|
1131
|
7.8 |
HIGH
Local
|
google
|
android_xr
|
In addInputMethodListener of com.android.server.inputmethod.InputMethodManagerService, there is a missing permission check. This could lead to local escalation of privilege with no additional executi…
Update
|
CWE-285
Improper Authorization
|
CVE-2026-0072
|
2026-06-4 05:16 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1132
|
7.5 |
HIGH
Network
|
juliangruber
|
brace-expansion
|
The brace-expansion library generates arbitrary strings containing a common prefix and suffix. From 5.0.0 to before 5.0.6, the max option was being applied too late. When expanding a single large num…
Update
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2026-45149
|
2026-06-4 05:13 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1133
|
5.4 |
MEDIUM
Network
|
mozilla
|
firefox
|
Firefox for iOS Reader View replaced page content in its HTML template before replacing other internal placeholders. A malicious page could include a placeholder string that was later substituted wit…
Update
|
CWE-79
Cross-site Scripting
|
CVE-2026-9308
|
2026-06-4 05:02 |
2026-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1134
|
5.4 |
MEDIUM
Network
|
mozilla
|
firefox
|
Firefox for iOS Reader View did not properly escape HTML tags in JSON-LD metadata. A malicious page could inject markup that changed Reader View behavior and leaked sensitive URL parameters. These pa…
Update
|
CWE-79
Cross-site Scripting
|
CVE-2026-9309
|
2026-06-4 05:02 |
2026-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1135
|
7.5 |
HIGH
Network
|
dlink
|
di-7001mini-8g_firmware
|
A vulnerability was detected in D-Link DI-7001 MINI up to 19.09.19A1. Impacted is the function sprintf of the file /httpd_debug.asp of the component API. The manipulation of the argument Time results…
Update
|
CWE-119 CWE-121
Incorrect Access of Indexable Resource ('Range Error') Stack-based Buffer Overflow
|
CVE-2026-10270
|
2026-06-4 05:02 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1136
|
9.6 |
CRITICAL
Network
|
cline
|
cline
|
Cline is an autonomous coding agent as an SDK, IDE extension, or CLI assistant. In versions 2.13.0 and prior, there is a cross-origin WebSocket hijack vulnerability in Cline Kanban servers. At time o…
Update
|
CWE-306 CWE-1385
Missing Authentication for Critical Function Missing Origin Validation in WebSockets
|
CVE-2026-44211
|
2026-06-4 04:52 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1137
|
9.1 |
CRITICAL
Network
|
projectcapsule
|
capsule
|
Capsule is a multi-tenancy and policy-based framework for Kubernetes. The Capsule Controller runs with cluster-admin privileges. Although the TenantResource RawItems processing logic forcibly sets th…
Update
|
CWE-20 CWE-863
Improper Input Validation Incorrect Authorization
|
CVE-2026-22872
|
2026-06-4 04:40 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1138
|
4.9 |
MEDIUM
Network
|
redhat
|
build_of_keycloak
|
A flaw was found in Keycloak. A remote attacker with high privileges, such as a realm administrator configuring a malicious Lightweight Directory Access Protocol (LDAP) server or an attacker compromi…
Update
|
CWE-1284
Improper Validation of Specified Quantity in Input
|
CVE-2026-9801
|
2026-06-4 04:38 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1139
|
4.3 |
MEDIUM
Network
|
redhat
|
build_of_keycloak
|
A flaw was found in Keycloak, an open-source identity and access management solution. When a user account is temporarily locked due to repeated failed login attempts, an attacker with valid client cr…
Update
|
CWE-305
Authentication Bypass by Primary Weakness
|
CVE-2026-9798
|
2026-06-4 04:38 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1140
|
6.5 |
MEDIUM
Network
|
redhat
|
build_of_keycloak
|
A flaw was found in Keycloak. An authenticated administrator with the `manage-clients` role can exploit a Time-of-check to time-of-use (TOCTOU) vulnerability in the name-based admin role checks. This…
Update
|
CWE-367
Time-of-check Time-of-use (TOCTOU) Race Condition
|
CVE-2026-9796
|
2026-06-4 04:38 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|