|
241
|
7.5 |
HIGH
Network
|
aquasec
|
trivy
|
Trivy is a security scanner. Prior to 0.71.1, when Trivy downloads an OCI artifact, it uses the org.opencontainers.image.title annotation from the artifact manifest as the destination filename withou…
New
|
CWE-22
Path Traversal
|
CVE-2026-55092
|
2026-06-28 05:45 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
242
|
7.1 |
HIGH
Network
|
bitwarden
|
server
|
Bitwarden Server before 2026.5.0 contains a privilege escalation vulnerability that allows authenticated Custom users with ManageUsers permission to remove Admin accounts from an organization by expl…
New
|
CWE-862
Missing Authorization
|
CVE-2026-57520
|
2026-06-28 05:41 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
243
|
4.3 |
MEDIUM
Network
|
bitwarden
|
server
|
Bitwarden Server before 2026.5.0 contains a broken access control vulnerability that allows any authenticated user to access arbitrary organization billing data by supplying an arbitrary organization…
New
|
CWE-862
Missing Authorization
|
CVE-2026-57521
|
2026-06-28 05:40 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
244
|
5.0 |
MEDIUM
Network
|
bitwarden
|
server
|
Bitwarden Server before 2026.5.0 contains a JSON injection vulnerability in IntegrationTemplateProcessor.ReplaceTokens(), which substitutes user-controlled values into event-integration templates wit…
New
|
CWE-74
Injection
|
CVE-2026-57522
|
2026-06-28 05:39 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
245
|
5.3 |
MEDIUM
Network
|
wolfssl
|
wolfssl
|
Integer underflow in wc_PKCS7_DecryptOri when handling crafted Other Recipient Info, leading to incorrect length handling during decryption.
New
|
CWE-191
Integer Underflow (Wrap or Wraparound)
|
CVE-2026-6678
|
2026-06-28 05:37 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
246
|
7.5 |
HIGH
Network
|
wolfssl
|
wolfssl
|
A heap buffer overflow could occur in the DTLS 1.3 ACK serialization path before the connecting peer is authenticated. The buffer overflow was due to an integer truncation when computing the length o…
New
|
CWE-190 CWE-197 CWE-787
Integer Overflow or Wraparound Numeric Truncation Error Out-of-bounds Write
|
CVE-2026-6679
|
2026-06-28 05:26 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
247
|
7.1 |
HIGH
Local
|
docling
|
docling
|
Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. From 2.45.0 until 2.91.0, the METS-GBS backend's XML parsing and the inp…
New
|
CWE-409 CWE-611 CWE-776
Improper Handling of Highly Compressed Data (Data Amplification) XXE XML Entity Expansion
|
CVE-2026-44018
|
2026-06-28 05:25 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
248
|
7.5 |
HIGH
Network
|
envoyproxy
|
envoy
|
Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.26.0 until 1.35.13, 1.36.9, 1.37.5, and 1.38.3, the envoy.filters.http.grpc_stats filter crashes (null po…
New
|
CWE-476
NULL Pointer Dereference
|
CVE-2026-47204
|
2026-06-28 05:23 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
249
|
6.5 |
MEDIUM
Network
|
envoyproxy
|
envoy
|
Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.34.0 until 1.35.13, 1.36.9, 1.37.5, and 1.38.3, Envoy crashes if an ext_proc server sends a single gRPC m…
New
|
CWE-416
Use After Free
|
CVE-2026-47207
|
2026-06-28 05:20 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
250
|
7.5 |
HIGH
Network
|
envoyproxy
|
envoy
|
Envoy is an open source edge and service proxy designed for cloud-native applications. From 1.18.0 until 1.35.13, 1.36.9, 1.37.5, and 1.38.3, the router filter contains a null pointer dereference vul…
New
|
CWE-476
NULL Pointer Dereference
|
CVE-2026-47221
|
2026-06-28 05:17 |
2026-06-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|