|
3201
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Improper Authentication (Authentication Bypass) exists in Neterbit NW-431F Router 20241014-IR03 and before. The router uses a weak/predictable cookie value for authentication. By modifying the cookie…
|
CWE-384
Session Fixation
|
CVE-2025-67446
|
2026-06-5 03:16 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3202
|
2.7 |
LOW
Network
|
element
|
synapse
|
Synapse is an open source Matrix homeserver implementation. Prior to 1.152.1, in federated rooms, malicious homeservers can craft room events in such a way that prevents Synapse from providing full h…
|
CWE-20
Improper Input Validation
|
CVE-2026-45076
|
2026-06-5 03:04 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3203
|
9.9 |
CRITICAL
Network
|
flowintel
|
flowintel
|
FlowIntel up to version 3.3.0 contains a server-side request forgery (SSRF) vulnerability in the external reference URL probe functionality in app/case/task.py. An attacker who can submit an external…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-9813
|
2026-06-5 03:03 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3204
|
5.4 |
MEDIUM
Network
|
appsmith
|
appsmith
|
Appsmith’s SQL query editor’s autocomplete functionality fails to sanitize database object names before rendering them in innerHTML, allowing an authenticated Developer to inject persistent XSS by a …
|
CWE-79
Cross-site Scripting
|
CVE-2026-7299
|
2026-06-5 02:41 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3205
|
6.5 |
MEDIUM
Adjacent
|
tp-link
|
tapo_c200_firmware
|
TP-Link Tapo C200 v5 contains a stack-based buffer overflow flaw in RTSP authentication handling due to improper validation of Authorization header field lengths, which can be triggered by a crafted …
|
CWE-121
Stack-based Buffer Overflow
|
CVE-2026-1871
|
2026-06-5 02:41 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3206
|
7.8 |
HIGH
Local
|
nvidia
|
nvtabular
|
NVIDIA NVTabular contains a vulnerability where an attacker could cause improper deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampe…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-24221
|
2026-06-5 02:41 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3207
|
7.8 |
HIGH
Local
|
nvidia
|
nvtabular
|
NVIDIA NVTabular contains a vulnerability where an attacker could cause improper deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampe…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-24237
|
2026-06-5 02:40 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3208
|
6.1 |
MEDIUM
Physics
|
dell
|
thinos
|
Dell ThinOS 10, versions prior to ThinOS10 2602_10.0765, contain an Improper Access control vulnerability. An unauthenticated attacker with physical access could potentially exploit this vulnerabilit…
|
CWE-284
Improper Access Control
|
CVE-2026-40713
|
2026-06-5 02:37 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3209
|
7.8 |
HIGH
Local
|
dell
|
thinos
|
Dell ThinOS 10, versions prior to ThinOS10 2602_10.0765, contain an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, le…
|
CWE-284
Improper Access Control
|
CVE-2026-40715
|
2026-06-5 02:29 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3210
|
7.5 |
HIGH
Network
|
mozilla
|
firefox
|
Incorrect boundary conditions in the Graphics: Text component. This vulnerability was fixed in Firefox 151.0.3.
|
CWE-119
Incorrect Access of Indexable Resource ('Range Error')
|
CVE-2026-10701
|
2026-06-5 02:25 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3211
|
5.3 |
MEDIUM
Network
|
-
|
-
|
OpenTelemetry-Go is the Go implementation of OpenTelemetry. Versions 1.41.0 and 1.43.0 removed raw-length rejection and it causes `Parse` to process arbitrarily large/invalid baggage headers and log …
|
CWE-789
Memory Allocation with Excessive Size Value
|
CVE-2026-41178
|
2026-06-5 02:16 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3212
|
7.1 |
HIGH
Physics
|
-
|
-
|
GNCC GP5 v7.1.76 was discovered to store pre-signed Backblaze B2 upload URLs (PUT requests) in plaintext to the serial console. This allows physically-proximate attackers to extract these active toke…
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2026-36176
|
2026-06-5 02:16 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3213
|
6.8 |
MEDIUM
Physics
|
-
|
-
|
An issue in the U-Boot component of GNCC GP5 v7.1.76 allows physically-proximate attackers to bypass authentication and gain root access via interrupting the boot sequence and injecting a crafted str…
|
CWE-20 CWE-288
Improper Input Validation Authentication Bypass Using an Alternate Path or Channel
|
CVE-2026-36175
|
2026-06-5 02:16 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3214
|
9.1 |
CRITICAL
Network
|
ibm
|
websphere_application_server
|
IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to identity spoofing.
