|
831
|
7.3 |
HIGH
Adjacent
|
-
|
-
|
An attacker with write permissions to the database table managed by JdbcAssertingPartyMetadataRepository (saml2_asserting_party_metadata) may be able to store malicious serialized payloads in the col…
New
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-40993
|
2026-06-10 09:16 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
832
|
5.9 |
MEDIUM
Network
|
-
|
-
|
When using spring-restdocs-webtestclient or spring-restdocs-restassured to document a remote API accessed over HTTP, an attacker who compromises the API or tricks the user into documenting a maliciou…
New
|
CWE-611
XXE
|
CVE-2026-40991
|
2026-06-10 09:16 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
833
|
7.5 |
HIGH
Network
|
-
|
-
|
An application using spring-security-saml2-service-provider and the REDIRECT binding for SAML 2.0 Login or Logout may be vulnerable to a denial of service by way of an unbounded writer that inflates …
New
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2026-40988
|
2026-06-10 09:16 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
834
|
- |
|
-
|
-
|
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
New
|
-
|
CVE-2026-10238
|
2026-06-10 08:16 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
835
|
8.1 |
HIGH
Network
|
-
|
-
|
Insecure permissions in bookcars v8.3 allows authenticated attackers to escalate privileges from user to admin via modifying their user type.
New
|
CWE-284
Improper Access Control
|
CVE-2026-36720
|
2026-06-10 07:16 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
836
|
7.8 |
HIGH
Local
|
-
|
-
|
Multiple Microsoft-sigend UEFI SHIM bootloaders are vulnerable to SecureBoot bypass. An attacker with administrative privileges or the ability to modify the boot process could use one of the vulnerab…
New
|
-
|
CVE-2026-8863
|
2026-06-10 06:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
837
|
6.3 |
MEDIUM
Network
|
-
|
-
|
SemCms 5.0 is vulnerable to Cross Site Request Forgery (CSRF) via crafted POST request to /admin/semcms_user.php.
New
|
CWE-352
Origin Validation Error
|
CVE-2026-39170
|
2026-06-10 06:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
838
|
7.5 |
HIGH
Network
|
-
|
-
|
SEMCMS 5.0 is vulnerable to unauthorized access in SEMCMS_copy.php.
New
|
CWE-284
Improper Access Control
|
CVE-2026-39169
|
2026-06-10 06:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
839
|
7.5 |
HIGH
Network
|
-
|
-
|
Shenzhen Tenda Technology Co., Ltd Tenda W20E v15.11.0.6 was discovered to contain a buffer overflow in the macAddr parameter of the formDelStaState function. This vulnerability allows attackers to c…
New
|
CWE-121
Stack-based Buffer Overflow
|
CVE-2026-36822
|
2026-06-10 06:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
840
|
7.5 |
HIGH
Network
|
-
|
-
|
Shenzhen Tenda Technology Co., Ltd Tenda W20E v15.11.0.6 was discovered to contain a buffer overflow in the picCropName parameter of the formCropAndSetWewifiPic function. This vulnerability allows at…
New
|
CWE-121
Stack-based Buffer Overflow
|
CVE-2026-36821
|
2026-06-10 06:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|