|
171
|
- |
|
-
|
-
|
Allocation of Resources Without Limits or Throttling vulnerability in membraneframework membrane_mp4_plugin allows unauthenticated denial-of-service via BEAM atom table exhaustion.
The MP4 box heade…
New
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2026-53423
|
2026-06-12 00:35 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
172
|
7.0 |
HIGH
Local
|
microsoft
|
windows_10_21h2 windows_10_22h2 windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2022 windows_server_2025
|
Time-of-check time-of-use (TOCTOU) race condition in Program Compatibility Assistant Service allows an authorized attacker to elevate privileges locally.
New
|
CWE-367
Time-of-check Time-of-use (TOCTOU) Race Condition
|
CVE-2026-45487
|
2026-06-12 00:35 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
173
|
6.1 |
MEDIUM
Local
|
-
|
-
|
bit7z is a cross-platform C++ static library that allows the compression/extraction of archive files. Prior to version 4.0.12, there is an arbitrary file overwrite vulnerability via symlink attack on…
New
|
CWE-59 CWE-377
Link Following Insecure Temporary File
|
CVE-2026-45384
|
2026-06-12 00:35 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
174
|
7.8 |
HIGH
Local
|
-
|
-
|
GIMP HDR File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User inte…
New
|
CWE-122
Heap-based Buffer Overflow
|
CVE-2026-2049
|
2026-06-12 00:34 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
175
|
7.0 |
HIGH
Network
|
-
|
-
|
Fedify is a TypeScript library for building federated server apps powered by ActivityPub. Prior to versions 1.9.11, 1.10.10, 2.0.18, 2.1.14, and 2.2.3, an attacker can make use of JSON-LD features to…
New
|
CWE-180 CWE-347 CWE-436 CWE-1289
Incorrect Behavior Order: Validate Before Canonicalize Improper Verification of Cryptographic Signature Interpretation Conflict Improper Validation of Unsafe Equivalence in Input
|
CVE-2026-42462
|
2026-06-12 00:34 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
176
|
- |
|
-
|
-
|
Boruta is a standalone authorization server that aims to implement OAuth 2.0 and Openid Connect up to decentralized identity specifications. Prior to version 0.9.1, boruta session cookies and the ide…
New
|
CWE-614
Sensitive Cookie in HTTPS Session Without 'Secure' Attribute
|
CVE-2026-53661
|
2026-06-12 00:34 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
177
|
5.8 |
MEDIUM
Network
|
-
|
-
|
Guzzle Services provides an implementation of the Guzzle Command library that uses Guzzle service descriptions to describe web services, serialize requests, and parse responses into easy to use model…
New
|
CWE-20 CWE-91
Improper Input Validation Blind XPath Injection
|
CVE-2026-53723
|
2026-06-12 00:34 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
178
|
7.8 |
HIGH
Local
|
microsoft
|
windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2012 windows_server_2016 w…
|
Improper link resolution before file access ('link following') in Windows Collaborative Translation Framework allows an authorized attacker to elevate privileges locally.
New
|
CWE-59
Link Following
|
CVE-2026-45586
|
2026-06-12 00:33 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
179
|
- |
|
-
|
-
|
A HTTP request smuggling and desynchronization vulnerability affects Kong Gateway Enterprise 3.4, 3.10, 3.11, 3.12, 3.13, and 3.14 series. The vulnerability is caused by a parsing flaw in Kong’s HTTP…
New
|
CWE-444
HTTP Request Smuggling
|
CVE-2026-6338
|
2026-06-12 00:32 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
180
|
7.7 |
HIGH
Network
|
-
|
-
|
Sharp is a content management framework built for Laravel as a package. Prior to version 9.22.0, Sharp exposes a generic download endpoint that authorizes access only to the supplied Sharp entity ins…
New
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-44692
|
2026-06-12 00:31 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|