|
4601
|
8.8 |
HIGH
Network
|
-
|
-
|
Versions of the package degit before 2.8.6, from 3.0.0 and before 3.3.1 are vulnerable to Command Injection due to improper sanitisation of user input for git shell commands directly invoked with exe…
|
CWE-78 CWE-77
OS Command Command Injection
|
CVE-2026-11572
|
2026-06-9 23:16 |
2026-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4602
|
6.5 |
MEDIUM
Network
|
google
|
chrome
|
Insufficient policy enforcement in CSS in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)
|
CWE-693
Protection Mechanism Failure
|
CVE-2026-11288
|
2026-06-9 22:59 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4603
|
6.5 |
MEDIUM
Network
|
google
|
chrome
|
Side-channel information leakage in Paint in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)
|
CWE-1300 CWE-203
Improper Protection of Physical Side Channels Information Exposure Through Discrepancy
|
CVE-2026-11289
|
2026-06-9 22:58 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4604
|
7.5 |
HIGH
Network
|
-
|
-
|
Shenzhen Tenda Technology Co., Ltd Tenda AC1206 v15.03.06.23 was discovered to contain multiple stack overflows in the fromGstDhcpSetSer function via the username and password parameters. These vulne…
|
CWE-121
Stack-based Buffer Overflow
|
CVE-2026-36789
|
2026-06-9 22:57 |
2026-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4605
|
6.5 |
MEDIUM
Network
|
-
|
-
|
OfflineIMAP before 8.0.3 trusts the server with their STARTTLS capability prior to authentication, which allows STRIPTLS/man-in-the-middle attacks, taking over the connection and extracting account c…
|
CWE-348
Use of Less Trusted Source
|
CVE-2020-37248
|
2026-06-9 22:57 |
2026-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4606
|
7.5 |
HIGH
Network
|
-
|
-
|
Software installed and run as a non-privileged user may conduct improper GPU system calls to corrupt kernel heap memory.
By creating resources of certain types and presenting a set of parameters t…
|
CWE-122
Heap-based Buffer Overflow
|
CVE-2026-22164
|
2026-06-9 22:57 |
2026-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4607
|
7.1 |
HIGH
Local
|
-
|
-
|
Software installed and run as a non-privileged user may conduct improper GPU system calls to cause mismanagement of a mapping state maintained for a sparse memory allocation.
The product accidenta…
|
CWE-468
|
CVE-2026-34194
|
2026-06-9 22:57 |
2026-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4608
|
7.5 |
HIGH
Network
|
-
|
-
|
Shenzhen Tenda Technology Co., Ltd Tenda FH451 V1.0.0.9 was discovered to contain a stack overflow in the list1 parameter of the fromDhcpListClient function. This vulnerability allows attackers to ca…
|
CWE-121
Stack-based Buffer Overflow
|
CVE-2026-36786
|
2026-06-9 22:57 |
2026-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4609
|
8.8 |
HIGH
Network
|
-
|
-
|
Bludit is a content management system. Versions prior to 3.22.0 have a Broken Access Control flaw where active sessions remain valid even after the corresponding user account has been physically del…
|
CWE-285 CWE-613
Improper Authorization Insufficient Session Expiration
|
CVE-2026-46656
|
2026-06-9 22:57 |
2026-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4610
|
7.1 |
HIGH
Network
|
-
|
-
|
Bludit is a content management system. Versions prior to 3.22.0 have a vulnerability in the user management logic that allows deactivated accounts to maintain access via persistent authentication tok…
|
CWE-212 CWE-613
Improper Removal of Sensitive Information Before Storage or Transfer Insufficient Session Expiration
|
CVE-2026-46657
|
2026-06-9 22:57 |
2026-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4611
|
8.7 |
HIGH
Network
|
-
|
-
|
A Stored Cross-Site Scripting vulnerability in Vinna Process Monitor Version 4.0 Service Pack 1 (Build 63255) allows an authenticated remote attacker with low privileges to inject malicious JavaScrip…
|
CWE-79
Cross-site Scripting
|
CVE-2026-41031
|
2026-06-9 22:57 |
2026-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4612
|
- |
-
|
-
|
-
|
When creating an export of all reusable media, the secrets of connected
gift cards were included in the export even if the user creating the
export does not have permission to view gift cards. This…
|
CWE-280
Improper Handling of Insufficient Permissions or Privileges
|
CVE-2026-11764
|
2026-06-9 22:57 |
2026-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4613
|
4.3 |
MEDIUM
Network
|
google
|
chrome
