|
3751
|
- |
-
|
-
|
-
|
Klaw is a self-service Apache Kafka Topic Management/Governance tool/portal. Prior to version 2.10.4, improper access control allows disclosure of password hash. This issue has been patched in versio…
|
CWE-200 CWE-284
Information Exposure Improper Access Control
|
CVE-2026-45080
|
2026-06-3 02:15 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3752
|
7.5 |
HIGH
Network
|
-
|
-
|
NiceGUI is a Python-based UI framework. Prior to version 3.12.0, ui.restructured_text() renders reStructuredText server-side with Docutils without disabling file insertion directives. When a NiceGUI …
|
CWE-200
Information Exposure
|
CVE-2026-45553
|
2026-06-3 02:15 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3753
|
5.3 |
MEDIUM
Network
|
-
|
-
|
NiceGUI is a Python-based UI framework. Prior to version 3.12.0, two FastAPI routes that serve per-component static assets in NiceGUI accept a sub-path parameter that may resolve to a directory rathe…
|
CWE-248 CWE-770
Uncaught Exception Allocation of Resources Without Limits or Throttling
|
CVE-2026-45554
|
2026-06-3 02:15 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3754
|
7.5 |
HIGH
Network
|
-
|
-
|
Authentication Bypass Using an Alternate Path or Channel vulnerability in Liquid Web / StellarWP BookIt allows Password Recovery Exploitation.
This issue affects BookIt: from n/a before 2.5.4.1.
|
CWE-288
Authentication Bypass Using an Alternate Path or Channel
|
CVE-2026-40780
|
2026-06-3 02:11 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3755
|
7.1 |
HIGH
Network
|
-
|
-
|
Authentication Bypass Using an Alternate Path or Channel vulnerability in WP Swings Wallet System for WooCommerce allows Password Recovery Exploitation.
This issue affects Wallet System for WooComme…
|
CWE-288
Authentication Bypass Using an Alternate Path or Channel
|
CVE-2026-42654
|
2026-06-3 02:11 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3756
|
8.8 |
HIGH
Network
|
tanium
|
connect
|
Tanium addressed an unauthorized code execution vulnerability in Connect.
|
CWE-78
OS Command
|
CVE-2026-9208
|
2026-06-3 01:29 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3757
|
8.8 |
HIGH
Network
|
samsung
|
escargot
|
Out-of-bounds write vulnerability in Samsung Open Source Escargot allows Overflow Buffers.
This issue affects Escargot: 36f5fb58366a67b713c02f6fd985e924fcc09e31.
|
CWE-787
Out-of-bounds Write
|
CVE-2026-8915
|
2026-06-3 01:23 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3758
|
8.2 |
HIGH
Network
|
-
|
-
|
A flaw was found in libgnutls. A remote attacker, by sending an extremely short premaster secret during an RSA key exchange to a server using an RSA key backed by a PKCS#11 token, could trigger a sho…
|
CWE-1284
Improper Validation of Specified Quantity in Input
|
CVE-2026-5260
|
2026-06-3 01:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3759
|
4.3 |
MEDIUM
Network
|
-
|
-
|
Thor Vector Graphics (ThorVG) is a production-ready vector graphics engine. Prior to version 1.0.5, a null pointer dereference in SvgLoader::run() allows any caller that passes untrusted SVG data to …
|
CWE-476
NULL Pointer Dereference
|
CVE-2026-45729
|
2026-06-3 01:16 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3760
|
8.2 |
HIGH
Network
|
-
|
-
|
parse-nested-form-data is a tiny node module for parsing FormData by name into objects and arrays. Prior to version 1.0.1, parseFormData() walks bracket and dot-notation FormData field names into nes…
|
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
|
CVE-2026-45302
|
2026-06-3 01:16 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3761
|
- |
-
|
-
|
-
|
esm.sh is a no-build content delivery network (CDN) for web development. In 137 and earlier, the legacy router first retrieves a response from legacyServer, parses the incoming request path, and ulti…
|
CWE-22
Path Traversal
|
CVE-2026-44593
|
2026-06-3 01:16 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3762
|
- |
-
|
-
|
-
|
Path traversal vulnerability in Gleam's dependency management allows arbitrary directory deletion via malicious build/packages/packages.toml content.
