|
251
|
5.4 |
MEDIUM
Network
|
microsoft
|
windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2012 windows_server_2016 w…
|
Protection mechanism failure in Windows Mark of the Web (MOTW) allows an unauthorized attacker to bypass a security feature over a network.
New
|
CWE-693
Protection Mechanism Failure
|
CVE-2026-45595
|
2026-06-12 00:10 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252
|
7.0 |
HIGH
Local
|
microsoft
|
windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2012 windows_server_2016 w…
|
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
New
|
CWE-362 CWE-416
Race Condition Use After Free
|
CVE-2026-45596
|
2026-06-12 00:07 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253
|
7.0 |
HIGH
Local
|
microsoft
|
windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2022 windows_server_2025
|
Concurrent execution using shared resource with improper synchronization ('race condition') in UI Automation Manager (uiamanager.dll) allows an authorized attacker to elevate privileges locally.
New
|
CWE-362
Race Condition
|
CVE-2026-45597
|
2026-06-12 00:03 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
254
|
7.0 |
HIGH
Local
|
microsoft
|
windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2012 windows_server_2016 w…
|
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
New
|
CWE-362
Race Condition
|
CVE-2026-45598
|
2026-06-12 00:00 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255
|
8.1 |
HIGH
Network
|
microsoft
|
windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2012 windows_server_2016 w…
|
Use after free in Universal Plug and Play (upnp.dll) allows an unauthorized attacker to execute code over a network.
New
|
CWE-416
Use After Free
|
CVE-2026-45599
|
2026-06-11 23:57 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256
|
7.1 |
HIGH
Local
|
-
|
-
|
A malicious application may cause unexpected changes in memory shared between processes. A memory corruption issue was addressed with improved state management. This issue is fixed in macOS Monterey …
New
|
CWE-362
Race Condition
|
CVE-2022-26758
|
2026-06-11 23:43 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257
|
3.5 |
LOW
Physics
|
-
|
-
|
A person with access to a Mac may be able to bypass Login Window. A consistency issue was addressed with improved state handling. This issue is fixed in macOS Monterey 12.4.
New
|
CWE-287
Improper Authentication
|
CVE-2022-48575
|
2026-06-11 23:43 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
258
|
5.3 |
MEDIUM
Local
|
-
|
-
|
Improper input validation for DIMM serial presence detect (SPD) metadata could allow an attacker with physical access, ring0 access on a system with a non-compliant DIMM, or control over the Root of …
New
|
CWE-20
Improper Input Validation
|
CVE-2024-21944
|
2026-06-11 23:43 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
259
|
- |
-
|
-
|
-
|
A privilege escalation vulnerability in Apache OFBiz allows a low-privileged authenticated user to obtain higher privileges
This issue affects Apache OFBiz: before 24.09.07.
Users are recommended…
New
|
CWE-285
Improper Authorization
|
CVE-2026-47342
|
2026-06-11 23:43 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
260
|
3.7 |
LOW
Network
|
-
|
-
|
A vulnerability was determined in TwiN gatus 5.36.0. Impacted is the function setSessionCookie of the file security/oidc.go of the component OIDC Session Cookie Handler. Executing a manipulation can …
New
|
CWE-614 CWE-1004
Sensitive Cookie in HTTPS Session Without 'Secure' Attribute Sensitive Cookie Without 'HttpOnly' Flag
|
CVE-2026-11956
|
2026-06-11 23:42 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
261
|
4.7 |
MEDIUM
Network
|
-
|
-
|
The Open User Map PRO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'oum_location_notification' parameter in versions up to, and including, 1.4.31 due to insufficient inpu…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-2827
|
2026-06-11 23:42 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
262
|
8.1 |
HIGH
Network
|
-
|
-
|
The UpdraftPlus: WP Backup & Migration Plugin plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.26.4 via the UpdraftPlus_Remote_Communications_V2::wp…
New
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2026-10795
|
2026-06-11 23:42 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
263
|
7.1 |
HIGH
Network
|
-
|
-
|
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in WPVibes WP Mail Log allows DOM-Based XSS.
This issue affects WP Mail Log: from n/a through 1.0.2.
