|
231
|
7.1 |
HIGH
Local
|
presire
|
qsnapper
|
Incorrect caching of authentication between different polkit methods in qSnapper before version 1.3.3 allowed a local attacker to use functions like "restore from snapshot" even if only allowed to do…
New
|
CWE-303 CWE-863
Incorrect Implementation of Authentication Algorithm Incorrect Authorization
|
CVE-2026-41048
|
2026-06-28 09:06 |
2026-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
232
|
7.1 |
HIGH
Local
|
presire
|
qsnapper
|
Incorrect caching of authentication between different users of the qSnapper dbus service before version 1.3.3 allowed any local attacker to use dbus functions after a privileged users has authentica…
New
|
CWE-303 CWE-863
Incorrect Implementation of Authentication Algorithm Incorrect Authorization
|
CVE-2026-41049
|
2026-06-28 08:59 |
2026-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
233
|
7.5 |
HIGH
Network
|
fasterxml
|
jackson-databind
|
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.13.0 until 2.14.0, a potential Denial-of-Service exists when attacker sends …
New
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2026-50193
|
2026-06-28 06:05 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
234
|
8.1 |
HIGH
Network
|
fasterxml
|
jackson-databind
|
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21.4, and 3.1.4, jackson-databind's PolymorphicTypeVali…
New
|
CWE-184 CWE-502
Incomplete Blacklist Deserialization of Untrusted Data
|
CVE-2026-54512
|
2026-06-28 06:01 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
235
|
8.1 |
HIGH
Network
|
fasterxml
|
jackson-databind
|
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.10.0 until 2.18.8, 2.21.4, and 3.1.4, BasicPolymorphicTypeValidator.Builder.…
New
|
CWE-184
Incomplete Blacklist
|
CVE-2026-54513
|
2026-06-28 06:00 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
236
|
5.3 |
MEDIUM
Network
|
fasterxml
|
jackson-databind
|
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.0.0 until 2.18.8, 2.21.4, and 3.1.4, JDKFromStringDeserializer constructed I…
New
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-54514
|
2026-06-28 05:55 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
237
|
5.3 |
MEDIUM
Network
|
fasterxml
|
jackson-databind
|
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.21.0 until 2.21.4 and 3.1.4, POJOPropertiesCollector._renameProperties() all…
New
|
CWE-915
Improperly Controlled Modification of Dynamically-Determined Object Attributes
|
CVE-2026-54516
|
2026-06-28 05:52 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
238
|
5.3 |
MEDIUM
Network
|
fasterxml
|
jackson-databind
|
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.21.0 until 2.21.4 and 3.1.4, in BeanDeserializer._deserializeUsingPropertyBa…
New
|
CWE-863
Incorrect Authorization
|
CVE-2026-54517
|
2026-06-28 05:51 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
239
|
6.5 |
MEDIUM
Network
|
fasterxml
|
jackson-databind
|
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.21.0 until 2.21.4 and 3.1.4, UnwrappedPropertyHandler.processUnwrappedCreato…
New
|
CWE-863
Incorrect Authorization
|
CVE-2026-54518
|
2026-06-28 05:49 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
240
|
7.5 |
HIGH
Network
|
sentry
|
sentry
|
Sentry is an error tracking and performance monitoring tool. From 24.4.0 until 26.5.2, a Regular Expression Denial of Service (ReDoS) vulnerability exists in Sentry's event ingestion pipeline, where …
New
|
CWE-1333
Inefficient Regular Expression Complexity
|
CVE-2026-52794
|
2026-06-28 05:45 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|