Package keys read from build/packages/packages.t…
|
CWE-22
Path Traversal
|
CVE-2026-43965
|
2026-06-3 01:16 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3763
|
- |
-
|
-
|
-
|
Symlink following vulnerability in Gleam's Hex package export allows files outside the project root to be embedded in the generated package tarball.
The file collection helpers (gleam_files, native_…
|
CWE-59
Link Following
|
CVE-2026-42795
|
2026-06-3 01:16 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3764
|
7.5 |
HIGH
Network
|
-
|
-
|
Missing Authorization vulnerability in Etoile Web Design Incorporated Five Star Restaurant Reservations allows Exploiting Incorrectly Configured Access Control Security Levels.
This issue affects Fi…
|
CWE-862
Missing Authorization
|
CVE-2026-42670
|
2026-06-3 01:16 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3765
|
5.3 |
MEDIUM
Network
|
-
|
-
|
A flaw was found in gnutls. An off-by-one error exists in the PKCS#12 bag element bounds check. This vulnerability allows an remote attacker to write past the internal array of a PKCS#12 bag when app…
|
CWE-193
Off-by-one Error
|
CVE-2026-42015
|
2026-06-3 01:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3766
|
8.2 |
HIGH
Network
|
-
|
-
|
A flaw was found in gnutls. When validating certificates, an oversized Subject Alternative Name (SAN) could cause the validation process to incorrectly fall back to checking the Common Name (CN) fiel…
|
CWE-1284
Improper Validation of Specified Quantity in Input
|
CVE-2026-42013
|
2026-06-3 01:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3767
|
7.1 |
HIGH
Network
|
-
|
-
|
A flaw was found in gnutls. A remote attacker could exploit this vulnerability by presenting a specially crafted certificate that contains Uniform Resource Identifier (URI) or Service (SRV) Subject A…
|
CWE-295
Improper Certificate Validation
|
CVE-2026-42012
|
2026-06-3 01:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3768
|
6.5 |
MEDIUM
Network
|
apache
|
flink_kubernetes_operator
|
Files or Directories Accessible to External Parties, Server-Side Request Forgery (SSRF) vulnerability in Apache Flink Kubernetes Operator.
The FlinkSessionJob jarURI is currently not validated so th…
|
CWE-552 CWE-918
Files or Directories Accessible to External Parties Server-Side Request Forgery (SSRF)
|
CVE-2026-40564
|
2026-06-3 01:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3769
|
- |
-
|
-
|
-
|
Path traversal vulnerability in Gleam's handling of custom documentation pages allows arbitrary file read and file write outside the intended documentation output directory.
The documentation.pages …
|
CWE-22
Path Traversal
|
CVE-2026-32685
|
2026-06-3 01:16 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3770
|
4.3 |
MEDIUM
Network
|
-
|
-
|
NamelessMC is website software for Minecraft servers. A Reflected Cross-Site Scripting (XSS) vulnerability was discovered in version 2.2.4 in the id parameter of the endpoint `/index.php?route=/queri…
|
CWE-79
Cross-site Scripting
|
CVE-2026-32250
|
2026-06-3 01:16 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3771
|
7.8 |
HIGH
Local
|
google
|
android
|
In validateNode of ResourceTypes.cpp, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges…
|
CWE-125
Out-of-bounds Read
|
CVE-2026-0076
|
2026-06-3 01:16 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3772
|
7.5 |
HIGH
Network
|
-
|
-
|
A NULL pointer dereference in the ext4_dir_en_get_name_len function in include/ext4_dir.h of lwext4 1.0.0 allows attackers to cause a denial of service by supplying a specially crafted EXT4 filesyste…
|
CWE-476
NULL Pointer Dereference
|
CVE-2025-70099
|
2026-06-3 01:16 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3773
|
6.6 |
MEDIUM
Network
|
jenkins
|
ldap
|
Jenkins LDAP Plugin 807.v7d7de30930cf and earlier deserializes data from LDAP referrals without validation.
