|
151
|
6.5 |
MEDIUM
Network
|
apache
|
flink_kubernetes_operator
|
Files or Directories Accessible to External Parties, Server-Side Request Forgery (SSRF) vulnerability in Apache Flink Kubernetes Operator.
The FlinkSessionJob jarURI is currently not validated so th…
Update
|
CWE-552 CWE-918
Files or Directories Accessible to External Parties Server-Side Request Forgery (SSRF)
|
CVE-2026-40564
|
2026-06-3 01:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
152
|
7.5 |
HIGH
Network
|
-
|
-
|
FlexRIC v2.0.0 contains an authorization bypass in the iApp's xApp isolation mechanism. The equality function eq_xapp_ric_gen_id() in src/ric/iApp/xapp_ric_id.c compares m0->xapp_id against itself (m…
New
|
CWE-617
Reachable Assertion
|
CVE-2026-37233
|
2026-06-3 01:16 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
153
|
7.5 |
HIGH
Network
|
-
|
-
|
FlexRIC v2.0.0 crashes when the near-RT RIC receives a RIC_INDICATION message with a ran_func_id that does not exist in its registry. The lookup returns NULL, triggering assert() in Debug builds (SIG…
New
|
CWE-476
NULL Pointer Dereference
|
CVE-2026-37230
|
2026-06-3 01:16 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
154
|
7.5 |
HIGH
Network
|
-
|
-
|
FlexRIC v2.0.0 crashes when the iApp receives an E42_RIC_SUBSCRIPTION_REQUEST referencing a non-existent E2 Node. The lookup function returns NULL, which is enforced by assert() in Debug builds (SIGA…
New
|
CWE-476
NULL Pointer Dereference
|
CVE-2026-37226
|
2026-06-3 01:16 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
155
|
- |
|
-
|
-
|
Path traversal vulnerability in Gleam's handling of custom documentation pages allows arbitrary file read and file write outside the intended documentation output directory.
The documentation.pages …
New
|
CWE-22
Path Traversal
|
CVE-2026-32685
|
2026-06-3 01:16 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
156
|
4.3 |
MEDIUM
Network
|
-
|
-
|
NamelessMC is website software for Minecraft servers. A Reflected Cross-Site Scripting (XSS) vulnerability was discovered in version 2.2.4 in the id parameter of the endpoint `/index.php?route=/queri…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-32250
|
2026-06-3 01:16 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
157
|
3.9 |
LOW
Network
|
-
|
-
|
Capsule is a multi-tenancy and policy-based framework for Kubernetes. To defend against namespace hijacking achieved through update/patch operations on namespaces, Capsule uses a webhook to validate …
New
|
CWE-20
Improper Input Validation
|
CVE-2026-30963
|
2026-06-3 01:16 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
158
|
7.8 |
HIGH
Local
|
-
|
-
|
In setGlobalProxy of DevicePolicyManagerService.java, there is a possible desync in persistence due to improper input validation. This could lead to local escalation of privilege with no additional e…
New
|
CWE-20
Improper Input Validation
|
CVE-2026-0078
|
2026-06-3 01:16 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
159
|
7.8 |
HIGH
Local
|
google
|
android
|
In validateNode of ResourceTypes.cpp, there is a possible out of bounds read due to an incorrect bounds check. This could lead to local escalation of privilege with no additional execution privileges…
New
|
CWE-125
Out-of-bounds Read
|
CVE-2026-0076
|
2026-06-3 01:16 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
160
|
7.5 |
HIGH
Network
|
-
|
-
|
A NULL pointer dereference in the ext4_dir_en_get_name_len function in include/ext4_dir.h of lwext4 1.0.0 allows attackers to cause a denial of service by supplying a specially crafted EXT4 filesyste…
New
|
CWE-476
NULL Pointer Dereference
|
CVE-2025-70099
|
2026-06-3 01:16 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|