|
101
|
6.5 |
MEDIUM
Network
|
-
|
-
|
A bug in Apache Airflow's auth manager logout handling left previously-issued JWT tokens valid after the user clicked logout in the UI: the logout flow for `FabAuthManager` and `KeycloakAuthManager` …
New
|
CWE-613
Insufficient Session Expiration
|
CVE-2026-48726
|
2026-06-3 02:16 |
2026-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
102
|
4.2 |
MEDIUM
Network
|
pyjwt_project
|
pyjwt
|
PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, PyJWKClient passes its uri argument directly to urllib.request.urlopen() which uses Python stdlib's default OpenerDirector registe…
Update
|
CWE-441 CWE-918
Confused Deputy Server-Side Request Forgery (SSRF)
|
CVE-2026-48522
|
2026-06-3 02:16 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
103
|
8.5 |
HIGH
Network
|
oracle
|
financials_common_modules
|
Vulnerability in the Oracle Financials Common Modules product of Oracle E-Business Suite (component: Common Components). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable v…
Update
|
NVD-CWE-noinfo CWE-284
Improper Access Control
|
CVE-2026-46820
|
2026-06-3 02:16 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
104
|
4.3 |
MEDIUM
Network
|
apache
|
airflow
|
The Event Log detail endpoint `GET /api/v2/eventLogs/{event_log_id}` in Apache Airflow fetched audit-log rows directly by numeric ID after only the generic Audit Log permission check, while the colle…
New
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-46764
|
2026-06-3 02:16 |
2026-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
105
|
8.8 |
HIGH
Network
|
-
|
-
|
Microsoft UFO open-source framework for intelligent automation across devices and platforms. In 3.0.1-4-ge2626659, Microsoft UFO's WebSocket control plane trusts client-supplied identity and role fie…
Update
|
CWE-290 CWE-639 CWE-862
Authentication Bypass by Spoofing Authorization Bypass Through User-Controlled Key Missing Authorization
|
CVE-2026-46414
|
2026-06-3 02:16 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
106
|
7.5 |
HIGH
Network
|
-
|
-
|
OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. From version 0.1.0 to before version 0.9.0, malformed MongoDB wire messages can trigger uncaught …
New
|
CWE-20 CWE-248 CWE-704
Improper Input Validation Uncaught Exception Incorrect Type Conversion or Cast
|
CVE-2026-45685
|
2026-06-3 02:16 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
107
|
4.9 |
MEDIUM
Local
|
-
|
-
|
OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. From version 0.7.0 to before version 0.9.0, OBI's log enricher mishandles writev buffers by readi…
New
|
CWE-126 CWE-787
Buffer Over-read Out-of-bounds Write
|
CVE-2026-45684
|
2026-06-3 02:16 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
108
|
6.5 |
MEDIUM
Network
|
-
|
-
|
OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0.9.0, OBI exports raw Redis error text as the span status message. Because Redi…
New
|
CWE-117 CWE-532
Improper Output Neutralization for Logs Inclusion of Sensitive Information in Log Files
|
CVE-2026-45679
|
2026-06-3 02:16 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
109
|
7.5 |
HIGH
Network
|
-
|
-
|
OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0.9.0, the Postgres protocol parser assumes BIND message payloads contain a vali…
New
|
CWE-20 CWE-754
Improper Input Validation Improper Check for Unusual or Exceptional Conditions
|
CVE-2026-45678
|
2026-06-3 02:16 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
110
|
9.9 |
CRITICAL
Network
|
-
|
-
|
Dokploy is a free, self-hostable Platform as a Service (PaaS). In 0.26.7 and earlier, the schedule router does not enforce organization/role checks. As a result, any authenticated user can create, up…
Update
|
CWE-78 CWE-269 CWE-862
OS Command Improper Privilege Management Missing Authorization
|
CVE-2026-45632
|
2026-06-3 02:16 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|