|
601
|
9.3 |
CRITICAL
Adjacent
|
-
|
-
|
A flaw was found in assisted-migration-agent. The application hardcodes insecure Transport Layer Security (TLS) connections when communicating with vCenter. This vulnerability allows a Man-in-the-Mid…
New
|
CWE-295
Improper Certificate Validation
|
CVE-2026-53475
|
2026-06-11 00:16 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
602
|
9.6 |
CRITICAL
Network
|
-
|
-
|
A flaw was found in migration-planner. A remote authenticated attacker could exploit this vulnerability by uploading a specially crafted RVTools .xlsx file. Due to improper input sanitization, malici…
New
|
CWE-89
SQL Injection
|
CVE-2026-53474
|
2026-06-11 00:16 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
603
|
7.3 |
HIGH
Network
|
-
|
-
|
A flaw was found in migration-planner-ui-app. An attacker can register a malicious discovery agent with a specially crafted credentialUrl containing JavaScript code. When an organizational user click…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-53473
|
2026-06-11 00:16 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
604
|
9.6 |
CRITICAL
Network
|
-
|
-
|
A flaw was found in migration-planner. An authenticated attacker could exploit an improper access control vulnerability in the `/api/v1/sources/{id}/image-url` endpoint. This flaw allows the attacker…
New
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-53470
|
2026-06-11 00:16 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
605
|
9.1 |
CRITICAL
Network
|
-
|
-
|
A flaw was found in migration-planner. An authenticated user can exploit this vulnerability by sending a DELETE request to the /api/v1/sources route, which lacks proper authorization and filtering. T…
New
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2026-53469
|
2026-06-11 00:16 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
606
|
4.8 |
MEDIUM
Network
|
-
|
-
|
Ghidra before 12.2 contains an unauthenticated path traversal vulnerability in the IsfServer that accepts TCP connections and passes client-supplied namespace strings directly to filesystem operation…
New
|
CWE-22
Path Traversal
|
CVE-2026-52756
|
2026-06-11 00:16 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
607
|
6.1 |
MEDIUM
Local
|
-
|
-
|
Ghidra before 12.1 contains a heap-use-after-free vulnerability in SleighBuilder::generatePointerAdd caused by iterator invalidation when PcodeCacher::allocateInstruction reallocates the issued vecto…
New
|
CWE-416
Use After Free
|
CVE-2026-49496
|
2026-06-11 00:16 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
608
|
9.9 |
CRITICAL
Network
|
-
|
-
|
Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, the install blueprint declares only bp.before_request → @jwt_required() (app/rout…
New
|
CWE-639 CWE-862 CWE-863
Authorization Bypass Through User-Controlled Key Missing Authorization Incorrect Authorization
|
CVE-2026-45552
|
2026-06-11 00:16 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
609
|
8.8 |
HIGH
Network
|
-
|
-
|
Issue summary: A specially crafted PKCS#7 or S/MIME signed message could
trigger a use-after-free during PKCS#7 signature verification.
Impact summary: A use-after-free may result in process crashes…
New
|
CWE-416
Use After Free
|
CVE-2026-45447
|
2026-06-11 00:16 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
610
|
9.8 |
CRITICAL
Network
|
-
|
-
|
DedeCMS V5.7.118 is vulnerable to Command Execution in file_manage_control.php.
New
|
CWE-78
OS Command
|
CVE-2026-38615
|
2026-06-11 00:16 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|