|
161
|
7.8 |
HIGH
Local
|
microsoft
|
windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2012 windows_server_2016 w…
|
Improper link resolution before file access ('link following') in Winlogon allows an authorized attacker to elevate privileges locally.
New
|
CWE-59
Link Following
|
CVE-2026-42989
|
2026-06-12 00:45 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
162
|
7.8 |
HIGH
Local
|
microsoft
|
windows_10_1809 windows_10_21h2 windows_10_22h2 windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2019 windows_server_2022 windows_server_2025
|
Concurrent execution using shared resource with improper synchronization ('race condition') in Windows Push Notifications allows an authorized attacker to elevate privileges locally.
New
|
CWE-362 CWE-416
Race Condition Use After Free
|
CVE-2026-42991
|
2026-06-12 00:43 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
163
|
5.3 |
MEDIUM
Network
|
vmware
|
spring_framework
|
A vulnerability in Spring Expression Language (SpEL) evaluation logic allows for arbitrary zero-argument method invocation, even within restricted or read-only contexts, which may allow an attacker t…
New
|
CWE-863
Incorrect Authorization
|
CVE-2026-41852
|
2026-06-12 00:43 |
2026-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
164
|
7.5 |
HIGH
Network
|
-
|
-
|
TDengine is an open source, time-series database optimized for Internet of Things devices. In versions 3.4.0.0 through 3.4.1.5, an unauthenticated remote attacker can crash the taosd server process b…
New
|
CWE-191
Integer Underflow (Wrap or Wraparound)
|
CVE-2026-42542
|
2026-06-12 00:37 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
165
|
7.5 |
HIGH
Network
|
-
|
-
|
vLLM versions 0.8.0 and later are vulnerable to an Out-of-Memory (OOM) Denial of Service (DoS) attack due to unbounded frame count processing in the `VideoMediaIO.load_base64()` method. When processi…
New
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2026-5497
|
2026-06-12 00:37 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
166
|
8.4 |
HIGH
Local
|
microsoft
|
365_apps microsoft_365 office_2019 office_2021 office_2024 sharepoint_server word
|
Access of resource using incompatible type ('type confusion') in Microsoft Office allows an unauthorized attacker to execute code locally.
New
|
CWE-416
Use After Free
|
CVE-2026-45458
|
2026-06-12 00:37 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
167
|
- |
|
-
|
-
|
Plonky3 is a toolkit for polynomial IOPs (PIOPs). Prior to versions 0.4.3 and 0.5.3, an attacker controlling prover-side observations can craft distinct transcripts that produce identical challenges,…
New
|
CWE-345 CWE-1240
Insufficient Verification of Data Authenticity Use of a Cryptographic Primitive with a Risky Implementation
|
CVE-2026-46654
|
2026-06-12 00:36 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
168
|
- |
|
-
|
-
|
Kanidm is an identity management platform. Prior to version 1.9.3, a single unauthenticated GET to any /scim/v1/... endpoint with a ?filter= query string of a few thousand nested parentheses (≈ 4–12 …
New
|
CWE-248 CWE-400 CWE-674
Uncaught Exception Uncontrolled Resource Consumption Uncontrolled Recursion
|
CVE-2026-46689
|
2026-06-12 00:36 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
169
|
5.4 |
MEDIUM
Network
|
apache
|
answer
|
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in Apache Answer.
This issue affects Apache Answer: through 2.0.0.
User-supplied content was included in …
New
|
CWE-80 CWE-79
Basic XSS Cross-site Scripting
|
CVE-2026-34033
|
2026-06-12 00:35 |
2026-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
170
|
- |
|
-
|
-
|
SpiceDB is an open source database system for creating and managing security-critical application permissions. From version 1.15.0 to before version 1.52.0, caveat structures with nested lists can re…
New
|
CWE-285
Improper Authorization
|
CVE-2026-46668
|
2026-06-12 00:35 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|