|
Insufficient policy enforcement in Blink in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass content security policy via a crafted HTML page. (Chromium security severity: Low)
|
CWE-693
Protection Mechanism Failure
|
CVE-2026-11292
|
2026-06-9 22:54 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4614
|
9.6 |
CRITICAL
Network
|
google
|
chrome
|
Use after free in Input in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)
|
CWE-416
Use After Free
|
CVE-2026-11293
|
2026-06-9 22:53 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4615
|
7.6 |
HIGH
Adjacent
|
-
|
-
|
A remote, unauthenticated BLE peer can trigger a 2-byte out-of-bounds write in the Bluetooth host during L2CAP LE CoC SDU reassembly. When the application enables segmentation (via chan_ops.alloc_buf…
|
CWE-787
Out-of-bounds Write
|
CVE-2026-5068
|
2026-06-9 22:53 |
2026-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4616
|
6.0 |
MEDIUM
Local
|
-
|
-
|
Dell iDRAC Tools, versions prior to 11.4.1.0, contains an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local access could potentially e…
|
CWE-59
Link Following
|
CVE-2026-28262
|
2026-06-9 22:53 |
2026-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4617
|
4.8 |
MEDIUM
Network
|
-
|
-
|
QloApps through 1.7.0 contains a stored cross-site scripting vulnerability in the admin file manager that allows authenticated administrators to inject malicious JavaScript by uploading crafted SVG f…
|
CWE-79
Cross-site Scripting
|
CVE-2026-25558
|
2026-06-9 22:51 |
2026-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4618
|
9.8 |
CRITICAL
Network
|
-
|
-
|
OpenBullet2 through version 0.3.2 contains an authentication bypass vulnerability in the API key authentication middleware that allows unauthenticated attackers to gain admin access by supplying an e…
|
CWE-305
Authentication Bypass by Primary Weakness
|
CVE-2026-25555
|
2026-06-9 22:51 |
2026-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4619
|
8.8 |
HIGH
Network
|
-
|
-
|
OpenBullet2 through version 0.3.2 contains a path traversal vulnerability in the wordlist endpoint that allows authenticated attackers to perform arbitrary file read, write, and delete operations by …
|
CWE-22
Path Traversal
|
CVE-2026-25559
|
2026-06-9 22:51 |
2026-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4620
|
8.8 |
HIGH
Network
|
-
|
-
|
OpenBullet2 through version 0.3.2 contains a remote code execution vulnerability that allows authenticated users to execute arbitrary commands by uploading script files (.bat.ps1.sh) through the File…
|
CWE-78
OS Command
|
CVE-2026-25855
|
2026-06-9 22:51 |
2026-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4621
|
8.8 |
HIGH
Network
|
-
|
-
|
OpenBullet2 through version 0.3.2 contains an authenticated remote code execution vulnerability that allows authenticated users to execute arbitrary C# code on the server host by creating or modifyin…
|
CWE-94
Code Injection
|
CVE-2026-25856
|
2026-06-9 22:51 |
2026-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4622
|
6.5 |
MEDIUM
Network
|
-
|
-
|
OpenBullet2 through version 0.3.2 on Windows contains a credential disclosure vulnerability that allows remote attackers to capture the NTLMv2 hash of the process user by configuring a job proxy sour…
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2026-39908
|
2026-06-9 22:51 |
2026-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4623
|
9.8 |
CRITICAL
Network
|
-
|
-
|
STACKIT IaaS API contains a missing authorization check vulnerability that allows authenticated, low-privileged attackers to escalate privileges to full organization compromise by attaching arbitrary…
|
CWE-862
Missing Authorization
|
CVE-2026-39910
|
2026-06-9 22:51 |
2026-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4624
|
9.4 |
CRITICAL
Network
|
-
|
-
|
AdGuard Home, when started with the --glinet flag, contains an authentication bypass vulnerability that allows unauthenticated attackers to gain full admin access by supplying a path traversal sequen…
|
CWE-22
Path Traversal
|
CVE-2026-41448
|
2026-06-9 22:51 |
2026-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4625
|
- |
-
|
-
|
-
|
A command Injection vulnerability exists in the WireGuard client configuration of Archer MR600 v5 due to improper neutralization of user-controlled input within the web management interface. An authe…
|
CWE-78
OS Command
|
CVE-2026-8913
|
2026-06-9 22:51 |