|
CWE-290
Authentication Bypass by Spoofing
|
CVE-2026-8644
|
2026-06-5 01:58 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3215
|
9.0 |
CRITICAL
Network
|
ibm
|
websphere_application_server
|
IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to potential remote code execution due to deserialization of untrusted data via JAX-WS endpoints with WS-Security.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-9319
|
2026-06-5 01:57 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3216
|
9.0 |
CRITICAL
Network
|
ibm
|
websphere_application_server
|
IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to remote code execution caused by the bypass of security controls.
|
CWE-94
Code Injection
|
CVE-2026-9311
|
2026-06-5 01:53 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3217
|
8.5 |
HIGH
Network
|
ibm
|
websphere_application_server
|
IBM WebSphere Application Server 9.0, and 8.5 is affected by an improper validation of user-supplied data during deserialization using the SAML Web Single Sign-On component. This could result in remo…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-9330
|
2026-06-5 01:52 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3218
|
5.5 |
MEDIUM
Local
|
pypa
|
pip
|
pip would treat console_scripts and gui_scripts as paths instead of file names without sanitizing the resolved absolute path to the installation directory, leading to entry points being installed out…
|
CWE-22
Path Traversal
|
CVE-2026-8643
|
2026-06-5 01:52 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3219
|
6.8 |
MEDIUM
Network
|
nextcloud
|
nextcloud_server
|
Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 31.0.0 to before 31.0.12, and 32.0.0 to before 32.0.3, a missing check of a relation allowed authenticate…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-45810
|
2026-06-5 01:51 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3220
|
7.1 |
HIGH
Network
|
nextcloud
|
tables
|
Nextcloud is an open source content collaboration platform. From versions 0.9.0 to before 0.9.7, and 1.0.0 to before 1.0.2, a missing sanitization in the Tables app allowed a user with access to the …
|
CWE-89
SQL Injection
|
CVE-2026-45722
|
2026-06-5 01:50 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3221
|
5.9 |
MEDIUM
Network
|
nextcloud
|
nextcloud_server
|
Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.9, and 33.0.0 to before 33.0.3, a pre-2FA session cookie (created after successful …
|
CWE-287
Improper Authentication
|
CVE-2026-45691
|
2026-06-5 01:50 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3222
|
5.9 |
MEDIUM
Network
|
nextcloud
|
nextcloud_server
|
Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.9, and 33.0.0 to before 33.0.3, an authentication bypass vulnerability allowed atta…
|
CWE-287
Improper Authentication
|
CVE-2026-45690
|
2026-06-5 01:50 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3223
|
8.2 |
HIGH
Network
|
nextcloud
|
tables
|
Nextcloud is an open source content collaboration platform. From versions 0.7.0 to before 0.7.7, 0.8.0 to before 0.8.10, 0.9.0 to before 0.9.8, and 1.0.0 to before 1.0.4, an authenticated attacker wi…
|
CWE-89
SQL Injection
|
CVE-2026-45545
|
2026-06-5 01:50 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3224
|
4.3 |
MEDIUM
Network
|
nextcloud
|
tables
|
Nextcloud is an open source content collaboration platform. From version 0.8.0 to before version 1.0.4, the view filter criteria is exposed to users with read-only permissions in Nextcloud Tables. Th…
|
CWE-1230
Exposure of Sensitive Information Through Metadata
|
CVE-2026-45544
|
2026-06-5 01:47 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3225
|
5.3 |
MEDIUM
Network
|
nextcloud
|
forms
|
Nextcloud is an open source content collaboration platform. From version 4.3.0 to before version 5.2.7, a removed collaborator retains unauthorized read access to uploaded respondent files for the af…
|
CWE-552
Files or Directories Accessible to External Parties
|
CVE-2026-45543
|
2026-06-5 01:43 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3226
|
5.3 |
MEDIUM
Network
|
-
|
-
|
Impact: The morgan logging middleware's :remote-user token extracts the Basic auth username from the Authorization request header and writes it to the log stream without neutralizing control characte…
|
CWE-117
Improper Output Neutralization for Logs
|
CVE-2026-5078
|
2026-06-5 01:40 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3227
|
- |
-
|
-
|
-
|
SWUpdate before 2026.05 is affected by a time-of-check time-of-use (TOCTOU) race condition that allows local unprivileged attackers to escalate privileges to root or install untrusted contents using …
|
CWE-367
Time-of-check Time-of-use (TOCTOU) Race Condition
|
CVE-2025-41259
|
2026-06-5 01:40 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3228
|
7.2 |
HIGH
Network
|
-
|
-
|
There is a vulnerability in the Supermicro BMC SMTP service at Supermicro AS-2115HS-TNR.
