|
3651
|
7.5 |
HIGH
Network
|
jg-rp
|
python_liquid
|
Python Liquid is a Python engine for the Liquid template language. Prior to 2.2.0, the built-in FileSystemLoader and CachingFileSystemLoader do not guard against reading files outside their search pa…
|
CWE-22
Path Traversal
|
CVE-2026-45017
|
2026-06-3 09:43 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3652
|
- |
-
|
-
|
-
|
Rejected reason: This CVE is a duplicate of another CVE.
|
-
|
CVE-2026-42029
|
2026-06-3 07:16 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3653
|
7.5 |
HIGH
Network
|
-
|
-
|
The ARMember Premium plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter of the 'arm_directory_paging_action' AJAX action in all versions up to, and including, 7.3.1. This i…
|
CWE-89
SQL Injection
|
CVE-2026-5073
|
2026-06-3 05:56 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3654
|
6.5 |
MEDIUM
Network
|
-
|
-
|
The ARMember Premium plugin for WordPress is vulnerable to SQL Injection via the 'sSortDir_0' parameter of the `get_private_content_data` AJAX action in all versions up to, and including, 7.3.1. This…
|
CWE-89
SQL Injection
|
CVE-2026-5074
|
2026-06-3 05:56 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3655
|
9.8 |
CRITICAL
Network
|
-
|
-
|
The ARMember Premium plugin for WordPress is vulnerable to an insecure password reset mechanism in all versions up to, and including, 7.3.1. The plugin stores a plaintext copy of the password reset k…
|
CWE-287
Improper Authentication
|
CVE-2026-5076
|
2026-06-3 05:56 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3656
|
9.8 |
CRITICAL
Network
|
synology
|
beestation_os
|
Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in AdminCenter in Synology BeeStation OS before 1.3.2-65648 allows remote attackers to execute arbitrary code via …
|
CWE-120
Classic Buffer Overflow
|
CVE-2025-12686
|
2026-06-3 05:43 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3657
|
9.8 |
CRITICAL
Network
|
synology
|
diskstation_manager
|
Improper check for unusual or exceptional conditions vulnerability in SSO in Synology DiskStation Manager (DSM) before 7.2.2-72806-5 and 7.3.1-86003-1 (7.2.1-69057 is not affected) allows remote atta…
|
CWE-754
Improper Check for Unusual or Exceptional Conditions
|
CVE-2025-13392
|
2026-06-3 05:42 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3658
|
7.5 |
HIGH
Network
|
synology
|
c2_identity_edge_server
|
An Exposed Dangerous Method or Function vulnerability in Synology C2 Identity Edge Server package in DSM before 1.76.0-0307 allows remote attackers to obtain user credentials from the edge server.
|
CWE-749
Exposed Dangerous Method or Function
|
CVE-2025-14713
|
2026-06-3 05:41 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3659
|
8.6 |
HIGH
Network
|
synology
|
active_backup_for_business
|
A vulnerability in Active Backup for Business allows unauthorized remote attackers to read arbitrary files.
|
CWE-89
SQL Injection
|
CVE-2025-30028
|
2026-06-3 05:41 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3660
|
5.9 |
MEDIUM
Network
|
synology
|
safe_access
|
Improper neutralization of input during web page generation ('Cross-site Scripting') vulnerability in Safe Access in Synology Safe Access before 1.3.1-0329 allows remote authenticated users with admi…
|
CWE-79
Cross-site Scripting
|
CVE-2025-10466
|
2026-06-3 05:30 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3661
|
8.6 |
HIGH
Local
|
zed
|
zed
|
Zed is a code editor. Prior to 0.227.1, Zed IDE executes arbitrary commands when opening a folder with a malicious .git/config file that abuses the core.fsmonitor Git configuration option. This allow…
|
CWE-78
OS Command
|
CVE-2026-44465
|
2026-06-3 05:17 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3662
|
- |
-
|
-
|
-
|
In OpenStack Neutron before 28.0.1, the tagging controller enforces plural policy action names on single-tag write operations while the defined policy rules use singular names. The mismatched names e…
|
CWE-863
Incorrect Authorization
|
CVE-2026-49299
|
2026-06-3 05:16 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3663
|
- |
-
|
-
|
-
|
In OpenStack Swift before 2.36.2 and 2.37.2, s3api middleware enters an infinite loop when processing a truncated aws-chunked PUT request body. The StreamingInput class repeatedly appends an empty bu…
