|
561
|
- |
|
-
|
-
|
Kanidm is an identity management platform. Prior to version 1.9.3, a single unauthenticated GET to any /scim/v1/... endpoint with a ?filter= query string of a few thousand nested parentheses (≈ 4–12 …
New
|
CWE-248 CWE-400 CWE-674
Uncaught Exception Uncontrolled Resource Consumption Uncontrolled Recursion
|
CVE-2026-46689
|
2026-06-12 00:36 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
562
|
5.4 |
MEDIUM
Network
|
apache
|
answer
|
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache Answer.
This issue affects Apache Answer: through 2.0.0.
User-supplied content was included in …
New
|
CWE-80 CWE-79
Basic XSS Cross-site Scripting
|
CVE-2026-34033
|
2026-06-12 00:35 |
2026-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
563
|
- |
|
-
|
-
|
SpiceDB is an open source database system for creating and managing security-critical application permissions. From version 1.15.0 to before version 1.52.0, caveat structures with nested lists can re…
New
|
CWE-285
Improper Authorization
|
CVE-2026-46668
|
2026-06-12 00:35 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
564
|
- |
|
-
|
-
|
Allocation of Resources Without Limits or Throttling vulnerability in membraneframework membrane_mp4_plugin allows unauthenticated denial-of-service via BEAM atom table exhaustion.
The MP4 box heade…
New
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2026-53423
|
2026-06-12 00:35 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
565
|
7.0 |
HIGH
Local
|
microsoft
|
windows_10_21h2 windows_10_22h2 windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2022 windows_server_2025
|
Time-of-check time-of-use (TOCTOU) race condition in Program Compatibility Assistant Service allows an authorized attacker to elevate privileges locally.
New
|
CWE-367
Time-of-check Time-of-use (TOCTOU) Race Condition
|
CVE-2026-45487
|
2026-06-12 00:35 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
566
|
6.1 |
MEDIUM
Local
|
-
|
-
|
bit7z is a cross-platform C++ static library that allows the compression/extraction of archive files. Prior to version 4.0.12, there is an arbitrary file overwrite vulnerability via symlink attack on…
New
|
CWE-59 CWE-377
Link Following Insecure Temporary File
|
CVE-2026-45384
|
2026-06-12 00:35 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
567
|
7.8 |
HIGH
Local
|
-
|
-
|
GIMP HDR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User inte…
New
|
CWE-122
Heap-based Buffer Overflow
|
CVE-2026-2049
|
2026-06-12 00:34 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
568
|
7.0 |
HIGH
Network
|
-
|
-
|
Fedify is a TypeScript library for building federated server apps powered by ActivityPub. Prior to versions 1.9.11, 1.10.10, 2.0.18, 2.1.14, and 2.2.3, an attacker can make use of JSON-LD features to…
New
|
CWE-180 CWE-347 CWE-436 CWE-1289
Incorrect Behavior Order: Validate Before Canonicalize Improper Verification of Cryptographic Signature Interpretation Conflict Improper Validation of Unsafe Equivalence in Input
|
CVE-2026-42462
|
2026-06-12 00:34 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
569
|
- |
|
-
|
-
|
Boruta is a standalone authorization server that aims to implement OAuth 2.0 and Openid Connect up to decentralized identity specifications. Prior to version 0.9.1, boruta session cookies and the ide…
New
|
CWE-614
Sensitive Cookie in HTTPS Session Without 'Secure' Attribute
|
CVE-2026-53661
|
2026-06-12 00:34 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
570
|
5.8 |
MEDIUM
Network
|
-
|
-
|
Guzzle Services provides an implementation of the Guzzle Command library that uses Guzzle service descriptions to describe web services, serialize requests, and parse responses into easy to use model…
New
|
CWE-20 CWE-91
Improper Input Validation Blind XPath Injection
|
CVE-2026-53723
|
2026-06-12 00:34 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|