|
301
|
7.3 |
HIGH
Network
|
apache
|
http_server
|
Buffer Over-read vulnerability in Apache HTTP Server via outbound OCSP requests to an attacker controlled OCSP server
This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67.
Users are rec…
Update
|
CWE-126
Buffer Over-read
|
CVE-2026-44185
|
2026-06-11 13:01 |
2026-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
302
|
5.5 |
MEDIUM
Local
|
apache
|
http_server
|
Improper Privilege Management vulnerability in Apache HTTP Server 2.4.67 and earlier allows local .htaccess authors to read files with the privileges of the httpd user.
This issue affects Apache HTT…
Update
|
CWE-269
Improper Privilege Management
|
CVE-2026-44119
|
2026-06-11 13:01 |
2026-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
303
|
6.5 |
MEDIUM
Network
|
apache
|
http_server
|
Out-of-bounds Read vulnerability in Apache HTTP Server with mod_headers and mod_mime and multiple response languages.
This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67.
Update
|
CWE-125
Out-of-bounds Read
|
CVE-2026-43951
|
2026-06-11 13:00 |
2026-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
304
|
8.1 |
HIGH
Network
|
flowiseai
|
flowise
|
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, a mass assignment vulnerability exists in the chatflow update endpoint of FlowiseAI. T…
Update
|
CWE-284 CWE-639 CWE-915
Improper Access Control Authorization Bypass Through User-Controlled Key Improperly Controlled Modification of Dynamically-Determined Object Attributes
|
CVE-2026-42863
|
2026-06-11 12:58 |
2026-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
305
|
5.0 |
MEDIUM
Network
|
flowiseai
|
flowise
|
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, a mass assignment vulnerability exists in the tool update endpoint of FlowiseAI. The e…
Update
|
CWE-284 CWE-639 CWE-915
Improper Access Control Authorization Bypass Through User-Controlled Key Improperly Controlled Modification of Dynamically-Determined Object Attributes
|
CVE-2026-42862
|
2026-06-11 12:56 |
2026-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
306
|
9.6 |
CRITICAL
Network
|
flowiseai
|
flowise
|
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, a mass assignment vulnerability exists in the variable update endpoint of FlowiseAI. T…
Update
|
CWE-284 CWE-639 CWE-915
Improper Access Control Authorization Bypass Through User-Controlled Key Improperly Controlled Modification of Dynamically-Determined Object Attributes
|
CVE-2026-42861
|
2026-06-11 12:53 |
2026-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
307
|
5.4 |
MEDIUM
Network
|
microsoft
|
sharepoint_server
|
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-45468
|
2026-06-11 11:43 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
308
|
9.1 |
CRITICAL
Network
|
-
|
-
|
No cwe for this issue in Windows DHCP Server allows an unauthorized attacker to perform tampering over a network.
New
|
CWE-229
Improper Handling of Values
|
CVE-2026-45602
|
2026-06-11 07:16 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
309
|
7.5 |
HIGH
Network
|
-
|
-
|
Race in V8 in Google Chrome prior to 144.0.7559.99 allowed a remote attacker to potentially exploit type confusion via a crafted HTML page. (Chromium security severity: High)
New
|
CWE-362
Race Condition
|
CVE-2026-1220
|
2026-06-11 07:16 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
310
|
4.3 |
MEDIUM
Network
|
buffalo
|
open_xdmod
|
OpenXDMoD is an open framework for collecting and analyzing HPC metrics. Prior to version 11.0.3, a flaw in Open XDMoD's access control logic allows an attacker to submit a crafted HTTPS POST request…
Update
|
CWE-284 NVD-CWE-noinfo
Improper Access Control
|
CVE-2026-45776
|
2026-06-11 06:07 |
2026-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
311
|
9.8 |
CRITICAL
Network
|
buffalo
|
open_xdmod
|
OpenXDMoD is an open framework for collecting and analyzing HPC metrics. Starting in version 9.5.0 and prior to version 11.0.3, an attacker can remotely execute arbitrary system commands on the web s…
Update
|
CWE-78
OS Command
|
CVE-2026-45777
|
2026-06-11 06:06 |
2026-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
312
|
5.4 |
MEDIUM
Network
|
buffalo
|
open_xdmod
|
OpenXDMoD is an open framework for collecting and analyzing HPC metrics. Prior to version 11.0.3, an authenticated attacker can inject malicious JavaScript into their Open XDMoD user profile and abus…
Update
|
CWE-79
Cross-site Scripting
|
CVE-2026-45778
|
2026-06-11 06:05 |
2026-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
313
|
9.8 |
CRITICAL
Network
|
buffalo
|
open_xdmod
|
OpenXDMoD is an open framework for collecting and analyzing HPC metrics. An SQL injection vulnerability exists in Open XDMoD versions prior to 10.0.3 that allows an unauthenticated remote attacker to…
Update
|
CWE-89
SQL Injection
|
CVE-2026-45779
|
2026-06-11 06:04 |
2026-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
314
|
6.8 |
MEDIUM
Physics
|
microsoft
|
windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2012 windows_server_2016 w…
|
Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.
