|
421
|
5.4 |
MEDIUM
Adjacent
|
-
|
-
|
Danelec MacGregor Voyage Data Recorder
passwords are stored with a hashing method which limits password length and is susceptible to brute force attacks.
New
|
CWE-916
Use of Password Hash With Insufficient Computational Effort
|
CVE-2026-44611
|
2026-06-2 02:07 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
422
|
4.3 |
MEDIUM
Adjacent
|
-
|
-
|
Kernel software installed and running inside a Guest/Host VM may post improper commands to the GPU Firmware to trigger a write of data outside the intended GPU memory.
A logic error in the address…
New
|
CWE-823
Use of Out-of-range Pointer Offset
|
CVE-2026-34193
|
2026-06-2 02:07 |
2026-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
423
|
- |
|
-
|
-
|
In certain scenarios when the admin has enabled Interactive Connectivity Establishment (ICE), a buffer overflow could enable
remote code execution on Poly Voice products on the Linux p…
New
|
CWE-121
Stack-based Buffer Overflow
|
CVE-2026-0826
|
2026-06-2 02:07 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
424
|
4.3 |
MEDIUM
Network
|
apache
|
activemq activemq_broker
|
Incomplete authorization by Apache ActiveMQ server before versions v6.2.6 and v5.19.7 allows authenticated connections to remove existing destinations with proper permissions.
This issue affects Apa…
New
|
CWE-285
Improper Authorization
|
CVE-2026-46605
|
2026-06-2 02:07 |
2026-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
425
|
7.5 |
HIGH
Network
|
-
|
-
|
CORS misconfiguration in the REST API of Network Optix Nx Witness VMS before version 6.1.2, when running in the default Standard security mode, on Linux and Windows allows an unauthenticated remote a…
New
|
CWE-942
Permissive Cross-domain Policy with Untrusted Domains
|
CVE-2026-10056
|
2026-06-2 02:06 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
426
|
9.1 |
CRITICAL
Network
|
-
|
-
|
There is an authentication bypass vulnerability in the NI SystemLink Enterprise Dashboard application that may allow an unauthenticated remote attacker to bypass authentication controls leading to pr…
New
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2026-9051
|
2026-06-2 02:06 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
427
|
5.4 |
MEDIUM
Network
|
-
|
-
|
Firefox for iOS Reader View replaced page content in its HTML template before replacing other internal placeholders. A malicious page could include a placeholder string that was later substituted wit…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-9308
|
2026-06-2 02:06 |
2026-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
428
|
5.4 |
MEDIUM
Network
|
-
|
-
|
Firefox for iOS Reader View did not properly escape HTML tags in JSON-LD metadata. A malicious page could inject markup that changed Reader View behavior and leaked sensitive URL parameters. These pa…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-9309
|
2026-06-2 02:06 |
2026-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
429
|
3.1 |
LOW
Network
|
apache
|
airflow
|
The structure_data endpoint in the Airflow UI returned external dependency graph nodes for linked Dags without checking whether the caller had read permission on those linked Dags. An authenticated U…
New
|
CWE-285
Improper Authorization
|
CVE-2026-40963
|
2026-06-2 02:06 |
2026-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
430
|
6.1 |
MEDIUM
Network
|
apache
|
activemq activemq_web
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache ActiveMQ, Apache ActiveMQ Web.
The MessageServlet in the ActiveMQ web console API copies …
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-42253
|
2026-06-2 02:06 |
2026-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|