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-48917
|
2026-06-3 01:14 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3774
|
6.6 |
MEDIUM
Network
|
jenkins
|
ldap
|
Jenkins LDAP Plugin 807.v7d7de30930cf and earlier follows LDAP referrals.
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-48916
|
2026-06-3 01:13 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3775
|
5.6 |
MEDIUM
Local
|
synology
|
assistant
|
An origin validation error vulnerability in Synology Assistant before 7.0.6-50085 allows local users to write arbitrary files with restricted content and conduct denial-of-service during installation.
|
CWE-346
Origin Validation Error
|
CVE-2025-66593
|
2026-06-3 01:09 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3776
|
5.6 |
MEDIUM
Local
|
synology
|
active_backup_for_business_agent
|
An origin validation error vulnerability in Synology Active Backup for Business Agent before 3.1.0-4967 allows local users to write arbitrary files with restricted content and conduct denial-of-servi…
|
CWE-346
Origin Validation Error
|
CVE-2025-66592
|
2026-06-3 01:08 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3777
|
5.6 |
MEDIUM
Local
|
synology
|
activeprotect_agent
|
Origin validation error vulnerability in Synology ActiveProtect Agent before 1.1.0-0439 allows local users to write arbitrary files with restricted content and conduct denial-of-service during instal…
|
CWE-346
Origin Validation Error
|
CVE-2025-13593
|
2026-06-3 01:08 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3778
|
5.9 |
MEDIUM
Local
|
google
|
android
|
In multiple functions of WindowState.java, there is a possible way to trick a user into accepting a permission due to a tapjacking/overlay attack. This could lead to local escalation of privilege wit…
|
CWE-1021
Improper Restriction of Rendered UI Layers or Frames
|
CVE-2026-0061
|
2026-06-3 00:48 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3779
|
5.5 |
MEDIUM
Local
|
google
|
android
|
In multiple functions of DevicePolicyManagerService.java, there is a possible way to hide a system critical package due to improper input validation. This could lead to local denial of service with n…
|
CWE-20
Improper Input Validation
|
CVE-2026-0070
|
2026-06-3 00:48 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3780
|
5.5 |
MEDIUM
Local
|
google
|
android
|
In getPreferredSize of LauncherProcessImageListener.kt, there is a possible denial of service due to resource exhaustion. This could lead to local denial of service with no additional execution priv…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2026-0074
|
2026-06-3 00:47 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3781
|
5.3 |
MEDIUM
Network
|
ibm
|
openbmc
|
IBM OPENBMC FW1110.00 through FW1110.11 is vulnerable to denial of service attacks by unauthenticated network users.
|
CWE-1284
Improper Validation of Specified Quantity in Input
|
CVE-2026-7254
|
2026-06-3 00:45 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3782
|
7.8 |
HIGH
Local
|
ibm
|
operations_analytics_log_analysis
|
IBM Operations Analytics - Log Analysis and IBM SmartCloud Analytics - Log Analysis uses default passwords default passwords from the manufacturing process for use during the installation process, w…
|
CWE-1392 NVD-CWE-noinfo
Use of Default Credentials
|
CVE-2026-7365
|
2026-06-3 00:40 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3783
|
6.4 |
MEDIUM
Local
|
qualcomm
|
snapdragon_g1_gen_2_gaming_platform_firmware 5g_fixed_wireless_access_platform_firmware c-v2x_9150_firmware cq7790_firmware cq8725s_firmware sm7435p_firmware sm7525_firmware sm75…
|
Memory Corruption when processing IOCTL requests with mismatched API versions due to concurrent modification of user-space buffer.
