|
1101
|
7.3 |
HIGH
Local
|
-
|
-
|
A local privilege escalation vulnerability was found in the ansible.posix authorized_key module. The module's keyfile() function uses os.chown() instead of os.lchown() and opens files without O_NOFOL…
New
|
CWE-59
Link Following
|
CVE-2026-11837
|
2026-06-10 14:16 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1102
|
2.4 |
LOW
Network
|
-
|
-
|
A weakness has been identified in FluentCMS 0.0.5. The impacted element is an unknown function of the file /admin/blocks of the component Blocks Plugin. This manipulation causes cross site scripting.…
Update
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-11434
|
2026-06-10 14:16 |
2026-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1103
|
- |
|
-
|
-
|
A missing authorization vulnerability has been reported to affect QuMagie. The remote attackers can then exploit the vulnerability to access unauthorized data or perform unauthorized actions.
We hav…
New
|
CWE-359 CWE-862
Exposure of Private Personal Information to an Unauthorized Actor Missing Authorization
|
CVE-2026-26237
|
2026-06-10 13:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1104
|
- |
|
-
|
-
|
A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to e…
New
|
CWE-78
OS Command
|
CVE-2026-24719
|
2026-06-10 13:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1105
|
- |
|
-
|
-
|
A path traversal vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to read…
New
|
CWE-22
Path Traversal
|
CVE-2026-24717
|
2026-06-10 13:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1106
|
- |
|
-
|
-
|
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerabili…
New
|
CWE-476
NULL Pointer Dereference
|
CVE-2026-24716
|
2026-06-10 13:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1107
|
- |
|
-
|
-
|
A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to e…
New
|
CWE-78
OS Command
|
CVE-2026-22893
|
2026-06-10 13:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1108
|
- |
|
-
|
-
|
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. The remote attackers can then exploit the vulnerability to launch a denial-of-service (DoS…
New
|
CWE-476
NULL Pointer Dereference
|
CVE-2025-66281
|
2026-06-10 13:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1109
|
- |
|
-
|
-
|
An integer overflow or wraparound vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vuln…
New
|
CWE-121 CWE-190
Stack-based Buffer Overflow Integer Overflow or Wraparound
|
CVE-2025-66280
|
2026-06-10 13:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1110
|
- |
|
-
|
-
|
A command injection vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to e…
New
|
CWE-78
OS Command
|
CVE-2025-66279
|
2026-06-10 13:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|