|
3601
|
6.5 |
MEDIUM
Network
|
springaicommunity
|
mcp_security
|
mcp-security provides Security and Authorization support for Model Context Protocol in Spring AI. Prior to 0.1.9, the mcp-security framework fails to implement the mandatory SSRF mitigations outlined…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-45609
|
2026-06-3 23:08 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3602
|
3.3 |
LOW
Local
|
google
|
android
|
In setTo of ResourceTypes.cpp, there is a possible read out of bounds due to an incorrect bounds check. This could lead to local information disclosure with no additional execution privileges needed.…
|
CWE-120
Classic Buffer Overflow
|
CVE-2026-0056
|
2026-06-3 22:47 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3603
|
7.8 |
HIGH
Local
|
google
|
android
|
In addWindow of WindowManagerService.java, there is a possible tapjacking issue due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privi…
|
CWE-1021
Improper Restriction of Rendered UI Layers or Frames
|
CVE-2026-28577
|
2026-06-3 22:47 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3604
|
5.5 |
MEDIUM
Local
|
google
|
android
|
In multiple functions of ubsan_throwing_runtime.cpp, there is a possible way to cause a permanent denial of service due to a logic error in the code. This could lead to local denial of service with n…
|
NVD-CWE-noinfo
|
CVE-2026-0067
|
2026-06-3 22:46 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3605
|
8.0 |
HIGH
Adjacent
|
google
|
android
|
In multiple functions of sdp_discovery.cc, there is a possible way to achieve code execution due to a heap buffer overflow. This could lead to remote (proximal/adjacent) code execution with no additi…
|
CWE-122
Heap-based Buffer Overflow
|
CVE-2026-0059
|
2026-06-3 22:46 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3606
|
5.5 |
MEDIUM
Local
|
google
|
android
|
In updateState of GraphicsDriverEnableAngleAsSystemDriverController.java, there is a possible persistent dos issue due to an unusual root cause. This could lead to local denial of service with no add…
|
NVD-CWE-noinfo
|
CVE-2026-0060
|
2026-06-3 22:46 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3607
|
7.8 |
HIGH
Local
|
google
|
android
|
In getAppLabel of ForgetDeviceDialogFragment.java, there is a possible trick the user into forgetting a device due to misleading or insufficient UI. This could lead to local escalation of privilege w…
|
CWE-451
User Interface (UI) Misrepresentation of Critical Information
|
CVE-2026-0096
|
2026-06-3 22:41 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3608
|
8.0 |
HIGH
Adjacent
|
google
|
android
|
In multiple locations, there is a possible way to bypass user interaction when pairing an LE device due to a logic error. This could lead to remote (proximal/adjacent) escalation of privilege with no…
|
CWE-693
Protection Mechanism Failure
|
CVE-2026-0097
|
2026-06-3 22:41 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3609
|
7.8 |
HIGH
Local
|
google
|
android
|
In getCallingPackageName of Shared.java, there is a possible way to bypass activity start restrictions due to a confused deputy. This could lead to local escalation of privilege with no additional ex…
|
CWE-441
Confused Deputy
|
CVE-2026-0098
|
2026-06-3 22:40 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3610
|
7.8 |
HIGH
Local
|
google
|
android
|
In onNullBinding of HostEmulationManager.java, there is a possible way to launch an activity from the background due to a logic error in the code. This could lead to local escalation of privilege wit…
|
CWE-273
Improper Check for Dropped Privileges
|
CVE-2026-0099
|
2026-06-3 22:40 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3611
|
7.8 |
HIGH
Local
|
google
|
android
|
In Load of LoadedArsc.cpp, there is a possible out of bounds write due to a heap buffer overflow. This could lead to local escalation of privilege with no additional execution privileges needed. User…
|
CWE-122
Heap-based Buffer Overflow
|
CVE-2026-0100
|
2026-06-3 22:39 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3612
|
5.5 |
MEDIUM
Local
|
google
|
android
|
In multiple functions of DevicePolicyManagerService.java, there is a possible desync from persistence due to improper input validation. This could lead to local denial of service with no additional e…
|
CWE-20
Improper Input Validation
|
CVE-2026-28578
|
2026-06-3 22:35 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3613
|
7.8 |
HIGH
Local
|
google
|
android
|
In multiple functions, there is a possible desync in persistence due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. Use…
