|
641
|
7.0 |
HIGH
Local
|
microsoft
|
windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2022 windows_server_2025
|
Concurrent execution using shared resource with improper synchronization ('race condition') in UI Automation Manager (uiamanager.dll) allows an authorized attacker to elevate privileges locally.
New
|
CWE-362
Race Condition
|
CVE-2026-45597
|
2026-06-12 00:03 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
642
|
7.0 |
HIGH
Local
|
microsoft
|
windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2012 windows_server_2016 w…
|
Use after free in Windows Ancillary Function Driver for WinSock allows an authorized attacker to elevate privileges locally.
New
|
CWE-362
Race Condition
|
CVE-2026-45598
|
2026-06-12 00:00 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
643
|
8.1 |
HIGH
Network
|
microsoft
|
windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2012 windows_server_2016 w…
|
Use after free in Universal Plug and Play (upnp.dll) allows an unauthorized attacker to execute code over a network.
New
|
CWE-416
Use After Free
|
CVE-2026-45599
|
2026-06-11 23:57 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
644
|
7.1 |
HIGH
Local
|
-
|
-
|
A malicious application may cause unexpected changes in memory shared between processes. A memory corruption issue was addressed with improved state management. This issue is fixed in macOS Monterey …
New
|
CWE-362
Race Condition
|
CVE-2022-26758
|
2026-06-11 23:43 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
645
|
3.5 |
LOW
Physics
|
-
|
-
|
A person with access to a Mac may be able to bypass Login Window. A consistency issue was addressed with improved state handling. This issue is fixed in macOS Monterey 12.4.
New
|
CWE-287
Improper Authentication
|
CVE-2022-48575
|
2026-06-11 23:43 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
646
|
5.3 |
MEDIUM
Local
|
-
|
-
|
Improper input validation for DIMM serial presence detect (SPD) metadata could allow an attacker with physical access, ring0 access on a system with a non-compliant DIMM, or control over the Root of …
New
|
CWE-20
Improper Input Validation
|
CVE-2024-21944
|
2026-06-11 23:43 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
647
|
3.7 |
LOW
Network
|
-
|
-
|
A vulnerability was determined in TwiN gatus 5.36.0. Impacted is the function setSessionCookie of the file security/oidc.go of the component OIDC Session Cookie Handler. Executing a manipulation can …
New
|
CWE-614 CWE-1004
Sensitive Cookie in HTTPS Session Without 'Secure' Attribute Sensitive Cookie Without 'HttpOnly' Flag
|
CVE-2026-11956
|
2026-06-11 23:42 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
648
|
4.7 |
MEDIUM
Network
|
-
|
-
|
The Open User Map PRO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'oum_location_notification' parameter in versions up to, and including, 1.4.31 due to insufficient inpu…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-2827
|
2026-06-11 23:42 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
649
|
8.1 |
HIGH
Network
|
-
|
-
|
The UpdraftPlus: WP Backup & Migration Plugin plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.26.4 via the UpdraftPlus_Remote_Communications_V2::wp…
New
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2026-10795
|
2026-06-11 23:42 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
650
|
7.1 |
HIGH
Network
|
-
|
-
|
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in WPVibes WP Mail Log allows DOM-Based XSS.
This issue affects WP Mail Log: from n/a through 1.0.2.
New
|
CWE-79
Cross-site Scripting
|
CVE-2023-33999
|
2026-06-11 23:42 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|