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2026-49017
|
2026-06-3 05:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3664
|
8.1 |
HIGH
Network
|
-
|
-
|
pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.9.1, when a PAM service is configured with deny_remote=false in pam_usb (commonly done for display manage…
|
CWE-863
Incorrect Authorization
|
CVE-2026-48064
|
2026-06-3 05:16 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3665
|
7.8 |
HIGH
Local
|
-
|
-
|
pam_usb provides hardware authentication for Linux using ordinary removable media. Prior to 0.8.7, pamusb-pinentry reads the PINENTRY_FALLBACK_APP environment variable and executes it directly withou…
|
CWE-78
OS Command
|
CVE-2026-44709
|
2026-06-3 05:16 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3666
|
8.6 |
HIGH
Local
|
zed
|
zed
|
Zed is a code editor. Prior to 0.229.0, Zed's terminal tool permission system can be bypassed via bash arithmetic expansion $((...)), allowing execution of arbitrary commands nested inside an allowli…
|
CWE-78
OS Command
|
CVE-2026-44466
|
2026-06-3 05:14 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3667
|
8.2 |
HIGH
Network
|
ibm
|
cognos_analytics cognos_transformer
|
IBM Cognos Analytics 11.2.0, 11.2.4, 12.0, and 12.1.0 and IBM Cognos Transformer 11.2.4, 12.0, and 12.1.0 are vulnerable to cross-site scripting (XSS). This vulnerability allows a remote attacker to …
|
CWE-79
Cross-site Scripting
|
CVE-2025-3633
|
2026-06-3 05:05 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3668
|
7.5 |
HIGH
Network
|
ibm
|
db2
|
IBM Db2 11.5.0 through 11.5.9, and 12.1.0 through 12.1.4 is vulnerable to a denial of service with a specially crafted query when autonomous transactions are enabled.
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2026-1718
|
2026-06-3 05:02 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3669
|
6.5 |
MEDIUM
Network
|
redhat samba
|
openshift_container_platform samba enterprise_linux
|
A flaw was found in Samba’s handling of NTFS-style reparse points on shares configured with read only = yes. Due to missing SMB-layer access checks, authenticated users with underlying filesystem wri…
|
CWE-284 NVD-CWE-noinfo
Improper Access Control
|
CVE-2026-1933
|
2026-06-3 05:01 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3670
|
6.8 |
MEDIUM
Local
|
synology
|
beedrive
|
Files or directories accessible to external parties vulnerability in redis-server component in Synology BeeDrive for desktop before 1.3.2-13814 allows local users to conduct denial-of-service attacks…
|
CWE-552
Files or Directories Accessible to External Parties
|
CVE-2024-11399
|
2026-06-3 04:55 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3671
|
7.5 |
HIGH
Network
|
ibm
|
infosphere_optim_test_data_fabrication
|
IBM InfoSphere Optim Test Data Fabrication 1.0.0, 1.0.0.1, 1.0.0.2, 1.0.2, 1.0.2.2, 1.0.2.3, 1.0.2.4, 1.0.2.5, 1.0.2.6, 1.0.2.7 could allow a remote attacker to traverse directories on the system. An…
|
CWE-22
Path Traversal
|
CVE-2026-3366
|
2026-06-3 04:50 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3672
|
7.8 |
HIGH
Local
|
ibm
|
netezza_performance_server_replication_services
|
IBM Netezza Performance Server Replication Services 3.0.2.0 through 3.0.5.0 allows an attacker with low‑privileged access to escalate their privileges to root. By exploiting this flaw, the attacker c…
|
CWE-250 NVD-CWE-noinfo
Execution with Unnecessary Privileges
|
CVE-2026-3623
|
2026-06-3 04:44 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3673
|
6.5 |
MEDIUM
Network
|
ibm
|
cloud_application_performance_managemen
|
IBM Cloud APM, Base Private 8.1.4 and IBM Cloud APM, Advanced Private 8.1.4 IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow an authenticated user to cause a denial of se…
|
CWE-1284
Improper Validation of Specified Quantity in Input
|
CVE-2026-3676
|
2026-06-3 04:41 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3674
|
3.7 |
LOW
Network
|
erlang
|
erlang\/otp
|
Improper Certificate Validation vulnerability in Erlang OTP public_key (pubkey_ocsp module) allows forged OCSP responses signed with an expired responder certificate to be accepted as valid.
