|
4101
|
6.5 |
MEDIUM
Network
|
google
|
chrome
|
Out of bounds read in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium secur…
|
CWE-125
Out-of-bounds Read
|
CVE-2026-9953
|
2026-06-2 03:30 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4102
|
7.5 |
HIGH
Network
|
google
|
chrome
|
Use after free in TabStrip in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a craft…
|
CWE-416
Use After Free
|
CVE-2026-9954
|
2026-06-2 03:29 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4103
|
4.3 |
MEDIUM
Network
|
google
|
chrome
|
Inappropriate implementation in iOS in Google Chrome on iOS prior to 148.0.7778.216 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)
|
CWE-200
Information Exposure
|
CVE-2026-9955
|
2026-06-2 03:29 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4104
|
8.8 |
HIGH
Network
|
google
|
chrome
|
Use after free in PDFium in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to potentially exploit heap corruption via a crafted PDF file. (Chromium security severity: High)
|
CWE-416
Use After Free
|
CVE-2026-9958
|
2026-06-2 03:28 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4105
|
5.4 |
MEDIUM
Network
|
google
|
chrome
|
Inappropriate implementation in iOS in Google Chrome on iOS prior to 148.0.7778.216 allowed a remote attacker who convinced a user to engage in specific UI gestures to inject arbitrary scripts or HTM…
|
CWE-79
Cross-site Scripting
|
CVE-2026-9971
|
2026-06-2 03:27 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4106
|
8.3 |
HIGH
Network
|
google
|
chrome
|
Uninitialized Use in Gamepad in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted H…
|
CWE-457
Use of Uninitialized Variable
|
CVE-2026-9972
|
2026-06-2 03:27 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4107
|
8.3 |
HIGH
Network
|
google
|
chrome
|
Insufficient validation of untrusted input in ANGLE in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape…
|
CWE-20 NVD-CWE-noinfo
Improper Input Validation
|
CVE-2026-9982
|
2026-06-2 03:27 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4108
|
8.3 |
HIGH
Network
|
google
|
chrome
|
Insufficient validation of untrusted input in WebShare in Google Chrome on Android prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to potentially perform a …
|
CWE-20 NVD-CWE-noinfo
Improper Input Validation
|
CVE-2026-9977
|
2026-06-2 03:26 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4109
|
7.5 |
HIGH
Network
|
-
|
-
|
Vanetza is an open-source implementation of the ETSI C-ITS protocol suite. In 26.02 and earlier, a denial-of-service vulnerability was identified in the ASN.1/OER parsing pipeline of Vanetza. When pr…
|
CWE-248
Uncaught Exception
|
CVE-2026-43988
|
2026-06-2 03:26 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4110
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Frappe HR is an open-source human resources management solution (HRMS). Prior to 16.5.0, authenticated employees could access other employees’ leave details due to improper authorization checks. This…
|
CWE-863
Incorrect Authorization
|
CVE-2026-45081
|
2026-06-2 03:26 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4111
|
7.5 |
HIGH
Network
|
-
|
-
|
bird-lg-go is a BIRD looking glass in Go. Prior to 1.4.5, the apiHandler (and similarly webHandlerTelegramBot) processes user-provided JSON payloads by directly using json.NewDecoder(r.Body).Decode(&…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2026-45047
|
2026-06-2 03:26 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4112
|
5.5 |
MEDIUM
Local
|
-
|
-
|
Gryph provides a security layer for AI coding agents. Prior to 0.7.0, Gryph implements logging levels that determine what content is logged to a local sqlite database. The README incorrectly mentions…
|
CWE-212
Improper Removal of Sensitive Information Before Storage or Transfer
|
CVE-2026-45046
|
2026-06-2 03:26 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4113
|
8.7 |
HIGH
Network
|
-
|
-
|
