|
941
|
7.5 |
HIGH
Network
|
yhirose
|
cpp-httplib
|
cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.43.4, negative chunk-size in chunked Transfer-Encoding causes unbounded memory allocation and process cras…
Update
|
CWE-20 CWE-770 CWE-1285
Improper Input Validation Allocation of Resources Without Limits or Throttling Improper Validation of Specified Index, Position, or Offset in Input
|
CVE-2026-45352
|
2026-06-2 12:16 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
942
|
5.3 |
MEDIUM
Network
|
-
|
-
|
FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to 1.8.219, the password reset endpoint returns visually distinct responses depending on whether the submitted…
Update
|
CWE-203 CWE-204
Information Exposure Through Discrepancy Response Discrepancy Information Exposure
|
CVE-2026-45294
|
2026-06-2 12:16 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
943
|
8.6 |
HIGH
Network
|
-
|
-
|
Klever-Go is the Go implementation of the Klever blockchain protocol. Prior to 1.7.17, a remote, unauthenticated denial-of-service vulnerability in Batch.Decompress (data/batch/batch.go) allows any p…
Update
|
CWE-409 CWE-770
Improper Handling of Highly Compressed Data (Data Amplification) Allocation of Resources Without Limits or Throttling
|
CVE-2026-44697
|
2026-06-2 12:16 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
944
|
9.8 |
CRITICAL
Network
|
-
|
-
|
SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to 1.18.0,…
Update
|
CWE-290 CWE-306 CWE-346 CWE-807
Authentication Bypass by Spoofing Missing Authentication for Critical Function Origin Validation Error Reliance on Untrusted Inputs in a Security Decision
|
CVE-2026-44649
|
2026-06-2 12:16 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
945
|
8.8 |
HIGH
Network
|
freerdp
|
freerdp
|
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, a malicious RDP client can trigger a heap-buffer-overflow write in FreeRDP's server-side clipboard (cliprdr) channel …
Update
|
CWE-122
Heap-based Buffer Overflow
|
CVE-2026-44420
|
2026-06-2 12:16 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
946
|
4.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was determined in Open5GS up to 2.7.7. Affected by this issue is the function handle_scp_info in the library lib/sbi/nnrf-handler.c of the component Shared NF-profile Parser. This man…
Update
|
CWE-119 CWE-787
Incorrect Access of Indexable Resource ('Range Error') Out-of-bounds Write
|
CVE-2026-10114
|
2026-06-2 12:16 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
947
|
8.3 |
HIGH
Network
|
-
|
-
|
agno 2.6.5 contains a SQL injection vulnerability in the ClickHouse vector database backend that allows attackers to inject arbitrary SQL expressions by supplying malicious metadata keys and values t…
Update
|
CWE-89
SQL Injection
|
CVE-2026-10105
|
2026-06-2 12:16 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
948
|
7.5 |
HIGH
Network
|
-
|
-
|
A vulnerability has been found in Shibby Tomato 1.28. The impacted element is an unknown function of the file usr/sbin/miniupnpd. Such manipulation leads to resource consumption. The attack may be la…
Update
|
CWE-400 CWE-404
Uncontrolled Resource Consumption Improper Resource Shutdown or Release
|
CVE-2026-10069
|
2026-06-2 12:16 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
949
|
9.9 |
CRITICAL
Network
|
-
|
-
|
RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In 0.24.0 and earlier, a Jinja2 template injection in the prompt generator (rag/prompts/generator.py) allows any authenticated u…
Update
|
CWE-1336
Improper Neutralization of Special Elements Used in a Template Engine
|
CVE-2026-45312
|
2026-06-2 11:16 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
950
|
- |
|
-
|
-
|
RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, improper validation in the PUT /rustfs/admin/v3/import-iam endpoint allows a user with ImportIAMAction to create se…
Update
|
CWE-269 CWE-284
Improper Privilege Management Improper Access Control
|
CVE-2026-45043
|
2026-06-2 11:16 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|