|
751
|
10.0 |
CRITICAL
Network
|
adobe
|
coldfusion
|
ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitati…
Update
|
CWE-20 NVD-CWE-noinfo
Improper Input Validation
|
CVE-2026-47928
|
2026-06-16 00:20 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
752
|
9.1 |
CRITICAL
Network
|
adobe
|
coldfusion
|
ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Incorrect Authorization vulnerability that could result in arbitrary code execution in the context of the current user. A high-privi…
Update
|
CWE-863
Incorrect Authorization
|
CVE-2026-47929
|
2026-06-16 00:18 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
753
|
8.1 |
HIGH
Network
|
adobe
|
coldfusion
|
ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Input Validation vulnerability that could result in a Security feature bypass. A low-privileged attacker could leverage thi…
Update
|
CWE-20 NVD-CWE-noinfo
Improper Input Validation
|
CVE-2026-47930
|
2026-06-16 00:18 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
754
|
9.9 |
CRITICAL
Network
|
adobe
|
coldfusion
|
ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Input Validation vulnerability that could result in arbitrary code execution in the context of the current user. Exploitati…
Update
|
CWE-20 NVD-CWE-noinfo
Improper Input Validation
|
CVE-2026-47931
|
2026-06-16 00:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
755
|
9.6 |
CRITICAL
Network
|
adobe
|
coldfusion
|
ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could result in a Security feature…
Update
|
CWE-22
Path Traversal
|
CVE-2026-47932
|
2026-06-16 00:12 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
756
|
5.4 |
MEDIUM
Network
|
adobe
|
coldfusion
|
ColdFusion versions 2023.19, 2025.8 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-privileged attacker to inject malicious scripts into vu…
Update
|
CWE-79
Cross-site Scripting
|
CVE-2026-47933
|
2026-06-16 00:11 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
757
|
7.4 |
HIGH
Network
|
adobe
|
coldfusion
|
ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could lead to arbitrary file system read. An attack…
Update
|
CWE-611
XXE
|
CVE-2026-47960
|
2026-06-16 00:09 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
758
|
5.5 |
MEDIUM
Local
|
adobe
|
c2pa c2pa-web
|
CAI Content Credentials versions c2pa-web@0.7.1, c2pa-v0.80.1 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could re…
Update
|
CWE-22
Path Traversal
|
CVE-2026-34657
|
2026-06-16 00:08 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
759
|
7.5 |
HIGH
Network
|
adobe
|
c2pa c2pa-web
|
CAI Content Credentials versions c2pa-web@0.7.1, c2pa-v0.80.1 and earlier are affected by an Integer Overflow or Wraparound vulnerability. An attacker could exploit this vulnerability to crash the ap…
Update
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2026-34711
|
2026-06-16 00:07 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
760
|
5.7 |
MEDIUM
Network
|
splunk
|
splunk splunk_cloud_platform
|
In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, and Splunk Cloud Platform versions below 10.3.2512.13, 10.2.2510.15, 10.1.2507.23, and 9.3.2411.132, a low-privileged user that…
Update
|
CWE-20
Improper Input Validation
|
CVE-2026-20254
|
2026-06-16 00:05 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|