RELATE is a web-based courseware package. Versions prior to commit 555f0efb1c5bd7531c07cd73724d7e566a81f620 have a stored cross-site scripting vulnerability that allows any enrolled student to execut…
|
CWE-79
Cross-site Scripting
|
CVE-2026-42197
|
2026-06-2 03:26 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4114
|
3.1 |
LOW
Network
|
apache
|
airflow
|
Exploitation requires the attacker to already be an authenticated Airflow worker holding a valid Log-server JWT issued for at least one Dag. Apache Airflow's Log server authorized JWT tokens against …
|
CWE-863
Incorrect Authorization
|
CVE-2026-45426
|
2026-06-2 03:25 |
2026-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4115
|
7.5 |
HIGH
Network
|
apache
|
fluss
|
Apache Fluss versions prior to 0.9.1 configure the Netty LengthFieldBasedFrameDecoder with Integer.MAX_VALUE as the maximum frame length, allowing unauthenticated remote attackers to exhaust JVM heap…
|
CWE-400 CWE-770
Uncontrolled Resource Consumption Allocation of Resources Without Limits or Throttling
|
CVE-2026-49361
|
2026-06-2 03:24 |
2026-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4116
|
8.0 |
HIGH
Network
|
openclaw
|
openclaw
|
OpenClaw before 2026.5.18 contains an authorization bypass vulnerability in QQBot native approval buttons that fails to enforce configured approver identity. Non-approver users can click approval but…
|
CWE-862
Missing Authorization
|
CVE-2026-35630
|
2026-06-2 03:23 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4117
|
8.2 |
HIGH
Network
|
-
|
-
|
GuardDog is a CLI tool to identify malicious PyPI packages. From 1.0.0 to 2.9.0, the programmatic remote project scanning path rewrites attacker-controlled repository URLs using a blind string replac…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-44971
|
2026-06-2 03:23 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4118
|
6.2 |
MEDIUM
Local
|
-
|
-
|
go-ipld-prime is an implementation of the InterPlanetary Linked Data (IPLD) spec interfaces, a batteries-included codec implementations of IPLD for CBOR and JSON, and tooling for basic operations on …
|
CWE-674
Uncontrolled Recursion
|
CVE-2026-42328
|
2026-06-2 03:23 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4119
|
8.8 |
HIGH
Network
|
-
|
-
|
elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.68, an authenticated SQL injection vulnerability in the elFinder MySQL volume driver (elFinderVolu…
|
CWE-89
SQL Injection
|
CVE-2026-44521
|
2026-06-2 03:23 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4120
|
- |
-
|
-
|
-
|
Cinny is a Matrix client. Prior to 4.10.3, A remote authenticated attacker who shares a room with a victim and has permissions to create room emotes (for example in a DM) can cause the victim's clien…
|
CWE-20
Improper Input Validation
|
CVE-2026-42553
|
2026-06-2 03:23 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4121
|
6.5 |
MEDIUM
Network
|
openclaw
|
openclaw
|
OpenClaw before 2026.4.29 contains an SSRF policy bypass vulnerability in browser debug and export routes that allows reuse of already-open blocked tabs. Attackers with access to these routes can byp…
|
CWE-863
Incorrect Authorization
|
CVE-2026-35673
|
2026-06-2 03:23 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4122
|
5.0 |
MEDIUM
Network
|
google
|
chrome
|
Insufficient validation of untrusted input in Printing in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a craft…
|
CWE-20 NVD-CWE-noinfo
Improper Input Validation
|
CVE-2026-9980
|
2026-06-2 03:23 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4123
|
8.8 |
HIGH
Network
|
openclaw
|
openclaw
|
OpenClaw before 2026.5.18 contains a scope bypass vulnerability in the Gateway chat.send route that allows scoped clients to execute privileged commands. Attackers with operator.write scope can deliv…
|
CWE-863
Incorrect Authorization
|
CVE-2026-35674
|
2026-06-2 03:22 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4124
|
6.5 |
MEDIUM
Network
|
google
|
chrome
|
