|
611
|
4.3 |
MEDIUM
Network
|
apache
|
kafka
|
An improper authorization vulnerability has been identified in Apache Kafka.
The implementation of the CONSUMER_GROUP_DESCRIBE (69) API validates the DESCRIBE operation on the GROUP resource instead…
New
|
CWE-285
Improper Authorization
|
CVE-2026-41115
|
2026-06-3 11:04 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
612
|
6.5 |
MEDIUM
Network
|
sharpcompress_project
|
sharpcompress
|
SharpCompress is a fully managed C# library to deal with many compression types and formats. In 0.47.4 and earlier, a path traversal vulnerability in IArchive.WriteToDirectory() allows a malicious ar…
Update
|
CWE-22
Path Traversal
|
CVE-2026-44788
|
2026-06-3 11:02 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
613
|
6.5 |
MEDIUM
Network
|
ibm
|
guardium_data_protection
|
IBM Guardium Data Protection 12.2.1, and 12.2.2 's add-on feature of Guardium Data Protection named "Long Term Retention" (LTR) can expose sensitive credentials in debug mode.
Update
|
CWE-200 NVD-CWE-noinfo
Information Exposure
|
CVE-2026-8405
|
2026-06-3 10:13 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
614
|
5.3 |
MEDIUM
Network
|
ibm
|
security_directory_integrator
|
IBM SDI 7.2.0.0 through 7.2.0.14 and IBM Security Directory Integrator 10.0.0.0 through 10.0.0.2 could allow a remote attacker to obtain sensitive information when a detailed technical error message …
Update
|
CWE-209
Information Exposure Through an Error Message
|
CVE-2024-28765
|
2026-06-3 10:13 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
615
|
7.8 |
HIGH
Local
|
zed
|
zed
|
Zed is a code editor. Prior to 0.229.0, Zed's terminal tool permission system can be bypassed by prepending environment variable assignments to allowlisted commands, hijacking program behavior (e.g.,…
Update
|
CWE-78 CWE-184
OS Command Incomplete Blacklist
|
CVE-2026-44463
|
2026-06-3 10:11 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
616
|
8.8 |
HIGH
Network
|
zed
|
zed
|
Zed is a code editor. Prior to 0.229.0, Zed's terminal tool permission system can be bypassed via bash variable expansion chaining (${var@P}), allowing arbitrary command execution under an allowliste…
Update
|
CWE-184
Incomplete Blacklist
|
CVE-2026-44462
|
2026-06-3 10:00 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
617
|
8.6 |
HIGH
Local
|
zed
|
zed
|
Zed is a code editor. Prior to 0.227.1, Zed builds SSH/WSL remote commands as a shell command string that starts with exec env ..., but environment variable keys are inserted without shell quoting or…
Update
|
CWE-78
OS Command
|
CVE-2026-44461
|
2026-06-3 09:58 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
618
|
7.5 |
HIGH
Network
|
jg-rp
|
python_liquid
|
Python Liquid is a Python engine for the Liquid template language. Prior to 2.2.0, the built-in FileSystemLoader and CachingFileSystemLoader do not guard against reading files outside their search pa…
Update
|
CWE-22
Path Traversal
|
CVE-2026-45017
|
2026-06-3 09:43 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
619
|
- |
|
-
|
-
|
Rejected reason: This CVE is a duplicate of another CVE.
New
|
-
|
CVE-2026-42029
|
2026-06-3 07:16 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
620
|
7.5 |
HIGH
Network
|
-
|
-
|
The ARMember Premium plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter of the 'arm_directory_paging_action' AJAX action in all versions up to, and including, 7.3.1. This i…
New
|
CWE-89
SQL Injection
|
CVE-2026-5073
|
2026-06-3 05:56 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|