|
611
|
6.8 |
MEDIUM
Network
|
-
|
-
|
Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 31.0.0 to before 31.0.12, and 32.0.0 to before 32.0.3, a missing check of a relation allowed authenticate…
New
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-45810
|
2026-06-2 23:00 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
612
|
8.8 |
HIGH
Network
|
bentoml
|
bentoml
|
BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4.39, src/bentoml/_internal/container/frontend/dockerfile/templates/base_v2.j2 in…
Update
|
CWE-78
OS Command
|
CVE-2026-44345
|
2026-06-2 22:59 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
613
|
- |
|
-
|
-
|
Server-Side Template Injection (SSTI) in Wirtualna Uczelnia allows an unauthenticated attacker to perform Remote Code Execution (RCE). In the endpoint redirectToUrl and parameter redirectUrlParameter…
New
|
CWE-1336
Improper Neutralization of Special Elements Used in a Template Engine
|
CVE-2026-34906
|
2026-06-2 22:54 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
614
|
- |
|
-
|
-
|
Wirtualna Uczelnia is vulnerable to Reflected Cross‑Site Scripting (XSS) due to insecure handling of the locale parameter across multiple endpoints. An attacker can craft a malicious URL with JavaScr…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-34907
|
2026-06-2 22:54 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
615
|
8.8 |
HIGH
Network
|
bentoml
|
bentoml
|
BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4.39, a malicious bentofile.yaml containing a newline-injected value in envs[*].n…
Update
|
CWE-78 CWE-94
OS Command Code Injection
|
CVE-2026-44346
|
2026-06-2 22:48 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
616
|
7.5 |
HIGH
Network
|
botan_project
|
botan
|
Botan is a C++ cryptography library. Prior to 3.12.0, certain patterns of indefinite length encodings in BER data could cause quadratic behavior in the parser, resulting in a denial of service. Such …
Update
|
CWE-407
Inefficient Algorithmic Complexity
|
CVE-2026-44378
|
2026-06-2 22:42 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
617
|
7.2 |
HIGH
Network
|
tp-link
|
archer_be450_firmware archer_be7200_firmware
|
An authenticated command injection vulnerability exists in the Archer BE450 v1 and BE7200 v1 router that allows an administrator to execute arbitrary system commands through the web management interf…
Update
|
CWE-20 CWE-77
Improper Input Validation Command Injection
|
CVE-2026-5509
|
2026-06-2 22:40 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
618
|
8.8 |
HIGH
Network
|
jetbrains
|
teamcity
|
In JetBrains TeamCity before 2026.1 remote code execution was possible via Perforce connection settings
Update
|
CWE-88
Argument Injection
|
CVE-2026-49373
|
2026-06-2 22:13 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
619
|
7.6 |
HIGH
Network
|
jetbrains
|
teamcity
|
In JetBrains TeamCity before 2026.1 improper permission checks exposed build configuration parameters
Update
|
CWE-862
Missing Authorization
|
CVE-2026-49374
|
2026-06-2 22:12 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
620
|
6.1 |
MEDIUM
Network
|
jetbrains
|
teamcity
|
In JetBrains TeamCity before 2026.1,
2025.11.5 reflected XSS was possible on the repository download page
Update
|
CWE-79
Cross-site Scripting
|
CVE-2026-49375
|
2026-06-2 22:11 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|