Inappropriate implementation in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chrom…
|
CWE-200
Information Exposure
|
CVE-2026-9981
|
2026-06-2 03:22 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4125
|
6.5 |
MEDIUM
Network
|
-
|
-
|
view_component is a framework for building reusable, testable, and encapsulated view components in Ruby on Rails. From 3.0.0 to 4.9.0, the preview route derives an example name from the URL and calls…
|
CWE-749
Exposed Dangerous Method or Function
|
CVE-2026-44836
|
2026-06-2 03:22 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4126
|
- |
-
|
-
|
-
|
eml_parser serves as a python module for parsing eml files and returning various information found in the e-mail as well as computed information. Prior to 3.0.1, EmlParser.get_raw_body_text() recurse…
|
CWE-674
Uncontrolled Recursion
|
CVE-2026-44844
|
2026-06-2 03:22 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4127
|
- |
-
|
-
|
-
|
GitLab MCP Server lets an AI agent talk directly to GitLab. Prior to 0.6.0, the HTTP transport in src/transport.ts ships with no authentication layer at all and a wildcard Access-Control-Allow-Origin…
|
CWE-306 CWE-942
Missing Authentication for Critical Function Permissive Cross-domain Policy with Untrusted Domains
|
CVE-2026-44895
|
2026-06-2 03:22 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4128
|
7.5 |
HIGH
Network
|
-
|
-
|
Vanetza is an open-source implementation of the ETSI C-ITS protocol suite. In 26.02 and earlier, a denial-of-service vulnerability was identified in the cryptographic verification pipeline of Vanetza…
|
CWE-248
Uncaught Exception
|
CVE-2026-44905
|
2026-06-2 03:22 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4129
|
7.3 |
HIGH
Local
|
-
|
-
|
smallbitvec is a growable bit-vector for Rust, optimized for size. From 1.0.1 to 2.6.0, an integer overflow in the internal capacity calculation of smallbitvec can lead to an undersized heap allocati…
|
CWE-122 CWE-190
Heap-based Buffer Overflow Integer Overflow or Wraparound
|
CVE-2026-44983
|
2026-06-2 03:22 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4130
|
- |
-
|
-
|
-
|
Nocturne Memory is a lightweight, rollbackable, and visual Long-Term Memory Server for MCP Agents. Prior to 2.4.1, when API_TOKEN is unset or empty, the BearerTokenAuthMiddleware bypasses authenticat…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2026-44830
|
2026-06-2 03:22 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4131
|
5.3 |
MEDIUM
Network
|
google
|
chrome
|
Insufficient validation of untrusted input in Media in Google Chrome on ChromeOS prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to obtain potentially sensi…
|
CWE-20 NVD-CWE-noinfo
Improper Input Validation
|
CVE-2026-9985
|
2026-06-2 03:20 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4132
|
6.3 |
MEDIUM
Network
|
google
|
chrome
|
Inappropriate implementation in Media in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to bypass same origin policy via a crafted video file. (Chromium security severity: High)
|
CWE-346
Origin Validation Error
|
CVE-2026-9989
|
2026-06-2 03:17 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4133
|
5.3 |
MEDIUM
Network
|
-
|
-
|
Decoding a paletted BMP file with an out-of-range palette index results in a panic when accessing pixels in the invalid image.
|
-
|
CVE-2026-42500
|
2026-06-2 03:16 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4134
|
7.5 |
HIGH
Network
|
-
|
-
|
The TIFF decoder does not place a limit on the size of PackBits-compressed data. A maliciously-crafted image can exploit this to cause a small image (both in terms of pixel width/height and encoded s…
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2026-46599
|
2026-06-2 03:16 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4135
|
- |
-
|
-
|
-
|
Deserialization of untrusted data vulnerability in QOS.CH Sarl logback logback-core (HardenedObjectInputStream (logback-core) modules) allows Object Injection, albeit heavily restricted.
