|
131
|
7.5 |
HIGH
Network
|
opentelemetry
|
ebpf_instrumentation
|
OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. From version 0.1.0 to before version 0.9.0, malformed MongoDB wire messages can trigger uncaught …
New
|
CWE-20 CWE-248 CWE-704
Improper Input Validation Uncaught Exception Incorrect Type Conversion or Cast
|
CVE-2026-45685
|
2026-06-4 01:52 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
132
|
5.3 |
MEDIUM
Network
|
oracle
|
rest_data_services
|
Vulnerability in Oracle REST Data Services (component: Core). Supported versions that are affected are 24.2.0-26.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network ac…
Update
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2026-46843
|
2026-06-4 01:52 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
133
|
5.3 |
MEDIUM
Local
|
opentelemetry
|
ebpf_instrumentation
|
OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. From version 0.7.0 to before version 0.9.0, OBI's log enricher mishandles writev buffers by readi…
New
|
CWE-126 CWE-787
Buffer Over-read Out-of-bounds Write
|
CVE-2026-45684
|
2026-06-4 01:52 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
134
|
3.8 |
LOW
Local
|
opentelemetry
|
ebpf_instrumentation
|
OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0.9.0, the Java TLS ioctl probe reads user-controlled ioctl pointers with bpf_pr…
New
|
CWE-127 CWE-200
Buffer Under-read Information Exposure
|
CVE-2026-45683
|
2026-06-4 01:52 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
135
|
5.9 |
MEDIUM
Network
|
opentelemetry
|
ebpf_instrumentation
|
OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0.9.0, the per-CPU message-buffer fallback path uses a 256-byte backup buffer bu…
New
|
CWE-125 CWE-130
Out-of-bounds Read Improper Handling of Length Parameter Inconsistency
|
CVE-2026-45681
|
2026-06-4 01:52 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
136
|
5.5 |
MEDIUM
Local
|
opentelemetry
|
ebpf_instrumentation
|
OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0.9.0, the custom CappedConcurrentHashMap introduced for Java TLS state tracking…
New
|
CWE-401 CWE-770
Missing Release of Memory after Effective Lifetime Allocation of Resources Without Limits or Throttling
|
CVE-2026-45682
|
2026-06-4 01:51 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
137
|
4.3 |
MEDIUM
Network
|
mintplexlabs
|
anythingllm
|
AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. Prior to 1.13.0, an approved mobile device token created in single-user mod…
Update
|
CWE-285 CWE-639
Improper Authorization Authorization Bypass Through User-Controlled Key
|
CVE-2026-47713
|
2026-06-4 01:51 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
138
|
7.5 |
HIGH
Network
|
opentelemetry
|
ebpf_instrumentation
|
OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0.9.0, OBI replays BPF probe hits into histogram observations by looping once pe…
New
|
CWE-400 CWE-834
Uncontrolled Resource Consumption Excessive Iteration
|
CVE-2026-45680
|
2026-06-4 01:51 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
139
|
6.5 |
MEDIUM
Network
|
opentelemetry
|
ebpf_instrumentation
|
OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0.9.0, OBI exports raw Redis error text as the span status message. Because Redi…
New
|
CWE-117 CWE-532
Improper Output Neutralization for Logs Inclusion of Sensitive Information in Log Files
|
CVE-2026-45679
|
2026-06-4 01:50 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
140
|
7.5 |
HIGH
Network
|
opentelemetry
|
ebpf_instrumentation
|
OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0.9.0, the Postgres protocol parser assumes BIND message payloads contain a vali…
New
|
CWE-20 CWE-754
Improper Input Validation Improper Check for Unusual or Exceptional Conditions
|
CVE-2026-45678
|
2026-06-4 01:50 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|