2026-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4626
|
7.5 |
HIGH
Network
|
-
|
-
|
Nginx Proxy Manager versions 2.9.14 through 2.15.1, fixed in commit a5db5ed, contain an authenticated remote code execution vulnerability via OS command injection in the setupCertbotPlugins() functio…
|
CWE-78
OS Command
|
CVE-2026-40519
|
2026-06-9 22:51 |
2026-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4627
|
7.1 |
HIGH
Network
|
-
|
-
|
WACRM prior to commit 73041bf contain an authorization bypass vulnerability in the automation engine that allows authenticated attackers to access and modify contacts belonging to other tenants by su…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-49141
|
2026-06-9 22:51 |
2026-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4628
|
3.5 |
LOW
Network
|
-
|
-
|
The Custom Block Builder WordPress plugin before 4.3.0 does not consistently check the unfiltered_html capability across all paths that write to its block template code fields, allowing administrato…
|
CWE-79
Cross-site Scripting
|
CVE-2026-8981
|
2026-06-9 22:51 |
2026-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4629
|
- |
-
|
-
|
-
|
SQL injection in the ‘two_steps_auth_code’ parameter processed by the ‘twoStepsAuthVerification’ function within the ‘/user-login’ endpoint. The two-factor authentication (2FA) functionality can be a…
|
CWE-89
SQL Injection
|
CVE-2026-10731
|
2026-06-9 22:51 |
2026-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4630
|
8.2 |
HIGH
Network
|
-
|
-
|
Simply Poll 1.4.1 plugin for WordPress contains an SQL injection vulnerability that allows unauthenticated attackers to extract database information by injecting SQL code through the 'pollid' POST pa…
|
CWE-89
SQL Injection
|
CVE-2016-20062
|
2026-06-9 22:51 |
2026-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4631
|
7.1 |
HIGH
Network
|
-
|
-
|
Single Personal Message 1.0.3 contains an SQL injection vulnerability that allows authenticated users to execute arbitrary SQL queries by injecting malicious code through the message parameter. Attac…
|
CWE-89
SQL Injection
|
CVE-2016-20063
|
2026-06-9 22:51 |
2026-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4632
|
6.2 |
MEDIUM
Local
|
-
|
-
|
WP Vault 0.8.6.6 contains a local file inclusion vulnerability that allows unauthenticated attackers to read arbitrary files by exploiting an unescaped parameter in the include functionality. Attacke…
|
CWE-98
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion')
|
CVE-2016-20064
|
2026-06-9 22:51 |
2026-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4633
|
8.2 |
HIGH
Network
|
-
|
-
|
Product Catalog 8 1.2 plugin for WordPress contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the selec…
|
CWE-89
SQL Injection
|
CVE-2016-20065
|
2026-06-9 22:51 |
2026-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4634
|
8.2 |
HIGH
Network
|
-
|
-
|
WordPress Car Park Booking Plugin version 13 October 17 contains a time-based SQL injection vulnerability that allows unauthenticated attackers to manipulate database queries by injecting SQL code th…
|
CWE-89
SQL Injection
|
CVE-2017-20243
|
2026-06-9 22:51 |
2026-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4635
|
8.2 |
HIGH
Network
|
-
|
-
|
Wow Forms WordPress Plugin version 2.1 contains an SQL injection vulnerability that allows unauthenticated attackers to read arbitrary database information by exploiting an unescaped POST parameter. …
|
CWE-89
SQL Injection
|
CVE-2017-20244
|
2026-06-9 22:51 |
2026-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4636
|
8.2 |
HIGH
Network
|
-
|
-
|
Wow Viral Signups 2.1 WordPress plugin contains an SQL injection vulnerability that allows unauthenticated attackers to extract database information by exploiting the unescaped 'idsignup' POST parame…
|
CWE-89
SQL Injection
|
CVE-2017-20245
|
2026-06-9 22:51 |
2026-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4637
|
8.2 |
HIGH
Network
|
-
|
-
|
KittyCatfish 2.2 plugin for WordPress contains an SQL injection vulnerability that allows unauthenticated attackers to read database contents by exploiting an unescaped GET parameter. Attackers can i…
|
CWE-89
SQL Injection
|
CVE-2017-20246
|
2026-06-9 22:51 |
2026-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4638
|
8.2 |
HIGH
Network
|
-
|
-
|
WordPress Plugin PICA Photo Gallery 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the aid para…
|
CWE-89
SQL Injection
|
CVE-2017-20247
|
2026-06-9 22:51 |
