|
251
|
8.7 |
HIGH
Network
|
axios
|
axios
|
Axios is a promise based HTTP client for the browser and Node.js. From 1.0.0 to before 1.16.0, the Axios library is vulnerable to a Prototype Pollution "Gadget" attack that allows any Object.prototyp…
New
|
CWE-441 CWE-1321
Confused Deputy Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
|
CVE-2026-44494
|
2026-06-13 03:01 |
2026-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
252
|
7.5 |
HIGH
Network
|
axios
|
axios
|
Axios is a promise based HTTP client for the browser and Node.js. Axios versions before 0.32.0 on the 0.x line and before 1.16.0 on the 1.x line build a regular expression from the configured XSRF co…
New
|
CWE-400 CWE-1333
Uncontrolled Resource Consumption Inefficient Regular Expression Complexity
|
CVE-2026-44496
|
2026-06-13 03:00 |
2026-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
253
|
8.3 |
HIGH
Network
|
google
|
chrome
|
Insufficient validation of untrusted input in Linux Toolkit Theming in Google Chrome on Linux prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to potentially…
New
|
CWE-20
Improper Input Validation
|
CVE-2026-12034
|
2026-06-13 02:58 |
2026-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
254
|
8.8 |
HIGH
Network
|
google
|
chrome
|
Use after free in Views in Google Chrome on Windows prior to 149.0.7827.115 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)
New
|
CWE-416
Use After Free
|
CVE-2026-12035
|
2026-06-13 02:58 |
2026-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
255
|
6.5 |
MEDIUM
Network
|
devolutions
|
devolutions_server
|
Improper access control in the ticketing integration settings in Devolutions Server allows an authenticated low-privileged user to obtain cleartext credentials for configured ticketing integrations v…
Update
|
CWE-312
Cleartext Storage of Sensitive Information
|
CVE-2026-10786
|
2026-06-13 02:56 |
2026-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
256
|
4.3 |
MEDIUM
Network
|
devolutions
|
devolutions_server
|
Missing authorization in the deleted user groups API in Devolutions Server allows an authenticated low-privileged user to enumerate metadata of deleted user groups via a crafted API request.
This is…
Update
|
CWE-862
Missing Authorization
|
CVE-2026-10787
|
2026-06-13 02:56 |
2026-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
257
|
9.1 |
CRITICAL
Network
|
microsoft
|
windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2012 windows_server_2016 w…
|
No cwe for this issue in Windows DHCP Server allows an unauthorized attacker to perform tampering over a network.
Update
|
CWE-229
Improper Handling of Values
|
CVE-2026-45602
|
2026-06-13 02:56 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
258
|
6.8 |
MEDIUM
Local
|
microsoft
|
windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2012 windows_server_2016 w…
|
Out-of-bounds read in Windows DHCP Server allows an authorized attacker to disclose information locally.
Update
|
CWE-125
Out-of-bounds Read
|
CVE-2026-45608
|
2026-06-13 02:53 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
259
|
8.8 |
HIGH
Network
|
flowiseai
|
flowise
|
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, assistant create and update mass-assignment allows cross-workspace assistant takeover.…
Update
|
CWE-915
Improperly Controlled Modification of Dynamically-Determined Object Attributes
|
CVE-2026-46475
|
2026-06-13 02:47 |
2026-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
260
|
5.5 |
MEDIUM
Local
|
microsoft
|
windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2012 windows_server_2016 w…
|
Out-of-bounds read in Windows DHCP Server allows an authorized attacker to disclose information locally.
Update
|
CWE-125
Out-of-bounds Read
|
CVE-2026-45634
|
2026-06-13 02:46 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|