|
1661
|
- |
|
-
|
-
|
Authelia is an open-source authentication and authorization server providing two-factor authentication and single sign-on (SSO) for applications via a web portal. In versions 4.38.0 through 4.39.19, …
|
CWE-178 CWE-307
Improper Handling of Case Sensitivity mproper Restriction of Excessive Authentication Attempts
|
CVE-2026-47203
|
2026-06-24 01:06 |
2026-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1662
|
- |
|
-
|
-
|
Authelia is an open-source authentication and authorization server providing two-factor authentication and single sign-on (SSO) for applications via a web portal. In versions 4.36.0 through 4.39.19, …
|
CWE-178 CWE-863
Improper Handling of Case Sensitivity Incorrect Authorization
|
CVE-2026-48794
|
2026-06-24 01:06 |
2026-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1663
|
- |
|
-
|
-
|
radvd is a router advertisement daemon for IPv6. Prior to version 2.21, the `radvdump` utility shipped with radvd contains a stack buffer overflow in the Route Information option parser. When process…
|
CWE-121
Stack-based Buffer Overflow
|
CVE-2026-48715
|
2026-06-24 01:04 |
2026-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1664
|
7.5 |
HIGH
Network
|
-
|
-
|
Quarkus is a Java framework for building cloud-native applications. Prior to versions 3.37.0, 3.36.3, 3.33.2.1, 3.33.3, 3.27.4.1, 3.27.5, and 3.20.6.2, Quarkus HTTP path-based authorization policies …
|
CWE-287 CWE-863
Improper Authentication Incorrect Authorization
|
CVE-2026-50559
|
2026-06-24 01:04 |
2026-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1665
|
3.2 |
LOW
Local
|
-
|
-
|
Babel is a compiler for writing next generation JavaScript. Prior to 8.0.0-rc.6 and 7.29.6, @babel/core affected by an arbitrary file read via a sourceMappingURL comment. Using @babel/core to compile…
|
CWE-22 CWE-200
Path Traversal Information Exposure
|
CVE-2026-49356
|
2026-06-24 01:04 |
2026-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1666
|
3.1 |
LOW
Network
|
-
|
-
|
React Router is a router for React. From 7.12.0 until 7.15.1, certain CSRF checks in React Router v7 Framework Mode were insufficient and run on POST requests, but were bypassed on PUT/PATCH/DELETE r…
|
CWE-352
Origin Validation Error
|
CVE-2026-53663
|
2026-06-24 01:04 |
2026-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1667
|
7.1 |
HIGH
Network
|
-
|
-
|
libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.20, a crafted H.265 bitstream can cause an out-of-bounds array write in `decoder_context::process_reference_pi…
|
CWE-787
Out-of-bounds Write
|
CVE-2026-49295
|
2026-06-24 01:00 |
2026-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1668
|
7.1 |
HIGH
Network
|
-
|
-
|
libde265 is an open source implementation of the h.265 video codec. Prior to version 1.1.0, a crafted H.265 bitstream with large SPS dimensions and 16-bit bit depth causes a signed integer overflow i…
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2026-49346
|
2026-06-24 01:00 |
2026-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1669
|
8.7 |
HIGH
Network
|
-
|
-
|
nanobot is a personal AI assistant. In versions 0.1.5.post3 and prior, the WhatsApp bridge in bridge/src/whatsapp.ts constructs a filesystem path using the fileName field from an incoming WhatsApp do…
|
CWE-22
Path Traversal
|
CVE-2026-48716
|
2026-06-24 00:59 |
2026-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1670
|
- |
|
-
|
-
|
OneDev is a Git server with CI/CD, kanban, and packages. In versions 15.0.6 and below, TarUtils.untar() creates symbolic links verbatim from TAR entry getLinkName() without validating whether the tar…
|
CWE-61
UNIX Symbolic Link (Symlink) Following
|
CVE-2026-49248
|
2026-06-24 00:59 |
2026-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|