|
CWE-120
Classic Buffer Overflow
|
CVE-2026-28580
|
2026-06-3 22:35 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3614
|
4.0 |
MEDIUM
Local
|
google
|
android
|
In fixInitiatingUserIfNecessary of CallIntentProcessor.java, there is a possible way to make an emergency call due to a logic error in the code. This could lead to local with null execution privileg…
|
CWE-476
NULL Pointer Dereference
|
CVE-2026-28581
|
2026-06-3 22:29 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3615
|
3.3 |
LOW
Local
|
google
|
android
|
In multiple functions of AppOpsService.java, there is a possible missing permission check due to a permissions bypass. This could lead to local information disclosure with no additional execution pri…
|
CWE-269
Improper Privilege Management
|
CVE-2026-28586
|
2026-06-3 22:26 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3616
|
8.0 |
HIGH
Adjacent
|
-
|
-
|
A flaw was found in Samba’s certificate auto-enrollment Group Policy handling. When certificate auto-enrollment is enabled, Samba may retrieve a CA certificate over an unencrypted HTTP connection and…
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2026-3012
|
2026-06-3 15:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3617
|
8.8 |
HIGH
Network
|
-
|
-
|
@pensar/apex <= 0.0.58 is vulnerable to OS command injection via the smart_enumerate tool. The createSmartEnumerateTool() function in src/core/agent/tools.ts constructs a shell command by concatenati…
|
CWE-78
OS Command
|
CVE-2026-36044
|
2026-06-3 13:17 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3618
|
8.3 |
HIGH
Network
|
google
|
chrome
|
Use after free in Passwords in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafte…
|
CWE-416
Use After Free
|
CVE-2026-10000
|
2026-06-3 11:32 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3619
|
6.5 |
MEDIUM
Network
|
google
|
chrome
|
Uninitialized Use in GPU in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromi…
|
CWE-457
Use of Uninitialized Variable
|
CVE-2026-10008
|
2026-06-3 11:31 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3620
|
5.0 |
MEDIUM
Network
|
google
|
chrome
|
Inappropriate implementation in Input in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTM…
|
CWE-346
Origin Validation Error
|
CVE-2026-10010
|
2026-06-3 11:31 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3621
|
3.1 |
LOW
Network
|
google
|
chrome
|
Inappropriate implementation in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Ch…
|
CWE-200
Information Exposure
|
CVE-2026-10011
|
2026-06-3 11:30 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3622
|
8.3 |
HIGH
Network
|
google
|
chrome
|
Out of bounds read in Headless in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML p…
|
CWE-125
Out-of-bounds Read
|
CVE-2026-10017
|
2026-06-3 11:30 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3623
|
9.0 |
CRITICAL
Network
|
google
|
chrome
|
Use after free in Bluetooth in Google Chrome on Mac prior to 148.0.7778.216 allowed an attacker who convinced a user to install a malicious extension to potentially perform a sandbox escape via a cra…
|
CWE-416
Use After Free
|
CVE-2026-9881
|
2026-06-3 11:30 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3624
|
8.3 |
HIGH
Network
|
google
|
chrome
|
Insufficient validation of untrusted input in UI in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox es…
|
CWE-20
Improper Input Validation
|
CVE-2026-9885
|
2026-06-3 11:29 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3625
|
9.6 |
CRITICAL
Network
|
google
|
chrome
|
Use after free in Base in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
|
CWE-416
Use After Free
|
CVE-2026-9886
|
2026-06-3 11:29 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3626
|
8.3 |
HIGH
Network
|
google
|
chrome
|
Use after free in XR in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML …
|
CWE-416
Use After Free
|
CVE-2026-9890
|
2026-06-3 11:25 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3627
|
8.3 |
HIGH
Network
|
google
|
chrome
|
Use after free in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Ch…
|
CWE-416
Use After Free
|
CVE-2026-9893
|
2026-06-3 11:24 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3628
|
8.3 |
HIGH
Network
|
google
|
chrome
|
Use after free in GPU in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chr…
|
CWE-416
Use After Free
|
CVE-2026-9894
|
2026-06-3 11:20 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3629
|
8.3 |
HIGH
Network
|
google
|
chrome
|
Out of bounds read in GPU in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. …