New
|
CWE-284 NVD-CWE-noinfo
Improper Access Control
|
CVE-2026-45658
|
2026-06-11 05:59 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
315
|
- |
-
|
-
|
-
|
Atril Document Viewer is the default document reader of the MATE desktop environment for Linux. A single-click remote code execution vulnerability in versions prior to 1.26.3 and 1.28.4 allows an att…
New
|
CWE-77 CWE-88 CWE-829
Command Injection Argument Injection Inclusion of Functionality from Untrusted Control Sphere
|
CVE-2026-46529
|
2026-06-11 05:58 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
316
|
- |
-
|
-
|
-
|
A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user.
New
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-44963
|
2026-06-11 05:58 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
317
|
7.1 |
HIGH
Adjacent
|
microsoft
|
windows_server_2012 windows_server_2016 windows_server_2019 windows_server_2022 windows_server_2025
|
Integer overflow or wraparound in Windows Kerberos allows an authorized attacker to execute code over an adjacent network.
New
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2026-47288
|
2026-06-11 05:57 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
318
|
9.8 |
CRITICAL
Network
|
microsoft
|
windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2012 windows_server_2016 w…
|
Integer overflow or wraparound in Windows HTTP.sys allows an unauthorized attacker to execute code over a network.
New
|
CWE-122 CWE-190
Heap-based Buffer Overflow Integer Overflow or Wraparound
|
CVE-2026-47291
|
2026-06-11 05:54 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
319
|
5.4 |
MEDIUM
Network
|
microsoft
|
sharepoint_server
|
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
New
|
CWE-74 CWE-79
Injection Cross-site Scripting
|
CVE-2026-47634
|
2026-06-11 05:49 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
320
|
5.4 |
MEDIUM
Network
|
microsoft
|
sharepoint_server
|
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-47636
|
2026-06-11 05:47 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
321
|
9.8 |
CRITICAL
Network
|
microsoft
|
windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2022 windows_server_2025
|
Use after free in Windows Kernel allows an unauthorized attacker to execute code over a network.
New
|
CWE-122 CWE-416
Heap-based Buffer Overflow Use After Free
|
CVE-2026-45657
|
2026-06-11 05:44 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
322
|
7.8 |
HIGH
Local
|
microsoft
|
windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2012 windows_server_2016 w…
|
Protection mechanism failure in Windows UEFI allows an authorized attacker to bypass a security feature locally.