New
|
CWE-79
Cross-site Scripting
|
CVE-2023-33999
|
2026-06-11 23:42 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264
|
5.3 |
MEDIUM
Network
|
-
|
-
|
Authorization bypass through User-Controlled key vulnerability in Essential Plugin WP Logo Showcase Responsive Slider and Carousel allows Exploiting Incorrectly Configured Access Control Security Lev…
New
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2023-40200
|
2026-06-11 23:42 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265
|
4.3 |
MEDIUM
Network
|
-
|
-
|
Cross-Site request forgery (CSRF) vulnerability in Magepeople inc. WpEvently allows Cross Site Request Forgery.
This issue affects WpEvently: from n/a through 4.1.2.
New
|
CWE-352
Origin Validation Error
|
CVE-2024-32110
|
2026-06-11 23:42 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266
|
5.4 |
MEDIUM
Network
|
-
|
-
|
Missing Authorization vulnerability in TemplateHouse Soledad allows Accessing Functionality Not Properly Constrained by ACLs.
This issue affects Soledad: from n/a through 8.2.5.
New
|
CWE-862
Missing Authorization
|
CVE-2022-42479
|
2026-06-11 23:42 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267
|
4.6 |
MEDIUM
Network
|
-
|
-
|
Cross-Site request forgery (CSRF) vulnerability in YITH YITH WooCommerce Product Slider Carousel allows Cross Site Request Forgery.
This issue affects YITH WooCommerce Product Slider Carousel: from …
New
|
CWE-352
Origin Validation Error
|
CVE-2022-44630
|
2026-06-11 23:42 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268
|
5.4 |
MEDIUM
Network
|
-
|
-
|
Missing Authorization vulnerability in BeRocket Advanced AJAX Product Filters allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects Advanced AJAX Product Filter…
New
|
CWE-862
Missing Authorization
|
CVE-2022-45813
|
2026-06-11 23:42 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269
|
4.3 |
MEDIUM
Network
|
-
|
-
|
Cross-Site request forgery (CSRF) vulnerability in weDevs WooCommerce Conversion Tracking allows Cross Site Request Forgery.
This issue affects WooCommerce Conversion Tracking: from n/a through 2.0.…
New
|
CWE-352
Origin Validation Error
|
CVE-2022-47150
|
2026-06-11 23:42 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270
|
5.4 |
MEDIUM
Network
|
-
|
-
|
Missing Authorization vulnerability in ThemeHunk Contact Form & Lead Form Elementor Builder allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects Contact Form &…
New
|
CWE-862
Missing Authorization
|
CVE-2023-25969
|
2026-06-11 23:42 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
271
|
4.3 |
MEDIUM
Network
|
-
|
-
|
Missing Authorization vulnerability in Sparkle WP MetroStore metrostore allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects MetroStore: from n/a through 1.3.2.
New
|
CWE-862
Missing Authorization
|
CVE-2023-32959
|
2026-06-11 23:42 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
272
|
6.1 |
MEDIUM
Network
|
-
|
-
|
draw.io is a configurable diagramming and whiteboarding application. Prior to version 29.7.12, a crafted .drawio file can execute arbitrary JavaScript in the editor's origin when the file is opened. …
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-46642
|
2026-06-11 23:16 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
273
|
8.1 |
HIGH
Network
|
-
|
-
|
Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, ommit d4d10006 ("Expand validation to block .. in config_file_name and configver …
New
|
CWE-22 CWE-697
Path Traversal Incorrect Comparison
|
CVE-2026-45569
|
2026-06-11 23:16 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
274
|
8.1 |
HIGH
Network
|
-
|
-
|
FrankenPHP is a modern application server for PHP. From version 1.11.2 to before version 1.12.3, the splitPos() function in cgi.go misuses golang.org/x/text/search with search.IgnoreCase when the req…
New
|
CWE-20 CWE-176 CWE-178
Improper Input Validation Improper Handling of Unicode Encoding Improper Handling of Case Sensitivity
|
CVE-2026-45062
|
2026-06-11 23:16 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
275
|
10.0 |
CRITICAL
Network
|
-
|
-
|
An OS Command Injection vulnerability in Ivanti Sentry before the R10.5.2, R10.6.2 and R10.7.1 versions allows a remote unauthenticated user to achieve root-level remote code execution
New
|
CWE-78
OS Command
|
CVE-2026-10520
|
2026-06-11 23:16 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
276
|
8.8 |
HIGH