OCSP re…
|
CWE-295 CWE-672
Improper Certificate Validation Operation on a Resource after Expiration or Release
|
CVE-2026-42791
|
2026-06-3 04:18 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3675
|
7.8 |
HIGH
Local
|
google
|
android
|
In performPreInstallChecks of InstallRepository.kt, there is a possible way to bypass MDM policy due to a logic error in the code. This could lead to local escalation of privilege with no additional …
|
CWE-693
Protection Mechanism Failure
|
CVE-2025-48652
|
2026-06-3 03:59 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3676
|
5.5 |
MEDIUM
Local
|
google
|
android
|
In isSameApp of NotificationManagerService.java, there is a possible persistent dos due to resource exhaustion. This could lead to local denial of service with no additional execution privileges need…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2025-48648
|
2026-06-3 03:59 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3677
|
3.3 |
LOW
Local
|
google
|
android
|
In multiple functions of KeyguardViewMediator.java , there is a possible way to bypass lockdown mode with screen pinning due to a logic error in the code. This could lead to local information disclos…
|
NVD-CWE-noinfo
|
CVE-2025-48616
|
2026-06-3 03:58 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3678
|
7.8 |
HIGH
Local
|
google
|
android
|
In multiple functions of PipTaskOrganizer.java, there is a possible way to launch an activity from the background due to a confused deputy. This could lead to local escalation of privilege with no ad…
|
CWE-441
Confused Deputy
|
CVE-2025-48570
|
2026-06-3 03:58 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3679
|
7.8 |
HIGH
Local
|
google
|
android
|
In multiple locations, there is a possible background activity launch due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges neede…
|
NVD-CWE-noinfo
|
CVE-2025-32348
|
2026-06-3 03:50 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3680
|
6.5 |
MEDIUM
Network
|
apache
|
airflow
|
A Dag author could either (a) create a symlink under their task's log directory pointing to an arbitrary file readable by the API server process (read-path attack — e.g. `/etc/passwd` or `airflow.cfg…
|
CWE-59
Link Following
|
CVE-2026-40861
|
2026-06-3 03:49 |
2026-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3681
|
7.2 |
HIGH
Network
|
apache
|
airflow
|
A bug in the login redirect route in Apache Airflow allowed authenticated users to craft URLs that bypassed the `is_safe_url` check, enabling redirection from a trusted Airflow domain to an attacker-…
|
CWE-601
Open Redirect
|
CVE-2026-40961
|
2026-06-3 03:49 |
2026-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3682
|
4.3 |
MEDIUM
Network
|
apache
|
airflow
|
The partitioned_dag_runs endpoints in the Airflow UI enforced only asset-level access control, not per-Dag authorization. An authenticated UI/API user with global Asset:read permission could enumerat…
|
CWE-862
Missing Authorization
|
CVE-2026-41014
|
2026-06-3 03:49 |
2026-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3683
|
7.5 |
HIGH
Network
|
apache
|
airflow
|
A bug in Apache Airflow's bulk Task Instances API (`PATCH/DELETE /api/v2/dags/{dag_id}/dagRuns/{dag_run_id}/taskInstances`) evaluated authorization against the `dag_id` resolved from the URL path whi…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-41084
|
2026-06-3 03:49 |
2026-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3684
|
9.1 |
CRITICAL
Network
|
apache
|
airflow
|
Apache Airflow's official documentation at `core-concepts/dag-run.html` ("Passing Parameters when triggering Dags") showed a verbatim `BashOperator(bash_command="echo value: {{ dag_run.conf['conf1'] …
|
CWE-1336
Improper Neutralization of Special Elements Used in a Template Engine
|
CVE-2026-42252
|
2026-06-3 03:48 |
2026-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3685
|
6.2 |
MEDIUM
Local
|
google
|
android
|
In createSessionInternal of PackageInstallerService.java, there is a possible to update a Device Policy Controller (DPC) into an invalid directory due to a path traversal error. This could lead to lo…
|
CWE-22 CWE-269
Path Traversal Improper Privilege Management
|
CVE-2026-0055
|
2026-06-3 03:47 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3686
|
6.5 |
MEDIUM
Network
|
google
|
android
|
In multiple functions of ubsan_throwing_runtime.cpp, there is a possible way to cause a crash due to an integer overflow. This could lead to remote denial of service with no additional execution priv…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2026-0052
|
2026-06-3 03:47 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3687
|
6.5 |
MEDIUM
Network
|
google
|
android
|
In multiple functions of ubsan_throwing_runtime.cpp, there is a possible way to cause a system crash due to improper input validation. This could lead to remote denial of service with no additional e…
|
CWE-20
Improper Input Validation