New
|
CWE-693
Protection Mechanism Failure
|
CVE-2026-45656
|
2026-06-11 05:42 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
323
|
5.4 |
MEDIUM
Network
|
microsoft
|
sharepoint_server
|
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-45453
|
2026-06-11 05:32 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
324
|
8.8 |
HIGH
Network
|
microsoft
|
sharepoint_server
|
Improper limitation of a pathname to a restricted directory ('path traversal') in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
New
|
CWE-22
Path Traversal
|
CVE-2026-45454
|
2026-06-11 05:31 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
325
|
5.4 |
MEDIUM
Network
|
microsoft
|
sharepoint_server
|
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-45462
|
2026-06-11 05:30 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
326
|
5.4 |
MEDIUM
Network
|
microsoft
|
sharepoint_server
|
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-45464
|
2026-06-11 05:29 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
327
|
5.4 |
MEDIUM
Network
|
microsoft
|
sharepoint_server
|
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-45465
|
2026-06-11 05:26 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
328
|
8.8 |
HIGH
Adjacent
|
-
|
-
|
A flaw was found in dracut. A remote attacker on the adjacent network can exploit this vulnerability by providing specially crafted DHCP (Dynamic Host Configuration Protocol) options, such as a malic…
New
|
CWE-78
OS Command
|
CVE-2026-6893
|
2026-06-11 05:22 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
329
|
7.5 |
HIGH
Network
|
-
|
-
|
SQLFluff is a modular SQL linter and auto-formatter with support for multiple dialects and templated code. Prior to version 4.1.0, in deployments where untrusted users can provide SQL queries to be l…
New
|
CWE-674
Uncontrolled Recursion
|
CVE-2026-46373
|
2026-06-11 05:21 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
330
|
7.5 |
HIGH
Network
|
-
|
-
|
SQLFluff is a modular SQL linter and auto-formatter with support for multiple dialects and templated code. Prior to version 4.2.0, in deployments where untrusted users can provide SQL queries to be l…
New
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2026-46374
|
2026-06-11 05:21 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
331
|
4.6 |
MEDIUM
Network
|
-
|
-
|
Weblate is a web based localization tool. Prior to version 2026.5, Weblate's live search preview renders unit source and context as HTML without escaping. Any contributor whose content reaches those …
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-45106
|
2026-06-11 05:21 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
332
|
- |
-
|
-
|
-
|
Snappy is a PHP library allowing thumbnail, snapshot or PDF generation from a url or a html page. Prior to version 1.7.0, there is a SSRF and local file read vulnerability via the xsl-style-sheet opt…
New
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-46683
|
2026-06-11 05:21 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
333
|
5.9 |
MEDIUM
Network
|
-
|
-
|
Weblate is a web based localization tool. From version 5.15 to before version 2026.6, Weblate's VCS_RESTRICT_PRIVATE did not properly account for some transitional IPv6 ranges, multicast addresses, o…
New
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-50127
|
2026-06-11 05:21 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
334
|
5.3 |
MEDIUM
Network
|
-
|
-
|
Unbounded memory allocation in the CRYPTO frame reassembler in s2n-quic before 1.8.2 may allow an unauthenticated remote actor to cause a denial of service (degraded availability) by sending crafted …
New
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2026-10740
|
2026-06-11 05:19 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
335
|
- |
-
|
-
|
-
|
Metrics::Any::Adapter::Statsd versions before 0.04 for Perl does not protect against metric injections.
The statsd protocol (and extensions) allow mutiple metrics,separated by newlines, to be sent p…
New
|
CWE-93
CRLF Injection
|
CVE-2026-50637
|
2026-06-11 05:19 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
336
|
- |
-
|
-
|
-
|
Metrics::Any::Adapter::DogStatsd versions before 0.04 for Perl does not protect against metric injections.
The statsd protocol (and extensions such as dogstatsd) allow mutiple metrics,separated by n…
New
|
CWE-93
CRLF Injection
|
CVE-2026-50638
|
2026-06-11 05:19 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
337
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Metrics::Any::Adapter::SignalFx versions before 0.04 for Perl does not protect against metric injections.