An attacker may obtain administrator privileges and inject specially crafted characters into the SMTP servic…
|
CWE-78
OS Command
|
CVE-2026-3820
|
2026-06-5 01:40 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3229
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was identified in wonderwhy-er DesktopCommanderMCP 0.2.37. This affects the function readFileFromUrl of the file src/tools/filesystem.ts of the component read_file. Such manipulation …
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-10690
|
2026-06-5 01:37 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3230
|
- |
-
|
-
|
-
|
An HTML injection vulnerability in the notification email for "Slow Redirect" and "Cloned Website" Canarytokens exists in Thinkst Applied Research Canarytokens, enabling Interface Manipulation, Cross…
|
CWE-74
Injection
|
CVE-2026-10729
|
2026-06-5 01:37 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3231
|
7.3 |
HIGH
Network
|
-
|
-
|
A vulnerability was found in crmeb crmeb_java 1.4. Affected is the function RestTemplate.getForEntity of the file crmeb-common/src/main/java/com/zbkj/common/utils/RestTemplateUtil.java of the compone…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-10771
|
2026-06-5 01:37 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3232
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A security vulnerability has been detected in EIPStackGroup OpENer up to 2.3.0. Affected is the function CreateMessageRouterRequestStructure of the file cipmessagerouter.c of the component SendRRData…
|
CWE-119 CWE-416
Incorrect Access of Indexable Resource ('Range Error') Use After Free
|
CVE-2026-10703
|
2026-06-5 01:35 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3233
|
4.3 |
MEDIUM
Network
|
-
|
-
|
A security flaw has been discovered in wonderwhy-er DesktopCommanderMCP up to 0.2.38. This impacts an unknown function of the file src/search-manager.ts of the component start_search. Performing a ma…
|
CWE-400 CWE-1333
Uncontrolled Resource Consumption Inefficient Regular Expression Complexity
|
CVE-2026-10691
|
2026-06-5 01:35 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3234
|
3.1 |
LOW
Network
|
-
|
-
|
A flaw has been found in dask up to 3.0. Affected by this issue is the function nunique_approx of the file dask/dataframe/hyperloglog.py of the component HLL Handler. This manipulation causes resourc…
|
CWE-400 CWE-404
Uncontrolled Resource Consumption Improper Resource Shutdown or Release
|
CVE-2026-10705
|
2026-06-5 01:35 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3235
|
3.6 |
LOW
Local
|
-
|
-
|
A weakness has been identified in PaddlePaddle FastDeploy up to 2.4.1. Affected by this issue is the function hash_features of the file fastdeploy/multimodal/hasher.py of the component MultimodalHash…
|
CWE-327 CWE-328
Use of a Broken or Risky Cryptographic Algorithm Use of Weak Hash
|
CVE-2026-10800
|
2026-06-5 01:35 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3236
|
3.6 |
LOW
Local
|
-
|
-
|
A security vulnerability has been detected in modelscope ms-swift up to 4.2.0. This affects the function Template._save_pil_image of the file swift/template/base.py of the component PIL Image Cache K…
|
CWE-327 CWE-328
Use of a Broken or Risky Cryptographic Algorithm Use of Weak Hash
|
CVE-2026-10801
|
2026-06-5 01:35 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3237
|
7.3 |
HIGH
Network
|
-
|
-
|
A vulnerability was identified in ealpha072 Student-Management-System up to 01451bd7a2f58cdda07bd0b86e3967582e3ecd08. Affected by this issue is some unknown functionality of the file admin/config.php…
|
CWE-287
Improper Authentication
|
CVE-2026-10777
|
2026-06-5 01:32 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3238
|
3.6 |
LOW
Local
|
-
|
-
|
A vulnerability was detected in zilliztech GPTCache up to 0.1.44. Affected by this issue is the function BufferedReader.peek of the file gptcache/processor/pre.py of the component Cache Key Handler. …
|
CWE-327 CWE-328
Use of a Broken or Risky Cryptographic Algorithm Use of Weak Hash
|
CVE-2026-10812
|
2026-06-5 01:32 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3239
|
3.6 |
LOW
Local
|
-
|
-
