|
531
|
8.8 |
HIGH
Network
|
-
|
-
|
CWE-20: Improper Input Validation in web services in Progress Sitefinity 14.1.x through 14.3.x, 14.4.x before 14.4.8152, 15.0.x before 15.0.8234, 15.1.x before 15.1.8335, 15.2.x before 15.2.8441, 15.…
New
|
CWE-20
Improper Input Validation
|
CVE-2026-7195
|
2026-06-2 23:48 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
532
|
2.5 |
LOW
Local
|
mintplexlabs
|
anythingllm
|
AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. Prior to 1.13.0, the AnythingLLM agent filesystem copy tool validates only …
Update
|
CWE-59
Link Following
|
CVE-2026-45403
|
2026-06-2 23:48 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
533
|
8.6 |
HIGH
Network
|
-
|
-
|
An issue was discovered in OpenAirInterface5G 2.4.0 (nr-softmodem) in the E2SM-KPM RAN Function's PRB utilization metric calculation. The functions fill_RRU_PrbTotDl() and fill_RRU_PrbTotUl() in open…
New
|
CWE-369
Divide By Zero
|
CVE-2026-37232
|
2026-06-2 23:47 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
534
|
- |
|
-
|
-
|
An authentication bypass vulnerability exists in MISP when LDAP mixed authentication is enabled with OTP enforcement. In deployments configured with LdapAuth.mixedAuth=true and Security.require_otp=t…
New
|
CWE-287
Improper Authentication
|
CVE-2026-10611
|
2026-06-2 23:47 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
535
|
- |
|
-
|
-
|
Path traversal in restore handler in Collibra Agent, allows an attacker to write arbitrary files via a crafted ZIP archive. Collibra Agent fails to properly validate and canonicalize file path during…
New
|
-
|
CVE-2026-10621
|
2026-06-2 23:46 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
536
|
- |
|
-
|
-
|
Improper Authentication in REST API in Collibra Agent, allows a remote unauthenticated attacker to access privileged functionality via exposed '/rest/* endpoints.
New
|
-
|
CVE-2026-10622
|
2026-06-2 23:46 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
537
|
7.5 |
HIGH
Network
|
-
|
-
|
Banana Slides through 0.4.0, patched in commit e8bc490, contains a path traversal vulnerability in the generate_image() function within the AI service backend that allows unauthenticated attackers to…
New
|
CWE-22
Path Traversal
|
CVE-2026-49136
|
2026-06-2 23:45 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
538
|
8.2 |
HIGH
Network
|
-
|
-
|
Joomla Component JE Photo Gallery 1.1 contains an SQL injection vulnerability that allows unauthenticated attackers to extract database information by injecting malicious SQL code through the categor…
New
|
CWE-89
SQL Injection
|
CVE-2018-25433
|
2026-06-2 23:45 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
539
|
6.5 |
MEDIUM
Adjacent
|
-
|
-
|
A buffer overflow vulnerability in the UPnP AddPortMapping() command in Zyxel VMG4005-B50B firmware versions through 5.13(ABRL.5.4)C0 could allow an adjacent attacker to trigger a temporary denial-of…
New
|
CWE-120
Classic Buffer Overflow
|
CVE-2026-3870
|
2026-06-2 23:45 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
540
|
6.5 |
MEDIUM
Adjacent
|
-
|
-
|
A buffer overflow vulnerability in the UPnP DeletePortMapping() command in Zyxel VMG4005-B50B firmware versions through 5.13(ABRL.5.4)C0 could allow an adjacent attacker to trigger a temporary denial…
New
|
CWE-120
Classic Buffer Overflow
|
CVE-2026-3871
|
2026-06-2 23:45 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|