|
281
|
8.0 |
HIGH
Network
|
-
|
-
|
Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.
New
|
CWE-78
OS Command
|
CVE-2026-47294
|
2026-06-2 23:01 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
282
|
8.8 |
HIGH
Network
|
-
|
-
|
IBM i Access Family 1.1.5.0 through 1.1.9.12 IBM i Access Client Solutions (ACS) is vulnerable to remote code execution when configured to listen for requests from IBM i Navigator.
New
|
CWE-74
Injection
|
CVE-2026-7770
|
2026-06-2 23:01 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
283
|
9.1 |
CRITICAL
Network
|
-
|
-
|
IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to identity spoofing.
New
|
CWE-290
Authentication Bypass by Spoofing
|
CVE-2026-8644
|
2026-06-2 23:01 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
284
|
9.0 |
CRITICAL
Network
|
-
|
-
|
IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to remote code execution caused by the bypass of security controls.
New
|
CWE-94
Code Injection
|
CVE-2026-9311
|
2026-06-2 23:01 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
285
|
9.0 |
CRITICAL
Network
|
-
|
-
|
IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to potential remote code execution due to deserialization of untrusted data via JAX-WS endpoints with WS-Security.
New
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-9319
|
2026-06-2 23:01 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
286
|
8.5 |
HIGH
Network
|
-
|
-
|
IBM WebSphere Application Server 9.0, and 8.5 is affected by an improper validation of user-supplied data during deserialization using the SAML Web Single Sign-On component. This could result in remo…
New
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-9330
|
2026-06-2 23:01 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
287
|
8.8 |
HIGH
Network
|
-
|
-
|
An Improper Access Control vulnerability in Ivanti Neurons for ITSM (cloud and on-premises) allows a remote authenticated attacker to gain administrative access.
New
|
CWE-284
Improper Access Control
|
CVE-2026-9614
|
2026-06-2 23:01 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
288
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Nextcloud is an open source content collaboration platform. Prior to version 2.7.2, a privilege escalation vulnerability exists in the Approval app that allows a user without sharing permissions to f…
New
|
CWE-285
Improper Authorization
|
CVE-2026-45275
|
2026-06-2 23:00 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
289
|
3.3 |
LOW
Local
|
-
|
-
|
Nextcloud is an open source content collaboration platform. Prior to version 2.7.2, authenticated users can check if arbitrary files are associated with specific approval workflows where they can req…
New
|
CWE-200
Information Exposure
|
CVE-2026-45277
|
2026-06-2 23:00 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
290
|
3.3 |
LOW
Local
|
-
|
-
|
Nextcloud is an open source content collaboration platform. From version 6.1.0 to before version 8.2.2, an attacker can craft links that would redirect users to another website, when the victim uses …
New
|
CWE-601
Open Redirect
|
CVE-2026-45278
|
2026-06-2 23:00 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|