|
A flaw has been found in LMCache up to 0.4.6. This affects the function hex_hash_to_int16 of the file lmcache/integration/vllm/utils.py of the component KV Cache Handler. Executing a manipulation can…
|
CWE-327 CWE-328
Use of a Broken or Risky Cryptographic Algorithm Use of Weak Hash
|
CVE-2026-10813
|
2026-06-5 01:32 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3240
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was found in LakshayD02 Hostel-Management-System-PHP up to f87e67c283bab6f718faf2fec6ae39a13bd7036b. This issue affects some unknown processing of the file hostel/index.php of the com…
|
CWE-862 CWE-863
Missing Authorization Incorrect Authorization
|
CVE-2026-10815
|
2026-06-5 01:32 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3241
|
5.9 |
MEDIUM
Network
|
-
|
-
|
FastNetMon Community Edition through 1.2.9 contains an out-of-bounds read in the IPv4 packet parser. In src/simple_packet_parser_ng.cpp, after validating that the packet contains at least sizeof(ipv4…
|
CWE-125
Out-of-bounds Read
|
CVE-2026-48682
|
2026-06-5 01:28 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3242
|
7.5 |
HIGH
Network
|
-
|
-
|
An integer underflow in the BGPUpdate.DecodeFromBytes function (/bgp/bgp.go) of gobgp v4.3.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted BGP UPDATE message.
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2026-37462
|
2026-06-5 01:28 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3243
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A Cross Site Scripting vulnerability exists in the Kimi AI v1.0 web interface's 'Preview' feature. The application fails to properly sanitize or encode HTML/JavaScript payloads generated by the AI mo…
|
CWE-79
Cross-site Scripting
|
CVE-2026-39107
|
2026-06-5 01:28 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3244
|
9.8 |
CRITICAL
Network
|
-
|
-
|
CrowCpp Crow through v1.3.1 HTTP is vulnerable to response header injection via unvalidated response header values.
|
CWE-113
HTTP Response Splitting
|
CVE-2026-38967
|
2026-06-5 01:26 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3245
|
9.8 |
CRITICAL
Network
|
-
|
-
|
An OS command injection vulnerability in the app.py component of openlabs docker-wkhtmltopdf-aas up to commit 9f50579 allows attackers to execute arbitrary commands via a crafted POST request.
|
CWE-78
OS Command
|
CVE-2026-36576
|
2026-06-5 01:26 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3246
|
6.1 |
MEDIUM
Network
|
-
|
-
|
Northern.tech CFEngine Enterprise 3.24.3 before 3.24.4 and 3.27.0 before 3.27.1 allows XSS.
|
CWE-79
Cross-site Scripting
|
CVE-2026-33553
|
2026-06-5 01:25 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3247
|
5.4 |
MEDIUM
Network
|
-
|
-
|
LIBPNG is a reference library for use in applications that process PNG (Portable Network Graphics) raster image files. In version 1.8.0, three inter-frame chunk discard paths in the push-mode APNG pa…
|
CWE-436
Interpretation Conflict
|
CVE-2026-40930
|
2026-06-5 01:23 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3248
|
9.6 |
CRITICAL
Network
|
-
|
-
|
An undocumented debug CGI endpoint in T3 Technology CPE models T625Pro v1.0.07, T6825G v1.0.03 allows unauthenticated attackers to execute arbitrary system commands as root via supplying a crafted HT…
|
CWE-78
OS Command
|
CVE-2026-35906
|
2026-06-5 01:23 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3249
|
8.8 |
HIGH
Network
|
-
|
-
|
Improper Access Control, Missing Authorization vulnerability in Kurt Software Studio WriteUp Mobile App allows Accessing Functionality Not Properly Constrained by ACLs.
This issue affects WriteUp Mo…
|
CWE-284 CWE-862
Improper Access Control Missing Authorization
|
CVE-2026-5228
|
2026-06-5 01:23 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3250
|
9.9 |
CRITICAL
Network
|
-
|
-
|
OpenStack Mistral through 22.0.0 allows Arbitrary Remote Code Execution when the API is exposed. There are endpoints that allow code execution, which can lead to exfiltration of service credentials.
|
CWE-863
Incorrect Authorization
|
CVE-2026-41283
|
2026-06-5 01:21 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|