|
101
|
7.8 |
HIGH
Local
|
-
|
-
|
A code injection vulnerability in the wxExecute() function of OpenCPN v5.12.0 allows attackers to execute arbitrary code via embedding shell metacharacters.
New
|
CWE-77
Command Injection
|
CVE-2025-56814
|
2026-06-17 00:51 |
2026-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
102
|
8.0 |
HIGH
Network
|
-
|
-
|
An issue was discovered in Rakuten Send Anywhere (File Transfer) for Android (com.estmob.android.sendanywhere) 23.2.9. The vulnerability allows untrusted applications (with no permissions) to force a…
New
|
CWE-926
Improper Export of Android Application Components
|
CVE-2025-68713
|
2026-06-17 00:51 |
2026-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
103
|
6.3 |
MEDIUM
Adjacent
|
-
|
-
|
A NULL pointer dereference occurs in Roy Marples NetworkConfiguration/dhcpcd 10.3.0 while parsing configuration options. In parse_option() (src/if-options.c:1886), the code performs a member access o…
New
|
CWE-476
NULL Pointer Dereference
|
CVE-2025-70102
|
2026-06-17 00:51 |
2026-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
104
|
7.8 |
HIGH
Local
|
-
|
-
|
An issue in Microvirt MEmu Android Emulator 9.2.7.0 allows a local attacker to escalate privileges via the MemuService.exe component.
New
|
CWE-269
Improper Privilege Management
|
CVE-2026-36213
|
2026-06-17 00:51 |
2026-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
105
|
- |
|
-
|
-
|
PublicCMS V5.202506.d has a Cross Site Scripting (XSS) vulnerability in the site configuration management module.
New
|
-
|
CVE-2026-36521
|
2026-06-17 00:51 |
2026-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
106
|
9.8 |
CRITICAL
Network
|
-
|
-
|
ThingsBoard v4.3.0.1 is vulnerable to an authentication bypass during the OAuth authorization code exchange. The application improperly trusts user-supplied identity data within the user parameter of…
New
|
CWE-290
Authentication Bypass by Spoofing
|
CVE-2026-36537
|
2026-06-17 00:51 |
2026-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
107
|
6.8 |
MEDIUM
Physics
|
-
|
-
|
An issue in Boyleep K11, y108 firmware v.2.3.0.11291 allows a physically proximate attacker to execute arbitrary code via the factory test feature.
New
|
CWE-284
Improper Access Control
|
CVE-2026-36933
|
2026-06-17 00:51 |
2026-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
108
|
- |
|
-
|
-
|
Ruoyi 4.8.2 is vulnerable to Cross Site Scripting (XSS) at the interface /system/notice/add.
New
|
-
|
CVE-2026-37216
|
2026-06-17 00:50 |
2026-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
109
|
9.8 |
CRITICAL
Network
|
-
|
-
|
RuoYi v4.8.2 is vulnerable to SQL Injection via the /tool/gen/createTable endpoint. The issue affects the code generation module and may allow an authenticated attacker with administrative privileges…
New
|
CWE-89
SQL Injection
|
CVE-2026-38812
|
2026-06-17 00:50 |
2026-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
110
|
9.8 |
CRITICAL
Network
|
-
|
-
|
An issue in SNMP4J-Agent 3.8.3 allows a remote attacker to execute arbitrary code via the snmp4jCfgStoragePath component.
New
|
CWE-73 CWE-284 CWE-502
External Control of File Name or Path Improper Access Control Deserialization of Untrusted Data
|
CVE-2026-39006
|
2026-06-17 00:50 |
2026-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|