|
571
|
7.3 |
HIGH
Local
|
presire
|
qsnapper
|
A path traversal attack when using a "configName" parameter in qSnapper before version 1.3.3 allowed a local attacker to use malicious config files for snapper and so cause a denial of service or pot…
New
|
CWE-23
Relative Path Traversal
|
CVE-2026-41046
|
2026-06-28 09:17 |
2026-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
572
|
7.0 |
HIGH
Local
|
presire
|
qsnapper
|
A time-to-check-time-of-use in polkit authentication of qSnapper before version 1.3.3 allowed a local attacker to bypass qSnappers authentication mechanism and operate e.g. as root user.
New
|
CWE-367
Time-of-check Time-of-use (TOCTOU) Race Condition
|
CVE-2026-41045
|
2026-06-28 09:10 |
2026-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
573
|
5.5 |
MEDIUM
Local
|
presire
|
qsnapper
|
Lack of authentication when using the "snapshot diff" functions in qSnapper before version 1.3.3 allowed a local attacker to see otherwise read protected information.
New
|
CWE-306 CWE-863
Missing Authentication for Critical Function Incorrect Authorization
|
CVE-2026-41047
|
2026-06-28 09:08 |
2026-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
574
|
7.1 |
HIGH
Local
|
presire
|
qsnapper
|
Incorrect caching of authentication between different polkit methods in qSnapper before version 1.3.3 allowed a local attacker to use functions like "restore from snapshot" even if only allowed to do…
New
|
CWE-303 CWE-863
Incorrect Implementation of Authentication Algorithm Incorrect Authorization
|
CVE-2026-41048
|
2026-06-28 09:06 |
2026-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
575
|
7.1 |
HIGH
Local
|
presire
|
qsnapper
|
Incorrect caching of authentication between different users of the qSnapper dbus service before version 1.3.3 allowed any local attacker to use dbus functions after a privileged users has authentica…
New
|
CWE-303 CWE-863
Incorrect Implementation of Authentication Algorithm Incorrect Authorization
|
CVE-2026-41049
|
2026-06-28 08:59 |
2026-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
576
|
7.5 |
HIGH
Network
|
fasterxml
|
jackson-databind
|
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.13.0 until 2.14.0, a potential Denial-of-Service exists when attacker sends …
New
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2026-50193
|
2026-06-28 06:05 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
577
|
8.1 |
HIGH
Network
|
fasterxml
|
jackson-databind
|
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21.4, and 3.1.4, jackson-databind's PolymorphicTypeVali…
New
|
CWE-184 CWE-502
Incomplete Blacklist Deserialization of Untrusted Data
|
CVE-2026-54512
|
2026-06-28 06:01 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
578
|
8.1 |
HIGH
Network
|
fasterxml
|
jackson-databind
|
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21.4, and 3.1.4, BasicPolymorphicTypeValidator.Builder.…
New
|
CWE-184
Incomplete Blacklist
|
CVE-2026-54513
|
2026-06-28 06:00 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
579
|
5.3 |
MEDIUM
Network
|
fasterxml
|
jackson-databind
|
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.0.0 until 2.18.8, 2.21.4, and 3.1.4, JDKFromStringDeserializer constructed I…
New
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-54514
|
2026-06-28 05:55 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
580
|
5.3 |
MEDIUM
Network
|
fasterxml
|
jackson-databind
|
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.21.0 until 2.21.4 and 3.1.4, POJOPropertiesCollector._renameProperties() all…
New
|
CWE-915
Improperly Controlled Modification of Dynamically-Determined Object Attributes
|
CVE-2026-54516
|
2026-06-28 05:52 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|