
|
-
|
Several Spring WS integration paths with Spring Security could surface detailed account state (for example locked or disabled user semantics) to remote SOAP clients through exception messages or call…
New
|
CWE-209
Information Exposure Through an Error Message
|
CVE-2026-40997
|
2026-06-12 00:21 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
232
|
8.2 |
HIGH
Network
|
-
|
-
|
Jaxp13XPathTemplate evaluated XPath expressions for StreamSource and SAXSource inputs using a code path that parsed attacker-controlled XML with the JDK's default DocumentBuilderFactory behavior inst…
New
|
CWE-611
XXE
|
CVE-2026-40998
|
2026-06-12 00:21 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
233
|
8.6 |
HIGH
Network
|
-
|
-
|
When WS-Addressing is used with non-anonymous ReplyTo or FaultTo addresses, Spring WS may initiate outbound connections through configured WebServiceMessageSender instances to destinations taken dire…
New
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-40999
|
2026-06-12 00:21 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
234
|
3.7 |
LOW
Network
|
-
|
-
|
Wss4jSecurityInterceptor did not consistently wire Apache WSS4J ReplayCache instances into RequestData for validation-time checks. As a result, protections against replay of UsernameToken nonces and …
New
|
CWE-294
Authentication Bypass by Capture-replay
|
CVE-2026-41000
|
2026-06-12 00:21 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
235
|
5.3 |
MEDIUM
Local
|
-
|
-
|
Spring Boot's ArtemisEmbeddedConfigurationFactory uses a fixed, static path for the embedded Artemis message broker's data directory when no explicit path is configured. A local attacker on the same …
New
|
CWE-377
Insecure Temporary File
|
CVE-2026-41001
|
2026-06-12 00:21 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
236
|
8.1 |
HIGH
Network
|
-
|
-
|
Spring for GraphQL applications are vulnerable to Unsafe Deserialization when processing paginated GraphQL queries. An attacker can craft a malicious GraphQL request that can lead to Remote Code Exec…
New
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-41699
|
2026-06-12 00:21 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
237
|
8.1 |
HIGH
Network
|
-
|
-
|
Spring for GraphQL applications that have enabled the WebSocket transport are vulnerable to Cross-Site WebSocket Hijacking. An attacker can trick an authenticated user into visiting a malicious page,…
New
|
CWE-346
Origin Validation Error
|
CVE-2026-41700
|
2026-06-12 00:21 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
238
|
7.5 |
HIGH
Network
|
-
|
-
|
The Spring GraphQL annotation detection mechanism for @Controller data fetchers may not correctly resolve annotations on methods within type hierarchies. This can be an issue if such annotations are …
New
|
CWE-284
Improper Access Control
|
CVE-2026-41856
|
2026-06-12 00:21 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
239
|
5.0 |
MEDIUM
Network
|
-
|
-
|
An integer underflow vulnerability was found in MIT krb5 in the berval2tl_data() function in plugins/kdb/ldap/libkdb_ldap/ldap_principal2.c. The function performs an unsigned subtraction (bv_len - 2)…
New
|
CWE-191
Integer Underflow (Wrap or Wraparound)
|
CVE-2026-11850
|
2026-06-12 00:21 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
240
|
7.8 |
HIGH
Local
|
microsoft
|
windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2012 windows_server_2016 w…
|
Integer overflow or wraparound in Windows Internet (wininet.dll) allows an authorized attacker to elevate privileges locally.
New
|
CWE-190 CWE-416
Integer Overflow or Wraparound Use After Free
|
CVE-2026-45592
|
2026-06-12 00:21 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
241
|
8.8 |
HIGH
Network
|
-
|
-
|
Dulwich is a pure-Python implementation of the Git file formats and protocols. Versions starting with 0.10.0 and prior to 1.2.5 have an arbitrary file write leading to remote code execution when clon…
New
|
CWE-22
Path Traversal
|
CVE-2026-42305
|
2026-06-12 00:21 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
242
|
- |
-
|
-
|
-
|
Dulwich is a pure-Python implementation of the Git file formats and protocols. Starting in version 0.24.0 and prior to version 1.2.5, Dulwich's `ProcessMergeDriver` substitutes the file path (from th…
New
|
CWE-78
OS Command
|
CVE-2026-42563
|
2026-06-12 00:21 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
243
|
10.0 |
CRITICAL
Network
|
-
|
-
|
Boxlite is a sandbox service that allows users to create lightweight virtual machines (Boxes) and launch OCI containers within them to run untrusted code. Prior to version 0.9.0, Boxlite does not res…
New
|
CWE-284
Improper Access Control
|
CVE-2026-46695
|
2026-06-12 00:21 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
244
|
9.6 |
CRITICAL
Network
|
-
|
-
|
Boxlite is a sandbox service that allows users to create lightweight virtual machines (Boxes) and launch OCI containers within them to run untrusted code. Prior to version 0.9.0, Boxlite allows users…
New
|
CWE-22
Path Traversal
|
CVE-2026-46703
|
2026-06-12 00:21 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Boxlite is a sandbox service that allows users to create lightweight virtual machines (Boxes) and launch OCI containers within them to run untrusted code. In versions 0.8.2 and prior, Boxlite allows …
New
|
CWE-404
Improper Resource Shutdown or Release
|
CVE-2026-47213
|
2026-06-12 00:21 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246
|
3.3 |
LOW
Local
|
-
|
-
|
Dulwich is a pure-Python implementation of the Git file formats and protocols. Starting in version 0.24.0 and prior to version 1.2.5, dulwich.porcelain.format_patch(outdir=...) derives each patch fil…
New
|
CWE-22
Path Traversal
|
CVE-2026-47712
|
2026-06-12 00:21 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247
|
5.7 |
MEDIUM
Network
|
-
|
-
|
Dulwich is a pure-Python implementation of the Git file formats and protocols. Starting in version 0.1.0 and prior to version 1.2.5, a client with push access could push a tiny crafted thin pack (~17…
New
|
CWE-400 CWE-789
Uncontrolled Resource Consumption Memory Allocation with Excessive Size Value
|
CVE-2026-47734
|
2026-06-12 00:21 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248
|
7.5 |
HIGH
Network
|
-
|
-
|
Dulwich is a pure-Python implementation of the Git file formats and protocols. Starting in version 0.23.2 and prior to version 1.2.5, `dulwich.porcelain.submodule_update`, and by extension `porcelain…
New
|
CWE-22
Path Traversal
|
CVE-2026-52726
|
2026-06-12 00:21 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249
|
7.8 |
HIGH
Local
|
microsoft
|
windows_10_1809 windows_10_21h2 windows_10_22h2 windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2019 windows_server_2022 windows_server_2025
|
Use after free in Windows SDK allows an authorized attacker to elevate privileges locally.
New
|
CWE-190 CWE-416
Integer Overflow or Wraparound Use After Free
|
CVE-2026-45593
|
2026-06-12 00:14 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250
|
5.5 |
MEDIUM
Local
|
microsoft
|
windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2016 windows_server_2019 w…
|
Exposure of sensitive information to an unauthorized actor in Windows Application Identity (AppID) Subsystem allows an authorized attacker to disclose information locally.
New
|
CWE-200
Information Exposure
|
CVE-2026-45594
|
2026-06-12 00:13 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|