|
211
|
7.5 |
HIGH
Network
|
netty
|
netty
|
Netty is a network application framework for development of protocol servers and clients. NoQuicTokenHandler is the tokenHandler used when the application does not set one. Prior to version 4.2.15.Fi…
New
|
CWE-940
Improper Verification of Source of a Communication Channel
|
CVE-2026-44894
|
2026-06-15 11:23 |
2026-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
212
|
4.3 |
MEDIUM
Network
|
-
|
-
|
A security flaw has been discovered in medkey-org medkey up to fc09b7ba9441ff590b72d428d5380834216b09ed. Impacted is the function actionGetPatientById of the file app\modules\medical\port\rest\contro…
New
|
CWE-99
Resource Injection
|
CVE-2026-12207
|
2026-06-15 11:16 |
2026-06-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
213
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was identified in Grit42 Grit up to 0.11.0. This issue affects the function Grit::Assays::DataTableEntity of the file modules/assays/backend/app/models/grit/assays/data_table_entity.r…
New
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-12206
|
2026-06-15 11:16 |
2026-06-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
214
|
7.3 |
HIGH
Network
|
-
|
-
|
A vulnerability was determined in ShopXO up to 6.7.1. This vulnerability affects the function OrderClose/OrderSuccess/PayLogOrderClose/GoodsGiveIntegral of the file app/api/controller/Crontab.php of …
New
|
CWE-285 CWE-639
Improper Authorization Authorization Bypass Through User-Controlled Key
|
CVE-2026-12204
|
2026-06-15 11:16 |
2026-06-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
215
|
5.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was found in HKUDS AI-Trader up to 74caf996f78dcc0c657df8365c8544678a16e215. This affects an unknown part of the file /api/research/agents.csv of the component Research Export. Perfor…
New
|
CWE-200 CWE-284
Information Exposure Improper Access Control
|
CVE-2026-12203
|
2026-06-15 11:16 |
2026-06-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
216
|
2.4 |
LOW
Network
|
-
|
-
|
A vulnerability has been found in Intelliants Subrion CMS up to 4.0.3. Affected by this issue is some unknown functionality of the component Blocks Endpoint. Such manipulation of the argument CSS cla…
New
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-12202
|
2026-06-15 11:16 |
2026-06-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
217
|
7.5 |
HIGH
Network
|
netty
|
netty
|
Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, SslClientHelloHandler.decode() reads the 24-bit TLS handsha…
New
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2026-45416
|
2026-06-15 11:15 |
2026-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
218
|
4.0 |
MEDIUM
Local
|
netty
|
netty
|
Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, netty_unix_socket_recvFd sets msg_control to `char control[…
New
|
CWE-200 CWE-772
Information Exposure Missing Release of Resource after Effective Lifetime
|
CVE-2026-45536
|
2026-06-15 11:14 |
2026-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
219
|
6.8 |
MEDIUM
Network
|
netty
|
netty
|
Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, Netty's DNS resolver uses a predictable PRNG for generating…
New
|
CWE-330 CWE-340
Use of Insufficiently Random Values Generation of Predictable Numbers or Identifiers
|
CVE-2026-45673
|
2026-06-15 11:14 |
2026-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
220
|
10.0 |
CRITICAL
Network
|
netty
|
netty
|
Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, Netty's DnsResolveContext fails to validate the origin (bai…
New
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2026-45674
|
2026-06-15 11:13 |
2026-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|