|
171
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Nextcloud is an open source content collaboration platform. Prior to version 5.2.6, a missing permissions check allowed users to request reading form submissions of other users. This issue has been p…
New
|
CWE-200 CWE-862
Information Exposure Missing Authorization
|
CVE-2026-45267
|
2026-06-2 03:14 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
172
|
8.8 |
HIGH
Network
|
google
|
chrome
|
Inappropriate implementation in ANGLE in Google Chrome on Mac prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security …
Update
|
CWE-269
Improper Privilege Management
|
CVE-2026-9999
|
2026-06-2 03:14 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
173
|
8.3 |
HIGH
Network
|
-
|
-
|
Velocity.js is a JavaScript implementation of the Apache Velocity template engine. In 2.1.5 and earlier, a prototype pollution vulnerability was discovered in velocityjs. This issue occurs during the…
Update
|
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
|
CVE-2026-44966
|
2026-06-2 03:13 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
174
|
7.8 |
HIGH
Local
|
-
|
-
|
Command injection in Raynet rvia version 12.6 Update 8 and previous versions allows adversaries to execute arbitrary code via a crafted path that matches the improperly terminated search criteria of …
Update
|
CWE-77
Command Injection
|
CVE-2026-38945
|
2026-06-2 03:12 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
175
|
7.8 |
HIGH
Local
|
-
|
-
|
Command injection in Raynet rvia RayVentory Scan Engine 12.6 Update 8 and previous versions allows adversaries to execute commands via getconfig, upload, inventory, and oracle options.
Update
|
CWE-77
Command Injection
|
CVE-2025-69600
|
2026-06-2 03:12 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
176
|
9.9 |
CRITICAL
Network
|
-
|
-
|
Exposed methods allow authenticated users to create and execute arbitrary JavaScript code on the server. The scripts execute with full access, enabling complete system compromise as commands are exec…
Update
|
CWE-78
OS Command
|
CVE-2026-9645
|
2026-06-2 03:12 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
177
|
6.1 |
MEDIUM
Network
|
-
|
-
|
A reflected cross-site scripting issue exists in URL handling.
Update
|
CWE-80
Basic XSS
|
CVE-2026-9646
|
2026-06-2 03:12 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
178
|
4.0 |
MEDIUM
Local
|
-
|
-
|
XX-Net V5.16.6 contains a WebSocket frame parsing vulnerability in the WebSocket_receive_worker routine of simple_http_server.py that allows attackers to cause corrupted application data by sending u…
Update
|
CWE-1286
Improper Validation of Syntactic Correctness of Input
|
CVE-2026-10099
|
2026-06-2 03:12 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
179
|
7.2 |
HIGH
Network
|
-
|
-
|
The template upload feature in Emlog Pro v2.6.9 has a path traversal vulnerability, allowing authenticated administrators to execute arbitrary PHP code. By uploading a malicious ZIP archive containin…
Update
|
CWE-22
Path Traversal
|
CVE-2026-39276
|
2026-06-2 03:12 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
180
|
5.3 |
MEDIUM
Network
|
-
|
-
|
Exim 4.88 before 4.99.4, in some proxy configurations, mishandles certain short payloads, leading to disclosure of uninitialized stack memory values to a client.
New
|
CWE-839
Numeric Range Comparison Without Minimum Check
|
CVE-2026-48840
|
2026-06-2 03:12 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|