|
621
|
7.5 |
HIGH
Network
|
aten
|
unizon
|
ATEN Unizon writeFileToHttpServletResponse Directory Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installat…
New
|
CWE-22
Path Traversal
|
CVE-2026-9776
|
2026-06-28 04:00 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
622
|
6.5 |
MEDIUM
Network
|
aten
|
unizon
|
ATEN Unizon uploadSSL Directory Traversal Arbitrary File Deletion Vulnerability. This vulnerability allows remote attackers to delete arbitrary files on affected installations of ATEN Unizon. Authent…
New
|
CWE-22
Path Traversal
|
CVE-2026-9775
|
2026-06-28 03:59 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
623
|
6.5 |
MEDIUM
Network
|
aten
|
unizon
|
ATEN Unizon updateLicense Directory Traversal Arbitrary File Deletion Vulnerability. This vulnerability allows remote attackers to delete arbitrary files on affected installations of ATEN Unizon. Aut…
New
|
CWE-22
Path Traversal
|
CVE-2026-9774
|
2026-06-28 03:59 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
624
|
9.8 |
CRITICAL
Network
|
jetbrains
|
youtrack
|
In JetBrains YouTrack before 2026.2.16593 the websandbox bridge was vulnerable to a prototype pollution attack
New
|
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
|
CVE-2026-57926
|
2026-06-28 03:51 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
625
|
4.3 |
MEDIUM
Network
|
wolfssl
|
wolfssl
|
Certificate policy and RFC 8446 compliance concerns regarding the continued acceptance of SHA-1/MD5 in certificate processing.
New
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2026-6412
|
2026-06-28 03:41 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
626
|
5.3 |
MEDIUM
Network
|
wolfssl
|
wolfssl
|
A CRL critical extension bypass exists in ParseCRL_Extensions where critical extensions are not properly enforced, allowing a crafted CRL with an unhandled critical extension to be accepted. This onl…
New
|
CWE-295
Improper Certificate Validation
|
CVE-2026-6450
|
2026-06-28 03:32 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
627
|
- |
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
bpf: Fix NULL pointer dereference in bpf_sk_storage_clone and diag paths
bpf_selem_unlink_nofail() sets SDATA(selem)->smap to NUL…
New
|
-
|
CVE-2026-52938
|
2026-06-27 20:16 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
628
|
7.5 |
HIGH
Network
|
-
|
-
|
A buffer overflow in the gf_media_import function (/media_tools/av_parsers.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted input.
New
|
CWE-121
Stack-based Buffer Overflow
|
CVE-2025-60474
|
2026-06-27 15:16 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
629
|
5.5 |
MEDIUM
Local
|
-
|
-
|
A NULL pointer dereference in the gf_filter_in_parent_chain function (/filter_core/filter_pid.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplyin…
New
|
CWE-476
NULL Pointer Dereference
|
CVE-2025-60473
|
2026-06-27 15:16 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
630
|
7.5 |
HIGH
Network
|
-
|
-
|
A use-after-free in the gf_filter_pid_inst_swap_delete_task function (/filter_core/filter_pid.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS) via supplyin…
New
|
CWE-416
Use After Free
|
CVE-2025-60467
|
2026-06-27 15:16 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|