|
1131
|
- |
|
-
|
-
|
The Electron preload script in Logseq exposes an API method that allows the renderer process to invoke IPC handlers without proper path validation. An attacker with JavaScript execution in the render…
New
|
CWE-749
Exposed Dangerous Method or Function
|
CVE-2026-47899
|
2026-06-9 23:47 |
2026-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1132
|
- |
|
-
|
-
|
Logseq is vulnerable to a stored cross-site scripting (XSS). A malicious plugin can include a JavaScript payload in the "name" field of its "package.json" file, which is rendered using "innerHTML" wi…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-47900
|
2026-06-9 23:47 |
2026-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1133
|
- |
|
-
|
-
|
Logseq is vulnerable to a sandbox escape flaw where plugins running in sandboxed iframes can inject arbitrary HTML attributes, such as event handlers, into their container element in the host DOM. Du…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-47901
|
2026-06-9 23:47 |
2026-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1134
|
- |
|
-
|
-
|
Uncontrolled Resource Consumption vulnerability in the Elixir standard library's Version module allows an attacker who controls a version string to cause a denial of service through CPU and memory ex…
New
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2026-49762
|
2026-06-9 23:47 |
2026-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1135
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Netcad Software Inc. E-İmar allows SQL Injection.
This issue affects E-İmar: from 2.10.1.0 befor…
New
|
CWE-89
SQL Injection
|
CVE-2026-7486
|
2026-06-9 23:47 |
2026-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1136
|
- |
|
-
|
-
|
Logseq exposes an IPC handler that allows the renderer process to execute shell commands. While an allowlist restricts the command name (e.g. `git`, `pandoc`, `grep`), the argument string is concaten…
New
|
CWE-78
OS Command
|
CVE-2026-9279
|
2026-06-9 23:47 |
2026-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1137
|
8.8 |
HIGH
Network
|
google
|
chrome
|
Use after free in File Input in Google Chrome prior to 149.0.7827.103 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: Critical)
New
|
CWE-416
Use After Free
|
CVE-2026-11630
|
2026-06-9 23:47 |
2026-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1138
|
8.3 |
HIGH
Network
|
google
|
chrome
|
Use after free in Aura in Google Chrome on Windows prior to 149.0.7827.103 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTM…
New
|
CWE-416
Use After Free
|
CVE-2026-11631
|
2026-06-9 23:45 |
2026-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1139
|
4.3 |
MEDIUM
Network
|
-
|
-
|
A flaw was found in 389 Directory Server. A type confusion in the SSO token extended operation handler causes partial stack address information to be disclosed in LDAP responses to authenticated user…
New
|
CWE-843
Type Confusion
|
CVE-2026-11785
|
2026-06-9 23:42 |
2026-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1140
|
1.9 |
LOW
Local
|
-
|
-
|
A flaw was found in 389 Directory Server. The LDIF parser reads past the end of a heap buffer when processing attribute types with trailing semicolons during database import, causing an out-of-bounds…
New
|
CWE-125
Out-of-bounds Read
|
CVE-2026-11786
|
2026-06-9 23:42 |
2026-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|