|
241
|
6.1 |
MEDIUM
Local
|
-
|
-
|
Out-of-bounds write vulnerability in Samsung Open Source rlottie allows Overflow Buffers.
This issue affects rlottie: before dcfde72eae1b0464dc0dd760aec00ada6a148635.
New
|
CWE-787
Out-of-bounds Write
|
CVE-2026-8916
|
2026-06-5 00:27 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
242
|
- |
|
-
|
-
|
This vulnerability exists in GX Earth ONT models due to improper handling of user-supplied input in multiple diagnostic functions in its web management interface. An authenticated remote attacker cou…
New
|
CWE-78
OS Command
|
CVE-2026-45431
|
2026-06-5 00:26 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
243
|
- |
|
-
|
-
|
This vulnerability exists in GX Earth ONT models due to the transmission of user credentials in plaintext over HTTP in its web management interface. A remote attacker could exploit this vulnerability…
New
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2026-45432
|
2026-06-5 00:26 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
244
|
- |
|
-
|
-
|
This vulnerability exists in GX Earth 2022 ONT models due to the presence of hardcoded RSA private key within the device firmware. A remote attacker could exploit this vulnerability by extracting the…
New
|
CWE-321
Use of Hard-coded Cryptographic Key
|
CVE-2026-45433
|
2026-06-5 00:26 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245
|
9.1 |
CRITICAL
Network
|
-
|
-
|
A vulnerability in mlflow/mlflow versions prior to 3.11.0 allows for the resolution of environment variables in AI Gateway secrets, which can be exploited to exfiltrate sensitive server-side environm…
New
|
CWE-201
Insertion of Sensitive Information Into Sent Data
|
CVE-2026-4035
|
2026-06-5 00:25 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246
|
6.1 |
MEDIUM
Network
|
-
|
-
|
A vulnerability in jupyter-server versions 1.12.0 through 2.17.0 allows an attacker to bypass CORS origin validation when the `allow_origin_pat` configuration is used. The issue arises from the use o…
New
|
CWE-346
Origin Validation Error
|
CVE-2026-6657
|
2026-06-5 00:25 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247
|
- |
|
-
|
-
|
A local privilege escalation vulnerability exists in Forcepoint VPN Client that allows a local non-administrative user to escalate privileges to SYSTEM. This issue affects VPN Client for Windows: ver…
New
|
CWE-250
Execution with Unnecessary Privileges
|
CVE-2025-12694
|
2026-06-5 00:25 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248
|
8.1 |
HIGH
Network
|
-
|
-
|
HCL Hive Telco Observability is affected by a Required directives missing from the CSP issue is detected in keycloak component of the web application. Missing essential directives can leave a site v…
New
|
CWE-1027
|
CVE-2025-59874
|
2026-06-5 00:25 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249
|
3.3 |
LOW
Local
|
-
|
-
|
The HCL BigFix Cloud Lifecycle Management is affected by Lack Of Input Validation. It may leads to an information exposure vulnerability. This low-level flaw allows unauthorized access.
New
|
-
|
CVE-2025-62338
|
2026-06-5 00:25 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250
|
- |
|
-
|
-
|
An unauthenticated user with write access to the knowledge base can store an XSS payload in a knowledge base item.
This issue affects glpi: before 11.0.7.
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-5385
|
2026-06-5 00:23 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|