2026-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4639
|
7.5 |
HIGH
Network
|
-
|
-
|
Apptha Slider Gallery 1.0 contains a path traversal vulnerability that allows unauthenticated attackers to download arbitrary files by manipulating the imgname parameter. Attackers can send requests …
|
CWE-22
Path Traversal
|
CVE-2017-20248
|
2026-06-9 22:51 |
2026-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4640
|
8.2 |
HIGH
Network
|
-
|
-
|
Apptha Slider Gallery 1.0 contains an SQL injection vulnerability that allows unauthenticated attackers to execute arbitrary SQL queries by injecting malicious code through the albid parameter. Attac…
|
CWE-89
SQL Injection
|
CVE-2017-20249
|
2026-06-9 22:51 |
2026-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4641
|
7.5 |
HIGH
Network
|
-
|
-
|
Mac Photo Gallery 3.0 contains a path traversal vulnerability that allows unauthenticated attackers to download arbitrary files by manipulating the albid parameter. Attackers can send requests to mac…
|
CWE-22
Path Traversal
|
CVE-2017-20250
|
2026-06-9 22:51 |
2026-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4642
|
9.8 |
CRITICAL
Network
|
-
|
-
|
WordPress Insert PHP plugin versions before 3.3.1 contain a PHP code injection vulnerability that allows unauthenticated attackers to execute arbitrary PHP code by injecting malicious shortcodes thro…
|
CWE-94
Code Injection
|
CVE-2017-20251
|
2026-06-9 22:51 |
2026-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4643
|
7.8 |
HIGH
Local
|
-
|
-
|
A YAML injection vulnerability exists in the Windows.Collectors.Remapping artifact of Rapid7 Velociraptor before version 0.76.6. The hostname field in client_info.json inside a collection ZIP is inse…
|
CWE-74 CWE-94 CWE-116
Injection Code Injection Improper Encoding or Escaping of Output
|
CVE-2026-8795
|
2026-06-9 22:49 |
2026-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4644
|
7.5 |
HIGH
Network
|
-
|
-
|
In Micrometer, it is possible for a user to provide specially crafted gRPC requests that may cause a denial-of-service (DoS) condition.
Affected versions:
Micrometer 1.16.0 through 1.16.5; 1.15.0 th…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2026-40983
|
2026-06-9 22:49 |
2026-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4645
|
7.5 |
HIGH
Network
|
-
|
-
|
In Micrometer, it is possible for a user to provide specially crafted HTTP requests that may cause a denial-of-service (DoS) condition.
Affected versions:
micrometer-core 1.16.0 through 1.16.5; 1.15…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2026-40984
|
2026-06-9 22:49 |
2026-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4646
|
5.9 |
MEDIUM
Network
|
-
|
-
|
An attacker can craft a large number of unique requests that trigger a failure, exhausting the capacity of the application-wide stateful retry cache. Once the cache is full, it permanently rejects an…
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2026-41710
|
2026-06-9 22:49 |
2026-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4647
|
6.1 |
MEDIUM
Network
|
-
|
-
|
In specific scenarios involving HTTP redirects from a secure to an insecure endpoint, the Reactor Netty HTTP client may leak credentials. In order for this to happen, the HTTP client must have been e…
|
CWE-522
Insufficiently Protected Credentials
|
CVE-2026-41715
|
2026-06-9 22:49 |
2026-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4648
|
7.4 |
HIGH
Network
|
-
|
-
|
Spring LDAP's DirContextAuthenticationStrategy implementations do not reject a bind request where a non-empty username is paired with an empty or null password.
Affected versions:
Spring LDAP 2.4.0 …
|
CWE-287
Improper Authentication
|
CVE-2026-41720
|
2026-06-9 22:49 |
2026-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4649
|
4.2 |
MEDIUM
Network
|
-
|
-
|
A WebFlux application with a compromised subdomain (for example, compromised via cross-site scripting (XSS)) is vulnerable to an escalation attack exchanging a known session ID for that of an authent…
|
CWE-384
Session Fixation
|
CVE-2026-41839
|
2026-06-9 22:49 |
2026-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4650
|
5.9 |
MEDIUM
Network
|
-
|
-
|
Spring WebFlux applications are vulnerable to Denial of Service (DoS) attacks when processing multipart requests.
Affected versions:
Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2026-41840
|
2026-06-9 22:49 |
2026-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|