|
841
|
5.3 |
MEDIUM
Network
|
-
|
-
|
An attacker can send crafted DNS over HTTP/3 queries, triggering an exception that prevents some buffer from being freed right away. The buffer will be freed at the end of the QUIC connection, but on…
New
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2026-40211
|
2026-06-26 00:59 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
842
|
3.7 |
LOW
Network
|
-
|
-
|
An attacker can send a crafted EDNS OPT record that will be ignored by DNSdist’s filtering rules, but will be rewritten as a valid OPT record when EDNS Client Subnet is inserted, causing the backend …
New
|
CWE-115
Misinterpretation of Input
|
CVE-2026-42004
|
2026-06-26 00:59 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
843
|
5.3 |
MEDIUM
Network
|
-
|
-
|
An invalid zone might pass ZONEMD validation while it should not. This is only relevant if ZoneToCache is configured with ZONEMD validation.
New
|
CWE-20
Improper Input Validation
|
CVE-2026-42390
|
2026-06-26 00:59 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
844
|
5.9 |
MEDIUM
Network
|
-
|
-
|
Spoofing replies to Recursor might mark an IP of an authoritative server as not supporting EDNS, causing valdiation of DNSSEC records served by that server to fail.
New
|
CWE-290
Authentication Bypass by Spoofing
|
CVE-2026-52690
|
2026-06-26 00:59 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
845
|
4.7 |
MEDIUM
Network
|
google
|
chrome
|
Inappropriate implementation in Passwords in Google Chrome prior to 149.0.7827.197 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page.…
New
|
CWE-346
Origin Validation Error
|
CVE-2026-13034
|
2026-06-26 00:23 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
846
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Contributor Sensitive Data Exposure in Elementor Website Builder <= 4.1.3 versions.
New
|
CWE-862
Missing Authorization
|
CVE-2026-57619
|
2026-06-26 00:16 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
847
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Contributor Broken Access Control in Slim SEO <= 4.6.2 versions.
New
|
CWE-862
Missing Authorization
|
CVE-2026-57429
|
2026-06-26 00:16 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
848
|
7.1 |
HIGH
Network
|
-
|
-
|
An arbitrary address write vulnerability was found in libaom, the reference AV1 codec implementation. A missing bounds check in the SVC (Scalable Video Coding) layer ID control function allows an att…
New
|
CWE-787
Out-of-bounds Write
|
CVE-2026-56209
|
2026-06-26 00:16 |
2026-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
849
|
7.6 |
HIGH
Network
|
-
|
-
|
A heap buffer overflow vulnerability was found in libaom, the reference AV1 codec implementation. A flaw in the AV1 encoder's Look-Ahead Processing (LAP) mode causes the first-pass stats ring buffer …
New
|
CWE-122
Heap-based Buffer Overflow
|
CVE-2026-56208
|
2026-06-26 00:16 |
2026-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
850
|
7.7 |
HIGH
Network
|
-
|
-
|
Subscriber Arbitrary File Deletion in JS Help Desk <= 3.1.1 versions.
New
|
CWE-22
Path Traversal
|
CVE-2026-56054
|
2026-06-26 00:16 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|