|
261
|
8.8 |
HIGH
Network
|
freerdp
|
freerdp
|
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, a malicious RDP client can trigger a heap-buffer-overflow write in FreeRDP's server-side clipboard (cliprdr) channel …
New
|
CWE-122
Heap-based Buffer Overflow
|
CVE-2026-44420
|
2026-06-2 02:37 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
262
|
8.8 |
HIGH
Network
|
freerdp
|
freerdp
|
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, a malicious RDP server can trigger a heap-buffer-overflow write in the FreeRDP client by sending crafted RDPGFX PDUs.…
New
|
CWE-122
Heap-based Buffer Overflow
|
CVE-2026-44421
|
2026-06-2 02:35 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
263
|
5.4 |
MEDIUM
Network
|
ibm
|
webmethods_integration_server
|
IBM webMethods Integration (on prem) -Integration Server 10.15 through IS_10.15_Core_Fix2611.1 to IS_11.1_Core_Fix10 IBM webMethods Integration is vulnerable to server-side request forgery (SSRF). Th…
Update
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2025-14290
|
2026-06-2 02:33 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
264
|
7.6 |
HIGH
Network
|
ibm
|
cognos_analytics cognos_transformer
|
IBM Cognos Analytics 11.2.0, 12.0, and 12.1.0 and IBM Cognos Transformer 12.0, 11.2.4, and 12.1.0 is vulnerable to stored cross-site scripting (XSS) in Cognos Adminstration. This vulnerability allows…
Update
|
CWE-79
Cross-site Scripting
|
CVE-2025-36126
|
2026-06-2 02:30 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
265
|
7.4 |
HIGH
Network
|
miniorange
|
saml_sso_-_service_provider
|
Improper Check for Unusual or Exceptional Conditions vulnerability in Drupal SAML SSO - Service Provider allows Privilege Escalation.
This issue affects SAML SSO - Service Provider: from 0.0.0 befor…
New
|
CWE-754
Improper Check for Unusual or Exceptional Conditions
|
CVE-2026-5343
|
2026-06-2 02:29 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
266
|
8.8 |
HIGH
Network
|
freerdp
|
freerdp
|
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, FreeRDP's RDPEAR NDR parser accepts one non-null NDR pointer ref-id for multiple logical pointer fields without track…
New
|
CWE-415 CWE-416
Double Free Use After Free
|
CVE-2026-44422
|
2026-06-2 02:26 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
267
|
5.3 |
MEDIUM
Network
|
ibm
|
watsonx.data
|
IBM watsonx.data 2.2 through 2.3.1 IBM Lakehouse does not properly restrict inbound and outbound connections which could allow an attacker to transfer or modify files without restrictions.
Update
|
CWE-923 NVD-CWE-noinfo
Improper Restriction of Communication Channel to Intended Endpoints
|
CVE-2025-36145
|
2026-06-2 02:24 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
268
|
9.8 |
CRITICAL
Network
|
freerdp
|
freerdp
|
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, FreeRDP's planar bitmap decoder has an out-of-bounds heap write when decoding RLE planar data. In libfreerdp/codec/pl…
New
|
CWE-787
Out-of-bounds Write
|
CVE-2026-45700
|
2026-06-2 02:23 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
269
|
6.1 |
MEDIUM
Network
|
ibm
|
financial_transaction_manager_for_multiplatform
|
IBM Financial Transaction Manager for SWIFT Services for Multiplatforms 3.2.4.0 through 3.2.4.15 IBM Financial Transaction Manager SWIFT is vulnerable to cross-site scripting. This vulnerability allo…
Update
|
CWE-79
Cross-site Scripting
|
CVE-2025-36148
|
2026-06-2 02:22 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
270
|
8.8 |
HIGH
Network
|
google
|
chrome
|
Use after free in WebCodecs in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)
New
|
CWE-416
Use After Free
|
CVE-2026-10013
|
2026-06-2 02:22 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|