|
651
|
- |
|
-
|
-
|
A bug in Apache Airflow's KubernetesExecutor caused JWT tokens used by worker pods to authenticate against the Execution API to be passed to the worker container as command-line arguments visible in …
New
|
CWE-538
File and Directory Information Exposure
|
CVE-2026-49298
|
2026-06-1 22:13 |
2026-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
652
|
5.4 |
MEDIUM
Network
|
jetbrains
|
youtrack
|
In JetBrains YouTrack before 2026.1.13162 stored XSS in project notification templates was possible
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-49368
|
2026-06-1 21:56 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
653
|
4.3 |
MEDIUM
Network
|
jetbrains
|
youtrack
|
In JetBrains YouTrack before 2026.1.13162 information disclosure was possible on Users and Groups pages
New
|
CWE-863
Incorrect Authorization
|
CVE-2026-49369
|
2026-06-1 21:56 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
654
|
7.5 |
HIGH
Network
|
jetbrains
|
youtrack
|
In JetBrains YouTrack before 2026.1.13162 information disclosure was possible on fetchApp requests
New
|
CWE-201
Insertion of Sensitive Information Into Sent Data
|
CVE-2026-49370
|
2026-06-1 21:52 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
655
|
6.1 |
MEDIUM
Network
|
jetbrains
|
pycharm
|
In JetBrains PyCharm before 2025.3.4 stored XSS in Jupyter notebook Markdown cells was possible
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-49384
|
2026-06-1 21:44 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
656
|
6.5 |
MEDIUM
Network
|
jetbrains
|
youtrack
|
In JetBrains YouTrack before 2026.1.13570 improper access control allowed low-privileged users to modify service accounts
New
|
CWE-862
Missing Authorization
|
CVE-2026-49385
|
2026-06-1 21:41 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
657
|
6.5 |
MEDIUM
Network
|
jetbrains
|
youtrack
|
In JetBrains YouTrack before 2026.1.13570 improper access control allowed enumeration of restricted issues and articles on Planning Canvas
New
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-49386
|
2026-06-1 21:40 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
658
|
7.3 |
HIGH
Network
|
-
|
-
|
Heap buffer overflow vulnerability in libjxl 0.12.0 via crafted PBM images to the jxl::extras::DecodeImagePNM function in file lib/extras/dec/pnm.cc.
Update
|
CWE-122
Heap-based Buffer Overflow
|
CVE-2025-70103
|
2026-05-31 05:16 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
659
|
7.8 |
HIGH
Local
|
linux
|
linux_kernel
|
In the Linux kernel, the following vulnerability has been resolved:
net: skbuff: preserve shared-frag marker during coalescing
skb_try_coalesce() can attach paged frags from @from to @to. If @from…
Update
|
CWE-787
Out-of-bounds Write
|
CVE-2026-46300
|
2026-05-30 20:17 |
2026-05-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
660
|
7.8 |
HIGH
Local
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
media: iris: Fix use-after-free in iris_release_internal_buffers()
The recent change in commit 1dabf00ee206 ("media: iris: gen1: …
Update
|
-
|
CVE-2026-46240
|
2026-05-30 20:17 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|