|
881
|
7.5 |
HIGH
Network
|
microsoft
|
windows_10_1809 windows_10_21h2 windows_10_22h2 windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2019 windows_server_2022 windows_server_2025
|
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
New
|
CWE-416 CWE-787
Use After Free Out-of-bounds Write
|
CVE-2026-48563
|
2026-06-11 02:32 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
882
|
7.0 |
HIGH
Local
|
milvus
|
milvus
|
A vulnerability has been found in milvus-io milvus up to 2.6.13. This vulnerability affects unknown code of the file internal/metastore/kv/rootcoord/kv_catalog.go of the component Grantee ID Hash Han…
Update
|
CWE-327 CWE-328
Use of a Broken or Risky Cryptographic Algorithm Use of Weak Hash
|
CVE-2026-10814
|
2026-06-11 02:32 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
883
|
4.3 |
MEDIUM
Network
|
google
|
chrome
|
Inappropriate implementation in File Input in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafte…
Update
|
CWE-451
User Interface (UI) Misrepresentation of Critical Information
|
CVE-2026-11228
|
2026-06-11 02:25 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
884
|
6.5 |
MEDIUM
Network
|
google
|
chrome
|
Type Confusion in XML in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted XML file. (Chromium security seve…
Update
|
CWE-843
Type Confusion
|
CVE-2026-11196
|
2026-06-11 02:25 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
885
|
5.5 |
MEDIUM
Local
|
microsoft
|
windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2025
|
Out-of-bounds read in Windows DWM Core Library allows an authorized attacker to disclose information locally.
New
|
CWE-125
Out-of-bounds Read
|
CVE-2026-48566
|
2026-06-11 02:19 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
886
|
7.9 |
HIGH
Local
|
microsoft
|
windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2012 windows_server_2016 w…
|
Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.
New
|
CWE-693
Protection Mechanism Failure
|
CVE-2026-48568
|
2026-06-11 02:18 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
887
|
7.9 |
HIGH
Local
|
microsoft
|
windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2012 windows_server_2016 w…
|
Protection mechanism failure in Windows Secure Boot allows an authorized attacker to bypass a security feature locally.
New
|
CWE-693
Protection Mechanism Failure
|
CVE-2026-48570
|
2026-06-11 02:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
888
|
5.4 |
MEDIUM
Network
|
-
|
-
|
Umbraco is an ASP.NET CMS. Prior to versions 13.14.0 and 17.4.0, some of the Surface Controllers in the CMS provide to support member related operations fail to validate redirect URLs, making Razor t…
New
|
CWE-601
Open Redirect
|
CVE-2026-46616
|
2026-06-11 02:16 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
889
|
4.6 |
MEDIUM
Network
|
-
|
-
|
Umbraco is an ASP.NET CMS. From version 14.0.0 to before version 17.4.0, authenticated users are able to inject HTML into an input field, which is rendered in the confirmation dialog without proper o…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-46609
|
2026-06-11 02:16 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
890
|
8.3 |
HIGH
Network
|
-
|
-
|
Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, there is an authentication bypass vulnerability via 'api' substring in URL + unau…
New
|
CWE-287 CWE-306 CWE-697
Improper Authentication Missing Authentication for Critical Function Incorrect Comparison
|
CVE-2026-45567
|
2026-06-11 02:16 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|