|
CWE-125
Out-of-bounds Read
|
CVE-2026-9895
|
2026-06-3 11:20 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3630
|
8.3 |
HIGH
Network
|
google
|
chrome
|
Use after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (C…
|
CWE-416
Use After Free
|
CVE-2026-9899
|
2026-06-3 11:20 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3631
|
8.3 |
HIGH
Network
|
google
|
chrome
|
Out of bounds write in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML pag…
|
CWE-787
Out-of-bounds Write
|
CVE-2026-9900
|
2026-06-3 11:17 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3632
|
8.3 |
HIGH
Network
|
google
|
chrome
|
Use after free in Accessibility in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML …
|
CWE-416
Use After Free
|
CVE-2026-9902
|
2026-06-3 11:16 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3633
|
5.0 |
MEDIUM
Network
|
google
|
chrome
|
Insufficient validation of untrusted input in Site Isolation in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a…
|
CWE-20
Improper Input Validation
|
CVE-2026-9903
|
2026-06-3 11:16 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3634
|
8.3 |
HIGH
Network
|
google
|
chrome
|
Use after free in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)
|
CWE-416
Use After Free
|
CVE-2026-9904
|
2026-06-3 11:16 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3635
|
5.5 |
MEDIUM
Local
|
element
|
synapse
|
Synapse is an open source Matrix homeserver implementation. Prior to 1.152.1, local authenticated users can cause Synapse to starve other requests of CPU and lead to other requests failing, causing o…
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2026-45078
|
2026-06-3 11:15 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3636
|
6.5 |
MEDIUM
Network
|
encode
|
starlette
|
Starlette is a lightweight ASGI framework/toolkit. Prior to version 1.0.1, the HTTP `Host` request header was not validated before being used to reconstruct `request.url`. Because the routing algorit…
|
CWE-444
HTTP Request Smuggling
|
CVE-2026-48710
|
2026-06-3 11:14 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3637
|
8.5 |
HIGH
Network
|
apache
|
directory_ldap_api
|
It was identified that the LDAP client implementation in version 2.1.7 does not verify if the server certificate matches the intended LDAP
hostname. While the underlying code validates the certifica…
|
CWE-297
Improper Validation of Certificate with Host Mismatch
|
CVE-2026-35563
|
2026-06-3 11:12 |
2026-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3638
|
8.8 |
HIGH
Network
|
apache
|
airflow
|
A bug in Apache Airflow's XCom PATCH endpoint `PATCH /api/v2/xcomEntries/{key}` allowed an authenticated UI/API user with XCom write permission on a Dag to set XCom entries under reserved key names (…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-42359
|
2026-06-3 11:07 |
2026-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3639
|
7.3 |
HIGH
Network
|
apache
|
airflow
|
Apache Airflow's scheduler-side deadline-reference decoder (`SerializedCustomReference.deserialize_reference`) imported and dispatched arbitrary class paths drawn from DAG-author-controlled serialize…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-45360
|
2026-06-3 11:06 |
2026-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3640
|
6.5 |
MEDIUM
Network
|
apache
|
airflow
|
A bug in Apache Airflow's auth manager logout handling left previously-issued JWT tokens valid after the user clicked logout in the UI: the logout flow for `FabAuthManager` and `KeycloakAuthManager` …
|
CWE-613
Insufficient Session Expiration
|
CVE-2026-48726
|
2026-06-3 11:06 |
2026-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3641
|
5.9 |
MEDIUM
Network
|
apache
|
airflow
|
Apache Airflow's EmailOperator and the underlying `airflow.utils.email` helpers established SMTP STARTTLS connections without verifying the remote certificate when the deployment used `[email] smtp_s…
|
CWE-295
Improper Certificate Validation
|
CVE-2026-49267
|
2026-06-3 11:06 |
2026-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3642
|
8.8 |
HIGH
Network
|
apache
|
airflow
|
A bug in Apache Airflow's KubernetesExecutor caused JWT tokens used by worker pods to authenticate against the Execution API to be passed to the worker container as command-line arguments visible in …
|
CWE-538
File and Directory Information Exposure
|
CVE-2026-49298
|
2026-06-3 11:06 |
2026-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3643
|
6.5 |
MEDIUM
Network
|
apache
|
calcite
|
Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Apache Calcite.