More precis…
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-10532
|
2026-06-2 03:16 |
2026-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4136
|
- |
-
|
-
|
-
|
Sulu is an open-source PHP content management system based on the Symfony framework. Prior to versions 2.6.23 and 3.0.6, the password reset tokenand API key generation uses a weak cryptographical has…
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2026-45701
|
2026-06-2 03:16 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4137
|
7.5 |
HIGH
Network
|
google
|
chrome
|
Use after free in WebAppInstalls in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruptio…
|
CWE-416
Use After Free
|
CVE-2026-9990
|
2026-06-2 03:15 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4138
|
3.1 |
LOW
Network
|
google
|
chrome
|
Inappropriate implementation in Media in Google Chrome on Windows prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HT…
|
CWE-200
Information Exposure
|
CVE-2026-9991
|
2026-06-2 03:15 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4139
|
6.5 |
MEDIUM
Network
|
google
|
chrome
|
Out of bounds read in WebRTC in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromi…
|
CWE-125
Out-of-bounds Read
|
CVE-2026-9996
|
2026-06-2 03:14 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4140
|
10.0 |
CRITICAL
Network
|
-
|
-
|
CloudPirates Open Source Helm Charts is a collection of Helm charts. Prior to commit fcf9302, a GitHub Actions workflow (pull-request.yaml) executes attacker-controlled code from fork pull requests i…
|
CWE-94
Code Injection
|
CVE-2026-45131
|
2026-06-2 03:14 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4141
|
10.0 |
CRITICAL
Network
|
-
|
-
|
CloudPirates Open Source Helm Charts is a collection of Helm charts. Prior to commit fcf9302, a GitHub Actions workflow (generate-schema.yaml) exposes sensitive credentials (Personal Access Token and…
|
CWE-94
Code Injection
|
CVE-2026-45132
|
2026-06-2 03:14 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4142
|
4.6 |
MEDIUM
Physics
|
-
|
-
|
Nextcloud is an open source content collaboration platform. From version 33.0.0 to before version 33.1.0, after unlocking a locked Android phone the back-button could be used to bypass the Nextcloud …
|
CWE-287
Improper Authentication
|
CVE-2026-45153
|
2026-06-2 03:14 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4143
|
2.6 |
LOW
Network
|
-
|
-
|
Nextcloud is an open source content collaboration platform. From version 2.6.0 to before version 4.3.0, when a previous collective pages was deleted and the collective was shared view-only, guests wi…
|
CWE-284
Improper Access Control
|
CVE-2026-45154
|
2026-06-2 03:14 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4144
|
2.6 |
LOW
Network
|
-
|
-
|
Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.7 and 33.0.0 to before 33.0.1, a missing access check on API level allowed to add u…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-45155
|
2026-06-2 03:14 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4145
|
8.1 |
HIGH
Network
|
-
|
-
|
Nextcloud is an open source content collaboration platform. From versions 0.3.0 to before 3.1.0, 5.0.0 to before 5.1.0, and 6.0.0 to before 6.4.0, a missing signature verification in User OIDC allowe…
|
CWE-287
Improper Authentication
|
CVE-2026-45156
|
2026-06-2 03:14 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4146
|
6.3 |
MEDIUM
Network
|
-
|
-
|
Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.9, and 33.0.0 to before 33.0.3, when a malicious user has access to a file share of…
|
CWE-284
Improper Access Control
|
CVE-2026-45157
|
2026-06-2 03:14 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4147
|
3.5 |
LOW
Network
|
-
|
-
|
Nextcloud is an open source content collaboration platform. From versions 1.15.0 to before 1.15.4, 1.16.0 to before 1.16.3, 1.17.0 to before 1.17.1, and 1.18.0 to before 1.18.1, a malicious user with…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-45159
|
2026-06-2 03:14 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4148
|
4.3 |
MEDIUM
Network
|
-
|
-
|
Nextcloud is an open source content collaboration platform. From versions 17.0.0 to before 17.0.15, 18.0.0 to before 18.1.12, 19.0.0 to before 19.1.16, 20.0.0 to before 20.1.11, and 21.0.0 to before …
|
CWE-284
Improper Access Control
|
CVE-2026-45264
|
2026-06-2 03:14 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4149
|
3.5 |
LOW
Network
|
-
|
-
|
Nextcloud is an open source content collaboration platform. Prior to versions 21.1.10, 22.0.11, and 23.0.3, a low-privileged user can force other user's microphones to be muted in calls when no High-…
|
CWE-284
Improper Access Control
|
CVE-2026-45266
|
2026-06-2 03:14 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4150
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Nextcloud is an open source content collaboration platform. Prior to version 5.2.6, a missing permissions check allowed users to request reading form submissions of other users. This issue has been p…
|
CWE-200 CWE-862
Information Exposure Missing Authorization
|
CVE-2026-45267
|
2026-06-2 03:14 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|