The statsd protocol (and extensions such as dogstatsd) allow mutiple metrics,separated by ne…
New
|
CWE-93
CRLF Injection
|
CVE-2026-50639
|
2026-06-11 05:19 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
338
|
7.5 |
HIGH
Network
|
-
|
-
|
Shenzhen Tenda Technology Co., Ltd Tenda W20E v15.11.0.6 was discovered to contain a buffer overflow in the wewifiWhiteUserInfo parameter of the formAddWewifiWhiteUser function. This vulnerability al…
New
|
CWE-120
Classic Buffer Overflow
|
CVE-2026-36818
|
2026-06-11 05:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
339
|
7.5 |
HIGH
Network
|
-
|
-
|
Shenzhen Tenda Technology Co., Ltd Tenda W15E v15.11.0.10 was discovered to contain a buffer overflow in the webAuthWhiteUserInfo parameter of the formAddWebAuthWhiteUser function. This vulnerability…
New
|
CWE-120
Classic Buffer Overflow
|
CVE-2026-36817
|
2026-06-11 05:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
340
|
7.5 |
HIGH
Network
|
-
|
-
|
Shenzhen Tenda Technology Co., Ltd Tenda W15E v15.11.0.10 was discovered to contain a buffer overflow in the wewifiWhiteUserInfo parameter of the formAddWewifiWhiteUser function. This vulnerability a…
New
|
CWE-120
Classic Buffer Overflow
|
CVE-2026-36816
|
2026-06-11 05:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
341
|
7.5 |
HIGH
Network
|
-
|
-
|
Shenzhen Tenda Technology Co., Ltd Tenda W15E v15.11.0.10 was discovered to contain a buffer overflow in the hostname parameter of the formSetNetCheckTools function. This vulnerability allows attacke…
New
|
CWE-120
Classic Buffer Overflow
|
CVE-2026-36815
|
2026-06-11 05:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
342
|
7.5 |
HIGH
Network
|
-
|
-
|
Shenzhen Tenda Technology Co., Ltd Tenda W15E v15.11.0.10 was discovered to contain a buffer overflow in the picName parameter of the formDelwebAuthPic function. This vulnerability allows attackers t…
New
|
CWE-120
Classic Buffer Overflow
|
CVE-2026-36811
|
2026-06-11 05:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
343
|
7.5 |
HIGH
Network
|
-
|
-
|
Shenzhen Tenda Technology Co., Ltd Tenda W15E v15.11.0.10 was discovered to contain a buffer overflow in the gotoUrl parameter of the formPortalAuth function. This vulnerability allows attackers to c…
New
|
CWE-120
Classic Buffer Overflow
|
CVE-2026-36810
|
2026-06-11 05:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
344
|
7.5 |
HIGH
Network
|
-
|
-
|
Shenzhen Tenda Technology Co., Ltd Tenda W15E v15.11.0.10 was discovered to contain a buffer overflow in the webAuthWhiteID parameter of the formModifyWebAuthWhiteUser function. This vulnerability al…
New
|
CWE-120
Classic Buffer Overflow
|
CVE-2026-36809
|
2026-06-11 05:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
345
|
7.5 |
HIGH
Network
|
-
|
-
|
Shenzhen Tenda Technology Co., Ltd Tenda W15E v15.11.0.10 was discovered to contain a buffer overflow in the webAuthUserInfo parameter of the formAddWebAuthUser function. This vulnerability allows at…
New
|
CWE-120
Classic Buffer Overflow
|
CVE-2026-36808
|
2026-06-11 05:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
346
|
7.5 |
HIGH
Network
|
-
|
-
|
Shenzhen Tenda Technology Co., Ltd Tenda W15E v15.11.0.10 was discovered to contain a buffer overflow in the webAuthUserPwd parameter of the formAddWebAuthUser function. This vulnerability allows att…
New
|
CWE-120
Classic Buffer Overflow
|
CVE-2026-36807
|
2026-06-11 05:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
347
|
7.5 |
HIGH
Network
|
-
|
-
|
Shenzhen Tenda Technology Co., Ltd Tenda G0 v15.11.0.5 was discovered to contain a buffer overflow in the portalAuth parameter of the formPortalAuth function. This vulnerability allows attackers to c…
New
|
CWE-120
Classic Buffer Overflow
|
CVE-2026-36799
|
2026-06-11 05:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
348
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Shenzhen Tenda Technology Co., Ltd Tenda G0 v15.11.0.5 was discovered to contain multiple stack overflows in the formSetDebugCfgr function via the enable, level, and module parameters. These vulnerab…
New
|
CWE-121
Stack-based Buffer Overflow
|
CVE-2026-36798
|
2026-06-11 05:16 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
349
|
7.5 |
HIGH
Network
|
-
|
-
|
Shenzhen Tenda Technology Co., Ltd Tenda G0 v15.11.0.5 was discovered to contain a stack overflow in the IPMacBindRuleIp parameter of the formIPMacBindModify function. This vulnerability allows attac…
New
|
CWE-120
Classic Buffer Overflow
|
CVE-2026-36797
|
2026-06-11 05:16 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
350
|
7.5 |
HIGH
Network
|
-
|
-
|
Shenzhen Tenda Technology Co., Ltd Tenda G0 v15.11.0.5 was discovered to contain a stack overflow in the picCropName parameter of the formCropAndSetWewifiPic function. This vulnerability allows attac…
New
|
CWE-120
Classic Buffer Overflow
|
CVE-2026-36796
|
2026-06-11 05:16 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|