Network
|
nsa
|
ghidra
|
Ghidra before 12.1 contains a SQL injection vulnerability in BSim filter types that concatenate user-supplied values directly into SQL queries without escaping or parameterization. Remote attackers c…
New
|
CWE-89
SQL Injection
|
CVE-2026-52758
|
2026-06-11 22:58 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
277
|
7.8 |
HIGH
Local
|
adobe
|
substance_3d_sampler
|
Substance3D - Sampler versions 6.0.0 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of…
New
|
CWE-787
Out-of-bounds Write
|
CVE-2026-48306
|
2026-06-11 22:53 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
278
|
7.8 |
HIGH
Local
|
adobe
|
substance_3d_sampler
|
Substance3D - Sampler versions 6.0.0 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of…
New
|
CWE-787
Out-of-bounds Write
|
CVE-2026-48305
|
2026-06-11 22:51 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
279
|
7.8 |
HIGH
Local
|
adobe
|
substance_3d_sampler
|
Substance3D - Sampler versions 6.0.0 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of…
New
|
CWE-787
Out-of-bounds Write
|
CVE-2026-34710
|
2026-06-11 22:50 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
280
|
5.5 |
MEDIUM
Local
|
nsa
|
ghidra
|
Ghidra before 12.1.1 contains an uncontrolled memory allocation vulnerability in the Mach-O binary parser that allows attackers to cause denial of service. An attacker can supply a crafted Mach-O bin…
New
|
CWE-789
Memory Allocation with Excessive Size Value
|
CVE-2026-52759
|
2026-06-11 22:28 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
281
|
8.8 |
HIGH
Network
|
jenkins
|
jenkins
|
In Jenkins 2.567 and earlier, LTS 2.555.2 and earlier, it is possible for attackers to have Jenkins deserialize arbitrary types defined in Jenkins core or plugins from an attacker-controlled `config.…
New
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-53435
|
2026-06-11 22:26 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
282
|
4.3 |
MEDIUM
Network
|
jenkins
|
jenkins
|
Jenkins 2.567 and earlier, LTS 2.555.2 and earlier improperly determines that a redirect URL after login is legitimately pointing to Jenkins when it contains relative path segments (`./` or `../`), a…
New
|
CWE-601
Open Redirect
|
CVE-2026-53436
|
2026-06-11 22:24 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283
|
4.3 |
MEDIUM
Network
|
jenkins
|
jenkins
|
Jenkins 2.567 and earlier, LTS 2.555.2 and earlier improperly determines that a redirect URL after login is legitimately pointing to Jenkins when it contains tab or newline characters between `//`, a…
New
|
CWE-601
Open Redirect
|
CVE-2026-53437
|
2026-06-11 22:23 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284
|
4.3 |
MEDIUM
Network
|
jenkins
|
jenkins
|
A missing permission check in Jenkins 2.567 and earlier, LTS 2.555.2 and earlier allows attackers with Item/Cancel permission, but lacking Item/Read permission, to cancel queue items they do not have…
New
|
CWE-862
Missing Authorization
|
CVE-2026-53438
|
2026-06-11 22:21 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285
|
4.3 |
MEDIUM
Network
|
jenkins
|
jenkins
|
Missing permission checks in Jenkins 2.567 and earlier, LTS 2.555.2 and earlier allow attackers with Overall/Read permission to determine other users' configured timezone and to enumerate view names …
New
|
CWE-862
Missing Authorization
|
CVE-2026-53439
|
2026-06-11 22:06 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286
|
7.8 |
HIGH
Local
|
adobe
|
substance_3d_sampler
|
Substance3D - Sampler versions 6.0.0 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of…
New
|
CWE-787
Out-of-bounds Write
|
CVE-2026-34709
|
2026-06-11 22:05 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287
|
7.8 |
HIGH
Local
|
-
|
-
|
LMDeploy is a toolkit for compressing, deploying, and serving large language models. In versions 0.12.3 and prior, hardcoded "trust_remote_code=True" enables HF supply-chain RCE without user opt-in. …
New
|
CWE-94 CWE-915 CWE-1188
Code Injection Improperly Controlled Modification of Dynamically-Determined Object Attributes Insecure Default Initialization of Resource
|
CVE-2026-46517
|
2026-06-11 21:16 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288
|
- |
-
|
-
|
-
|
A vulnerability in the affected NETGEAR gaming routers allows attackers with the ability to intercept and tamper with traffic between the router and the Internet, to execute code on the device.