|
CWE-367
Time-of-check Time-of-use (TOCTOU) Race Condition
|
CVE-2025-59610
|
2026-06-3 00:28 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3784
|
6.7 |
MEDIUM
Local
|
qualcomm
|
aqt1000_firmware cologne_firmware fastconnect_6200_firmware fastconnect_6700_firmware fastconnect_6800_firmware fastconnect_6900_firmware fastconnect_7800_firmware iqx5121_firmwa…
|
Memory corruption in diagnostic services due to absence of input validation
|
CWE-787
Out-of-bounds Write
|
CVE-2025-59611
|
2026-06-3 00:27 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3785
|
6.7 |
MEDIUM
Local
|
qualcomm
|
cologne_firmware fastconnect_6700_firmware fastconnect_6900_firmware fastconnect_7800_firmware iqx5121_firmware iqx7181_firmware qca0000_firmware qcm5430_firmware qcm6490_firm…
|
Memory corruption in windows drivers while sending incorrect trusted application request
|
CWE-121
Stack-based Buffer Overflow
|
CVE-2025-59612
|
2026-06-3 00:27 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3786
|
6.7 |
MEDIUM
Local
|
qualcomm
|
cologne_firmware fastconnect_6700_firmware fastconnect_6900_firmware fastconnect_7800_firmware iqx5121_firmware iqx7181_firmware qca0000_firmware qcm5430_firmware qcm6490_firm…
|
Memory Corruption when output buffer size is smaller than input buffer size during data copying operation.
|
CWE-121
Stack-based Buffer Overflow
|
CVE-2025-59613
|
2026-06-3 00:26 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3787
|
6.7 |
MEDIUM
Local
|
qualcomm
|
cologne_firmware fastconnect_6900_firmware fastconnect_7800_firmware iqx5121_firmware iqx7181_firmware qca0000_firmware sc8380xp_firmware wcd9378c_firmware wcd9380_firmware
|
Memory Corruption when sending random number generator command with insufficient output buffer size.
|
CWE-787
Out-of-bounds Write
|
CVE-2025-59614
|
2026-06-3 00:26 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3788
|
7.2 |
HIGH
Physics
|
qualcomm
|
qca6391_firmware qca6564au_firmware qca6574_firmware qca6574a_firmware qca6574au_firmware qca6584au_firmware qca6595_firmware qca6595au_firmware qca6678aq_firmware qca6688a…
|
Memory Corruption when processing display command line information due to improper initialization of a variable.
|
CWE-121
Stack-based Buffer Overflow
|
CVE-2026-24085
|
2026-06-3 00:26 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3789
|
7.2 |
HIGH
Physics
|
qualcomm
|
ar8031_firmware ar8035_firmware cologne_firmware cq7790_firmware cq8725s_firmware qpa1083bd_firmware qpa1086bd_firmware qrb5165n_firmware qru1032_firmware qualcomm_dragonwi…
|
Memory corruption while processing fastboot OEM commands.
|
CWE-1286
Improper Validation of Syntactic Correctness of Input
|
CVE-2026-24087
|
2026-06-3 00:26 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3790
|
8.2 |
HIGH
Local
|
qualcomm
|
ar9380_firmware csr8811_firmware fastconnect_6200_firmware fastconnect_6700_firmware fastconnect_6900_firmware fastconnect_7800_firmware g1_gen_1_firmware g2_gen_1_firmware g3…
|
Cryptographic Issue while processing a specific partition which allows unauthorized write access to load a customized bootloader.