|
CVE-2026-0051
|
2026-06-3 03:47 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3688
|
3.3 |
LOW
Local
|
google
|
android
|
In handleBondStateChanged of AdapterService.java, there is a possible sensitive information disclosure due to a permissions bypass. This could lead to local information disclosure with no additional …
|
CWE-269
Improper Privilege Management
|
CVE-2026-0050
|
2026-06-3 03:47 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3689
|
6.8 |
MEDIUM
Local
|
google
|
android
|
In hide of WindowState.java, there is a possible way to trick the user into approving permissions due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no addition…
|
CWE-269
Improper Privilege Management
|
CVE-2026-0048
|
2026-06-3 03:46 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3690
|
6.2 |
MEDIUM
Local
|
google
|
android
|
In InputInterceptor of Letterbox.java, there is a possible way to trick a user into accepting a permission due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no…
|
CWE-269
Improper Privilege Management
|
CVE-2026-0046
|
2026-06-3 03:46 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3691
|
6.5 |
MEDIUM
Network
|
google
|
android
|
In multiple functions of ubsan_throwing_runtime.cpp, there is a possible way to cause the system to crash due to an integer overflow. This could lead to remote denial of service with no additional ex…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2026-0044
|
2026-06-3 03:46 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3692
|
5.5 |
MEDIUM
Local
|
google
|
android
|
In multiple functions of ubsan_throwing_runtime.cpp, there is a possible persistent denial of service due to an integer overflow. This could lead to local escalation of privilege with no additional e…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2026-0043
|
2026-06-3 03:45 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3693
|
5.5 |
MEDIUM
Local
|
google
|
android
|
In multiple functions of ubsan_throwing_runtime.cpp, there is a possible persistent denial of service due to resource exhaustion. This could lead to local denial of service with no additional executi…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2026-0042
|
2026-06-3 03:45 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3694
|
6.5 |
MEDIUM
Network
|
google
|
android
|
In multiple functions of ubsan_throwing_runtime.cpp, there is a possible UBSan failure due to an integer overflow. This could lead to remote denial of service with no additional execution privileges …
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2026-0041
|
2026-06-3 03:45 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3695
|
6.5 |
MEDIUM
Network
|
google
|
android
|
In multiple functions of ubsan_throwing_runtime.cpp, there is a possible way to cause a crash due to an integer overflow. This could lead to remote denial of service with no additional execution priv…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2026-0040
|
2026-06-3 03:44 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3696
|
6.5 |
MEDIUM
Network
|
google
|
android
|
In multiple functions of ubsan_throwing_runtime.cpp, there is a possible persistent denial of service due to an integer overflow. This could lead to remote denial of service with no additional execut…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2026-0039
|
2026-06-3 03:44 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3697
|
5.5 |
MEDIUM
Local
|
google
|
android
|
In multiple functions of AccessibilityManagerService.java, there is a possible persistent denial of service due to improper input validation. This could lead to local denial of service with no additi…
|
CWE-20
Improper Input Validation
|
CVE-2026-0018
|
2026-06-3 03:44 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3698
|
7.1 |
HIGH
Network
|
ibm
|
engineering_lifecycle_management
|
IBM Engineering Lifecycle Management 7.0.3 Interim Fix 001 through Interim Fix 021, 7.1.0 Interim Fix 001 through Interim Fix 009, and 7.2.0 and 7.2.0 Interim Fix 001 is vulnerable to an XML exter…
|
CWE-611
XXE
|
CVE-2026-3603
|
2026-06-3 03:44 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3699
|
7.5 |
HIGH
Network
|
viewcomponent
|
view_component
|
view_component is a framework for building reusable, testable, and encapsulated view components in Ruby on Rails. From 3.0.0 to 4.9.0, the system test entrypoint canonicalizes a user-controlled file …
|
CWE-187
Partial String Comparison
|
CVE-2026-44837
|
2026-06-3 03:43 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3700
|
3.3 |
LOW
Local
|
google
|
android
|
In updateProvidersWhenServiceRemoved of CredentialManagerService.java, there is a possible way to override settings across users due to a permissions bypass. This could lead to local information disc…
|
CWE-269
Improper Privilege Management
|
CVE-2026-0016
|
2026-06-3 03:41 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|