|
221
|
5.9 |
MEDIUM
Network
|
-
|
-
|
A cleartext transmission of sensitive information vulnerability in Synology Note Station Client before 2.2.4-703 allows man-in-the-middle attackers to obtain user credential.
New
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2023-52951
|
2026-06-3 23:16 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222
|
7.8 |
HIGH
Local
|
-
|
-
|
An inclusion of functionality from untrusted control sphere vulnerability in MinGW DLL component in Synology Hyper Backup Explorer before 3.0.1-0156 allows local users to execute arbitrary code via u…
New
|
CWE-829
Inclusion of Functionality from Untrusted Control Sphere
|
CVE-2022-49042
|
2026-06-3 23:16 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223
|
7.8 |
HIGH
Local
|
-
|
-
|
An inclusion of functionality from untrusted control sphere vulnerability in OpenSSL configuration in Synology Active Backup for Business Recovery Media Creator before 2.5.0-2081 allows local users t…
New
|
CWE-829
Inclusion of Functionality from Untrusted Control Sphere
|
CVE-2022-49036
|
2026-06-3 23:16 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224
|
6.5 |
MEDIUM
Network
|
springaicommunity
|
mcp_security
|
mcp-security provides Security and Authorization support for Model Context Protocol in Spring AI. Prior to 0.1.9, the mcp-security framework fails to implement the mandatory SSRF mitigations outlined…
Update
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-45609
|
2026-06-3 23:08 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
225
|
3.3 |
LOW
Local
|
google
|
android
|
In setTo of ResourceTypes.cpp, there is a possible read out of bounds due to an incorrect bounds check. This could lead to local information disclosure with no additional execution privileges needed.…
New
|
CWE-120
Classic Buffer Overflow
|
CVE-2026-0056
|
2026-06-3 22:47 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
226
|
7.8 |
HIGH
Local
|
google
|
android
|
In addWindow of WindowManagerService.java, there is a possible tapjacking issue due to a tapjacking/overlay attack. This could lead to local escalation of privilege with no additional execution privi…
New
|
CWE-1021
Improper Restriction of Rendered UI Layers or Frames
|
CVE-2026-28577
|
2026-06-3 22:47 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
227
|
5.5 |
MEDIUM
Local
|
google
|
android
|
In multiple functions of ubsan_throwing_runtime.cpp, there is a possible way to cause a permanent denial of service due to a logic error in the code. This could lead to local denial of service with n…
New
|
NVD-CWE-noinfo
|
CVE-2026-0067
|
2026-06-3 22:46 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
228
|
8.0 |
HIGH
Adjacent
|
google
|
android
|
In multiple functions of sdp_discovery.cc, there is a possible way to achieve code execution due to a heap buffer overflow. This could lead to remote (proximal/adjacent) code execution with no additi…
New
|
CWE-122
Heap-based Buffer Overflow
|
CVE-2026-0059
|
2026-06-3 22:46 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
229
|
5.5 |
MEDIUM
Local
|
google
|
android
|
In updateState of GraphicsDriverEnableAngleAsSystemDriverController.java, there is a possible persistent dos issue due to an unusual root cause. This could lead to local denial of service with no add…
New
|
NVD-CWE-noinfo
|
CVE-2026-0060
|
2026-06-3 22:46 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
230
|
7.8 |
HIGH
Local
|
google
|
android
|
In getAppLabel of ForgetDeviceDialogFragment.java, there is a possible trick the user into forgetting a device due to misleading or insufficient UI. This could lead to local escalation of privilege w…
New
|
CWE-451
User Interface (UI) Misrepresentation of Critical Information
|
CVE-2026-0096
|
2026-06-3 22:41 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|