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2026-24088
|
2026-06-3 00:26 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3791
|
7.2 |
HIGH
Physics
|
qualcomm
|
ar8031_firmware ar8035_firmware cologne_firmware cq7790_firmware cq8725s_firmware qmp1000_firmware qmp2001_firmware qpa1083bd_firmware qpa1086bd_firmware qrb5165n_firmware<…
|
Memory corruption while processing fastboot commands with invalid input.
|
CWE-1286
Improper Validation of Syntactic Correctness of Input
|
CVE-2026-24089
|
2026-06-3 00:25 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3792
|
7.1 |
HIGH
Local
|
qualcomm
|
ar8031_firmware ar8035_firmware cologne_firmware cq7790_firmware cq8725s_firmware sm6850_firmware sm7435_firmware sm7435p_firmware sm7525_firmware sm7550_firmware sm7550…
|
Cryptographic issue while processing partition table entries allows unauthorized modification of boot flow.
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2026-24090
|
2026-06-3 00:25 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3793
|
7.2 |
HIGH
Physics
|
qualcomm
|
c-v2x_9150_firmware cologne_firmware cq7790_firmware cq8725s_firmware cq8750m_firmware csra6620_firmware csra6640_firmware csrb31024_firmware fastconnect_6200_firmware fast…
|
Memory corruption while processing fastboot commands with improperly formatted input.
|
CWE-1286
Improper Validation of Syntactic Correctness of Input
|
CVE-2026-24091
|
2026-06-3 00:25 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3794
|
7.2 |
HIGH
Physics
|
qualcomm
|
ar8031_firmware ar8035_firmware cologne_firmware cq7790_firmware cq8725s_firmware cq8750m_firmware csra6620_firmware csra6640_firmware fastconnect_6200_firmware fastconnect…
|
Memory Corruption when processing fastboot commands to set display mode.
|
CWE-1286
Improper Validation of Syntactic Correctness of Input
|
CVE-2026-24092
|
2026-06-3 00:25 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3795
|
9.8 |
CRITICAL
Network
|
langflow
|
langflow
|
IBM Langflow OSS 1.0.0 through 1.9.1 could allow remote code execution due to improper validation of symbolic links during archive extraction.
|
CWE-22
Path Traversal
|
CVE-2026-7524
|
2026-06-3 00:24 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3796
|
7.8 |
HIGH
Local
|
qualcomm
|
cologne_firmware fastconnect_6900_firmware fastconnect_7800_firmware iqx5121_firmware iqx7181_firmware qca0000_firmware sc8380xp_firmware wcd9378c_firmware wcd9380_firmware
|
Memory corruption while processing IOCTL calls for escape operations.
|
CWE-125
Out-of-bounds Read
|
CVE-2026-25258
|
2026-06-3 00:23 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3797
|
7.8 |
HIGH
Local
|
qualcomm
|
cologne_firmware fastconnect_6700_firmware fastconnect_6900_firmware fastconnect_7800_firmware iqx5121_firmware iqx7181_firmware qca0000_firmware qcm5430_firmware qcm6490_firm…
|
Memory corruption while processing multiple IOCTL command for escape operations.
|
CWE-787
Out-of-bounds Write
|
CVE-2026-25259
|
2026-06-3 00:22 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3798
|
7.0 |
HIGH
Local
|
qualcomm
|
cologne_firmware fastconnect_6700_firmware fastconnect_6900_firmware fastconnect_7800_firmware qcm5430_firmware qcm6490_firmware video_collaboration_vc3_platform_firmware sc8380x…
|
Memory Corruption when accessing shared buffers without validation of concurrent user-mode input modifications.
|
CWE-367
Time-of-check Time-of-use (TOCTOU) Race Condition
|
CVE-2026-25260
|
2026-06-3 00:22 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3799
|
7.5 |
HIGH
Network
|
langflow
|
langflow
|
IBM Langflow OSS 1.0.0 through 1.9.0 could allow a denial of service due to uncontrolled resource consumption.
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2026-7528
|
2026-06-3 00:20 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3800
|
8.8 |
HIGH
Network
|
ibm
|
controller
|
IBM Controller 11.0.1, 11.1.0, 11.1.1, and 11.1.2 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2026-5065
|
2026-06-3 00:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|