|
1651
|
6.5 |
MEDIUM
Network
|
streamlink
|
streamlink
|
Streamlink is a CLI utility which pipes video streams from various services into a video player. Prior to 8.4.0, Streamlink's HLS and DASH parsers do not validate the URI scheme of segment entries an…
|
CWE-22
Path Traversal
|
CVE-2026-44353
|
2026-06-2 05:14 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1652
|
5.5 |
MEDIUM
Local
|
wireshark
|
wireshark
|
ROHC protocol dissector crash in Wireshark 4.6.0 to 4.6.5 and 4.4.0 to 4.4.15 allows denial of service
|
CWE-476
NULL Pointer Dereference
|
CVE-2026-9759
|
2026-06-2 04:26 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1653
|
7.3 |
HIGH
Network
|
-
|
-
|
Plack::Middleware::Security::Common versions before 0.13.1 for Perl did not block header injections in request paths.
The header injection rule was ineffective at blocking header injections in the r…
|
CWE-113 CWE-790
HTTP Response Splitting
|
CVE-2026-9658
|
2026-06-2 04:16 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1654
|
9.1 |
CRITICAL
Network
|
-
|
-
|
Casdoor versions 2.362.0 and earlier contain a vulnerability involving unverified email binding that may enable account takeover. The getExistUserByBindingRule function matches users by email without…
|
-
|
CVE-2026-9092
|
2026-06-2 04:16 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1655
|
4.3 |
MEDIUM
Network
|
-
|
-
|
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to 1.8.221, while investigating the ThreadPolicy::delete issue reported previously, the same missing mailbox m…
|
CWE-285
Improper Authorization
|
CVE-2026-48810
|
2026-06-2 04:16 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1656
|
9.0 |
CRITICAL
Network
|
-
|
-
|
Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.28.8 and earlier, authenticated OS command injection in the application.updateTraefikConfig tRPC endpoint allows admin/owner users …
|
CWE-78
OS Command
|
CVE-2026-45630
|
2026-06-2 04:16 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1657
|
7.2 |
HIGH
Network
|
waterfall-security
|
wf-500_firmware
|
Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Administration WebUI in Waterfall WF-500 TX Host in version…
|
CWE-78
OS Command
|
CVE-2025-41265
|
2026-06-2 03:58 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1658
|
7.2 |
HIGH
Network
|
waterfall-security
|
wf-500_firmware
|
Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Administration WebUI in Waterfall WF-500 TX Host in version…
|
CWE-78
OS Command
|
CVE-2025-41266
|
2026-06-2 03:57 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1659
|
7.2 |
HIGH
Network
|
waterfall-security
|
wf-500_firmware
|
Nozomi Networks Labs identified a CWE-78: Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') in the Administration WebUI in Waterfall WF-500 TX Host in version…
|
CWE-78
OS Command
|
CVE-2025-41267
|
2026-06-2 03:57 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1660
|
9.1 |
CRITICAL
Network
|
waterfall-security
|
wf-500_firmware
|
Nozomi Networks Labs identified a CWE-23: Relative Path Traversal in the Administration WebUI in Waterfall WF-500 TX and RX Hosts in version 7.9.1.0 R2502171040 that allows remote unauthenticated att…
|
CWE-23
Relative Path Traversal
|
CVE-2025-41268
|
2026-06-2 03:57 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|