|
951
|
9.1 |
CRITICAL
Network
|
-
|
-
|
A flaw was found in migration-planner. An authenticated user can exploit this vulnerability by sending a DELETE request to the /api/v1/sources route, which lacks proper authorization and filtering. T…
New
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2026-53469
|
2026-06-11 00:16 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
952
|
9.9 |
CRITICAL
Network
|
-
|
-
|
Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, the install blueprint declares only bp.before_request → @jwt_required() (app/rout…
New
|
CWE-639 CWE-862 CWE-863
Authorization Bypass Through User-Controlled Key Missing Authorization Incorrect Authorization
|
CVE-2026-45552
|
2026-06-11 00:16 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
953
|
8.8 |
HIGH
Network
|
-
|
-
|
Issue summary: A specially crafted PKCS#7 or S/MIME signed message could
trigger a use-after-free during PKCS#7 signature verification.
Impact summary: A use-after-free may result in process crashes…
Update
|
CWE-416
Use After Free
|
CVE-2026-45447
|
2026-06-11 00:16 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
954
|
9.8 |
CRITICAL
Network
|
-
|
-
|
DedeCMS V5.7.118 is vulnerable to Command Execution in file_manage_control.php.
Update
|
CWE-78
OS Command
|
CVE-2026-38615
|
2026-06-11 00:16 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
955
|
9.8 |
CRITICAL
Network
|
-
|
-
|
A lack of cryptographic signature verification in the validateAccessToken function of bookcars v8.3 allows attackers to bypass authentication via a forged JWT token.
New
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2026-36721
|
2026-06-11 00:16 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
956
|
7.5 |
HIGH
Network
|
-
|
-
|
An information disclosure vulnerability in the /api/v1/user/info endpoint of AgentChat v2.3.0 allows unauthenticated attackers to obtain sensitive information, including SHA256 password hashes, via e…
New
|
CWE-200
Information Exposure
|
CVE-2026-36719
|
2026-06-11 00:16 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
957
|
8.4 |
HIGH
Local
|
-
|
-
|
Slate Digital Connect 1.37.0 for macOS installs a privileged helper tool, com.slatedigital.connect.privileged.helper.tool, which exposes the XPC service com.slatedigital.connect.privileged.helper.too…
New
|
CWE-367
Time-of-check Time-of-use (TOCTOU) Race Condition
|
CVE-2026-24067
|
2026-06-11 00:16 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
958
|
8.4 |
HIGH
Local
|
-
|
-
|
Slate Digital Connect 1.37.0 for macOS installs a privileged helper tool, com.slatedigital.connect.privileged.helper.tool, which exposes the XPC service com.slatedigital.connect.privileged.helper.too…
New
|
CWE-296
Improper Following of a Certificate's Chain of Trust
|
CVE-2026-24066
|
2026-06-11 00:16 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
959
|
7.8 |
HIGH
Local
|
-
|
-
|
Waves Central for macOS versions 13.0.9 through 16.5.5 contain a local privilege escalation vulnerability. A trusted XPC client component included with the product is signed with hardened runtime ent…
Update
|
CWE-426
Untrusted Search Path
|
CVE-2026-24064
|
2026-06-11 00:16 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
960
|
6.5 |
MEDIUM
Network
|
-
|
-
|
A heap buffer overflow flaw was found in 389 Directory Server. When serializing objectclass definitions, the oc_superior (SUP) field length is omitted from buffer size calculations in read_schema_dse…
New
|
CWE-122
Heap-based Buffer Overflow
|
CVE-2026-11884
|
2026-06-11 00:16 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|