|
521
|
6.5 |
MEDIUM
Network
|
gitlawb
|
openclaude
|
OpenClaude is an open-source coding-agent command line interface for cloud and local model providers. Prior to version 0.5.1, the OpenClaude MCP authentication flow starts a temporary local HTTP serv…
New
|
CWE-352 CWE-400
Origin Validation Error Uncontrolled Resource Consumption
|
CVE-2026-42073
|
2026-06-4 01:54 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
522
|
5.4 |
MEDIUM
Network
|
shopify
|
react-router
|
React Router is a router for React. In versions 7.5.1 through 7.13.1, when using Framework Mode with pre-rendering enabled, improper neutralization of the HTTP `Location` header value can permit Cros…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-33244
|
2026-06-4 01:54 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
523
|
5.3 |
MEDIUM
Network
|
oracle
|
rest_data_services
|
Vulnerability in Oracle REST Data Services (component: Core). Supported versions that are affected are 24.2.0-26.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network ac…
Update
|
CWE-284
Improper Access Control
|
CVE-2026-46842
|
2026-06-4 01:53 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
524
|
7.5 |
HIGH
Network
|
opentelemetry
|
ebpf_instrumentation
|
OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. From version 0.7.0 to before version 0.9.0, a remotely reachable integer overflow in OBI's memcac…
New
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2026-45686
|
2026-06-4 01:52 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
525
|
7.5 |
HIGH
Network
|
opentelemetry
|
ebpf_instrumentation
|
OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. From version 0.1.0 to before version 0.9.0, malformed MongoDB wire messages can trigger uncaught …
New
|
CWE-20 CWE-248 CWE-704
Improper Input Validation Uncaught Exception Incorrect Type Conversion or Cast
|
CVE-2026-45685
|
2026-06-4 01:52 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
526
|
5.3 |
MEDIUM
Network
|
oracle
|
rest_data_services
|
Vulnerability in Oracle REST Data Services (component: Core). Supported versions that are affected are 24.2.0-26.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network ac…
Update
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2026-46843
|
2026-06-4 01:52 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
527
|
5.3 |
MEDIUM
Local
|
opentelemetry
|
ebpf_instrumentation
|
OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. From version 0.7.0 to before version 0.9.0, OBI's log enricher mishandles writev buffers by readi…
New
|
CWE-126 CWE-787
Buffer Over-read Out-of-bounds Write
|
CVE-2026-45684
|
2026-06-4 01:52 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
528
|
3.8 |
LOW
Local
|
opentelemetry
|
ebpf_instrumentation
|
OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0.9.0, the Java TLS ioctl probe reads user-controlled ioctl pointers with bpf_pr…
New
|
CWE-127 CWE-200
Buffer Under-read Information Exposure
|
CVE-2026-45683
|
2026-06-4 01:52 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
529
|
5.9 |
MEDIUM
Network
|
opentelemetry
|
ebpf_instrumentation
|
OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0.9.0, the per-CPU message-buffer fallback path uses a 256-byte backup buffer bu…
New
|
CWE-125 CWE-130
Out-of-bounds Read Improper Handling of Length Parameter Inconsistency
|
CVE-2026-45681
|
2026-06-4 01:52 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
530
|
5.5 |
MEDIUM
Local
|
opentelemetry
|
ebpf_instrumentation
|
OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. Prior to version 0.9.0, the custom CappedConcurrentHashMap introduced for Java TLS state tracking…
New
|
CWE-401 CWE-770
Missing Release of Memory after Effective Lifetime Allocation of Resources Without Limits or Throttling
|
CVE-2026-45682
|
2026-06-4 01:51 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|