New
|
CWE-20
Improper Input Validation
|
CVE-2026-9213
|
2026-06-11 16:16 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289
|
- |
-
|
-
|
-
|
An improper implementation of TLS certificate validation vulnerability found in NETGEAR's ReadyCloud client app which could allow an attacker to perform attacker-in-the-middle (MiTM) style attacks im…
New
|
CWE-325
Missing Required Cryptographic Step
|
CVE-2026-0420
|
2026-06-11 16:16 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290
|
- |
-
|
-
|
-
|
An insufficient input validation vulnerability in certain NETGEAR router models as listed allows an authenticated administrator with local network access to submit crafted input that bypasses intende…
New
|
CWE-20
Improper Input Validation
|
CVE-2026-0416
|
2026-06-11 16:16 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
291
|
- |
-
|
-
|
-
|
A buffer overflow vulnerability due to insufficient input validation in the listed NETGEAR models allows authenticated administrators connected to the local network to make unauthorized modification …
New
|
CWE-121
Stack-based Buffer Overflow
|
CVE-2026-0413
|
2026-06-11 16:16 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
292
|
- |
-
|
-
|
-
|
An information disclosure vulnerability in the NETGEAR Orbi satellites (RBR/RBE/RBS Series) could allow a user connected to your network to gain administrator access to the Orbi router. The listed NE…
New
|
CWE-200
Information Exposure
|
CVE-2026-0411
|
2026-06-11 16:16 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
293
|
- |
-
|
-
|
-
|
Insufficient authentication and input validation in the listed NETGEAR models allow users connected to the local network to execute commands impacting the product's confidentiality or change certain …
New
|
CWE-20 CWE-306
Improper Input Validation Missing Authentication for Critical Function
|
CVE-2026-9212
|
2026-06-11 14:16 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
294
|
8.8 |
HIGH
Network
|
flowiseai
|
flowise
|
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, all CRUD endpoints for OpenAI Assistants Vector Store have no authentication middlewar…
Update
|
CWE-862
Missing Authorization
|
CVE-2026-46444
|
2026-06-11 13:08 |
2026-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
295
|
6.5 |
MEDIUM
Network
|
flowiseai
|
flowise
|
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, when credentials are fetched with a credentialName filter parameter, the encryptedData…
Update
|
CWE-200
Information Exposure
|
CVE-2026-46443
|
2026-06-11 13:08 |
2026-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
296
|
9.9 |
CRITICAL
Network
|
flowiseai
|
flowise
|
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, POST /api/v1/node-custom-function lacks route-level authorization, allowing any authen…
Update
|
CWE-94
Code Injection
|
CVE-2026-46442
|
2026-06-11 13:07 |
2026-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
297
|
9.6 |
CRITICAL
Network
|
flowiseai
|
flowise
|
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, a mass assignment vulnerability exists in the assistant update endpoint of FlowiseAI. …
Update
|
CWE-284 CWE-639 CWE-915
Improper Access Control Authorization Bypass Through User-Controlled Key Improperly Controlled Modification of Dynamically-Determined Object Attributes
|
CVE-2026-46441
|
2026-06-11 13:06 |
2026-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
298
|
9.1 |
CRITICAL
Network
|
flowiseai
|
flowise
|
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, the checkBasicAuth endpoint validates credentials in plaintext without rate limiting a…
Update
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2026-46440
|
2026-06-11 13:06 |
2026-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
299
|
9.8 |
CRITICAL
Network
|
apache
|
http_server
|
Buffer Underwrite vulnerability in Apache HTTP Server on crafted regular expressions in the configuration.
This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67.
Users are recommended to…
Update
|
CWE-124
Buffer Underflow
|
CVE-2026-44631
|
2026-06-11 13:01 |
2026-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
300
|
7.3 |
HIGH
Network
|
apache
|
http_server
|
Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in the mod_proxy_ftp module in Apache HTTP Server with an attacker controlled backend FTP server.
This issue affects undefined: f…
Update
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2026-44186
|
2026-06-11 13:01 |
2026-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|