|
1571
|
7.8 |
HIGH
Local
|
-
|
-
|
Missing symlink validation in Language Servers for AWS may allow an arbitrary file write outside of the workspace trust boundary. This may occur when a local user opens a workspace with a maliciously…
|
CWE-61
UNIX Symbolic Link (Symlink) Following
|
CVE-2026-12958
|
2026-06-24 04:36 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1572
|
6.5 |
MEDIUM
Network
|
-
|
-
|
SQL Injection vulnerability in Cboard v.0.4.2 and before allows a remote attacker to execute arbitrary code via the getDimensionsValues component
|
CWE-89
SQL Injection
|
CVE-2026-52673
|
2026-06-24 04:35 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1573
|
- |
|
-
|
-
|
Pega Platform versions 8.3.0 through Infinity 25.1.2 are affected by an authorization weakness that may allow authenticated users to access certain additional data via crafted URLs.
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2025-62180
|
2026-06-24 04:34 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1574
|
5.2 |
MEDIUM
Local
|
-
|
-
|
Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.8.1, when a WebSocket connection was opened, Deno checked the destination hostname against --deny-net rules but did not re-check …
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-49860
|
2026-06-24 04:34 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1575
|
5.2 |
MEDIUM
Local
|
-
|
-
|
Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.8.1, environment access is gated by the env permission. You can deny it with --deny-env, or restrict it to a specific allowlist w…
|
CWE-863
Incorrect Authorization
|
CVE-2026-49983
|
2026-06-24 04:34 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1576
|
4.3 |
MEDIUM
Network
|
-
|
-
|
Deno is a JavaScript, TypeScript, and WebAssembly runtime. Prior to 2.7.5, a Deno program that opens a client WebSocket connection could be crashed by the remote server. While handling the WebSocket …
|
CWE-248
Uncaught Exception
|
CVE-2026-55517
|
2026-06-24 04:34 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1577
|
7.6 |
HIGH
Adjacent
|
-
|
-
|
Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2026.6.0, the Konnected integration registers an HTTP endpoint, KonnectedView (homeassistant…
|
CWE-200 CWE-306
Information Exposure Missing Authentication for Critical Function
|
CVE-2026-54317
|
2026-06-24 04:34 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1578
|
- |
|
-
|
-
|
Claude Code is an agentic coding tool. From 0.2.54 until 2.1.163, because the hostname huggingface.co was pre-approved as a bare hostname for the WebFetch tool, any path on that domain—including att…
|
CWE-183 CWE-200 CWE-515
Permissive List of Allowed Inputs Information Exposure
|
CVE-2026-54316
|
2026-06-24 04:32 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1579
|
7.5 |
HIGH
Network
|
-
|
-
|
An issue in the sqlo_try_in_loop component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.
|
CWE-89
SQL Injection
|
CVE-2025-61024
|
2026-06-24 04:26 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1580
|
7.5 |
HIGH
Network
|
-
|
-
|
An issue in the sqlo_untry component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.
|
CWE-89
SQL Injection
|
CVE-2025-61029
|
2026-06-24 04:26 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|