|
101
|
7.4 |
HIGH
Network
|
adobe
|
coldfusion
|
ColdFusion versions 2023.19, 2025.8 and earlier are affected by an Improper Restriction of XML External Entity Reference ('XXE') vulnerability that could lead to arbitrary file system read. An attack…
Update
|
CWE-611
XXE
|
CVE-2026-47960
|
2026-06-16 00:09 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
102
|
5.5 |
MEDIUM
Local
|
adobe
|
c2pa c2pa-web
|
CAI Content Credentials versions c2pa-web@0.7.1, c2pa-v0.80.1 and earlier are affected by an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability that could re…
Update
|
CWE-22
Path Traversal
|
CVE-2026-34657
|
2026-06-16 00:08 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
103
|
7.5 |
HIGH
Network
|
adobe
|
c2pa c2pa-web
|
CAI Content Credentials versions c2pa-web@0.7.1, c2pa-v0.80.1 and earlier are affected by an Integer Overflow or Wraparound vulnerability. An attacker could exploit this vulnerability to crash the ap…
Update
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2026-34711
|
2026-06-16 00:07 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
104
|
5.7 |
MEDIUM
Network
|
splunk
|
splunk splunk_cloud_platform
|
In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, and Splunk Cloud Platform versions below 10.3.2512.13, 10.2.2510.15, 10.1.2507.23, and 9.3.2411.132, a low-privileged user that…
Update
|
CWE-20
Improper Input Validation
|
CVE-2026-20254
|
2026-06-16 00:05 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
105
|
5.7 |
MEDIUM
Network
|
splunk
|
splunk splunk_cloud_platform
|
In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, and Splunk Cloud Platform versions below 10.3.2512.13, 10.2.2510.15, 10.1.2507.23, and 9.3.2411.132, a low-privileged user that…
Update
|
CWE-20
Improper Input Validation
|
CVE-2026-20255
|
2026-06-16 00:04 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
106
|
5.3 |
MEDIUM
Network
|
guzzlephp
|
psr-7
|
guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Versions prior to 2.10.2 contain improper Host header validation when parsing raw HTTP request messages and when deriving a serv…
Update
|
CWE-20 CWE-918
Improper Input Validation Server-Side Request Forgery (SSRF)
|
CVE-2026-48998
|
2026-06-15 23:52 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
107
|
5.3 |
MEDIUM
Network
|
guzzlephp
|
psr-7
|
guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Versions prior to 2.10.2 did not reject ASCII control characters, whitespace, or DEL in first-party URI host components. A vulne…
Update
|
CWE-20 CWE-93 CWE-113
Improper Input Validation CRLF Injection HTTP Response Splitting
|
CVE-2026-49214
|
2026-06-15 23:41 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
108
|
5.7 |
MEDIUM
Network
|
splunk
|
splunk splunk_cloud_platform
|
In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, and Splunk Cloud Platform versions below 10.3.2512.13, 10.2.2510.15, 10.1.2507.23, and 9.3.2411.132, a low-privileged user that…
Update
|
CWE-20
Improper Input Validation
|
CVE-2026-20256
|
2026-06-15 23:33 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
109
|
5.5 |
MEDIUM
Local
|
apple
|
macos
|
A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.4, macOS Sonoma 14.7.5, macOS Ventura 13.7.5. An app may be able to cause unexpected system ter…
New
|
CWE-284
Improper Access Control
|
CVE-2025-24165
|
2026-06-15 23:26 |
2026-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
110
|
5.5 |
MEDIUM
Local
|
apple
|
macos
|
This issue was addressed with improved handling of symlinks. This issue is fixed in macOS Sequoia 15.4. An app may be able to access protected user data.
New
|
CWE-61
UNIX Symbolic Link (Symlink) Following
|
CVE-2025-43278
|
2026-06-15 23:25 |
2026-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|