This issue affects Apache Calcite: from 1.5.0 before 1.42.
Users are recommended …
|
CWE-470
Unsafe Reflection
|
CVE-2026-46718
|
2026-06-3 11:04 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3644
|
4.3 |
MEDIUM
Network
|
apache
|
kafka
|
An improper authorization vulnerability has been identified in Apache Kafka.
The implementation of the CONSUMER_GROUP_DESCRIBE (69) API validates the DESCRIBE operation on the GROUP resource instead…
|
CWE-285
Improper Authorization
|
CVE-2026-41115
|
2026-06-3 11:04 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3645
|
6.5 |
MEDIUM
Network
|
sharpcompress_project
|
sharpcompress
|
SharpCompress is a fully managed C# library to deal with many compression types and formats. In 0.47.4 and earlier, a path traversal vulnerability in IArchive.WriteToDirectory() allows a malicious ar…
|
CWE-22
Path Traversal
|
CVE-2026-44788
|
2026-06-3 11:02 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3646
|
6.5 |
MEDIUM
Network
|
ibm
|
guardium_data_protection
|
IBM Guardium Data Protection 12.2.1, and 12.2.2 's add-on feature of Guardium Data Protection named "Long Term Retention" (LTR) can expose sensitive credentials in debug mode.
|
CWE-200 NVD-CWE-noinfo
Information Exposure
|
CVE-2026-8405
|
2026-06-3 10:13 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3647
|
5.3 |
MEDIUM
Network
|
ibm
|
security_directory_integrator
|
IBM SDI 7.2.0.0 through 7.2.0.14 and IBM Security Directory Integrator 10.0.0.0 through 10.0.0.2 could allow a remote attacker to obtain sensitive information when a detailed technical error message …
|
CWE-209
Information Exposure Through an Error Message
|
CVE-2024-28765
|
2026-06-3 10:13 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3648
|
7.8 |
HIGH
Local
|
zed
|
zed
|
Zed is a code editor. Prior to 0.229.0, Zed's terminal tool permission system can be bypassed by prepending environment variable assignments to allowlisted commands, hijacking program behavior (e.g.,…
|
CWE-78 CWE-184
OS Command Incomplete Blacklist
|
CVE-2026-44463
|
2026-06-3 10:11 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3649
|
8.8 |
HIGH
Network
|
zed
|
zed
|
Zed is a code editor. Prior to 0.229.0, Zed's terminal tool permission system can be bypassed via bash variable expansion chaining (${var@P}), allowing arbitrary command execution under an allowliste…
|
CWE-184
Incomplete Blacklist
|
CVE-2026-44462
|
2026-06-3 10:00 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3650
|
8.6 |
HIGH
Local
|
zed
|
zed
|
Zed is a code editor. Prior to 0.227.1, Zed builds SSH/WSL remote commands as a shell command string that starts with exec env ..., but environment variable keys are inserted without shell quoting or…
|
CWE-78
OS Command
|
CVE-2026-44461
|
2026-06-3 09:58 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|