|
1841
|
4.8 |
MEDIUM
Physics
|
-
|
-
|
capacitor-native-biometric before 12.128.2 contains an authentication bypass vulnerability where the onAuthenticationSucceeded() method fails to validate CryptoObject parameters. Attackers can hook t…
|
CWE-287
Improper Authentication
|
CVE-2026-56294
|
2026-06-23 06:14 |
2026-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1842
|
- |
|
-
|
-
|
In affected versions of Octopus Server with certain access levels it was possible to embed a Cross-Site Scripting Payload via artifacts.
|
CWE-79
Cross-site Scripting
|
CVE-2026-8296
|
2026-06-23 05:44 |
2026-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1843
|
- |
|
-
|
-
|
Liquidfiles versions before 4.2.12 are affected by a broken access control vulnerability resulting in privilege escalation from an Admin in a secondary domain to a Sysadmin by modifying a group in th…
|
CWE-285
Improper Authorization
|
CVE-2026-12673
|
2026-06-23 05:44 |
2026-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1844
|
9.1 |
CRITICAL
Network
|
-
|
-
|
Microsoft HEIF Image Extensions 1.2.22.0 has an out-of-bounds read because CHEIFItemInfoEntry_GetDataSize can return success while leaving the reported data size as 0. This causes a caller to make a …
|
CWE-125
Out-of-bounds Read
|
CVE-2025-62821
|
2026-06-23 05:44 |
2026-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1845
|
7.5 |
HIGH
Network
|
-
|
-
|
GitHub Copilot 1.372.0 allows filesystem access outside of a workspace folder (without user approval) via a file-handler URI parameter to fetch_webpage. Therefore, exfiltration could occur if there i…
|
CWE-552
Files or Directories Accessible to External Parties
|
CVE-2025-66389
|
2026-06-23 05:44 |
2026-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1846
|
3.7 |
LOW
Network
|
-
|
-
|
GNU Savannah Administration Savane through 3.17 uses untrusted data as part of authorization.
|
CWE-696
Incorrect Behavior Order
|
CVE-2026-56355
|
2026-06-23 05:43 |
2026-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1847
|
6.3 |
MEDIUM
Local
|
-
|
-
|
The compose-rich-editor library (v1.0.0-rc14) used in HCL Verse for Android's rich text email composition fails to properly validate all HTML input thereby allowing malicious content to be executed i…
|
CWE-20 CWE-79
Improper Input Validation Cross-site Scripting
|
CVE-2026-21768
|
2026-06-23 05:42 |
2026-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1848
|
9.9 |
CRITICAL
Network
|
-
|
-
|
Prefect version 3.6.23 is vulnerable to remote code execution due to improper handling of user-controlled input in the `GitRepository` storage class. The `commit_sha` parameter, which is passed to gi…
|
CWE-94
Code Injection
|
CVE-2026-5366
|
2026-06-23 05:41 |
2026-06-21 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1849
|
7.7 |
HIGH
Local
|
-
|
-
|
Software installed and run as a non-privileged user may conduct improper GPU system calls to cause an error path leading to UAF of GPU page tables.
The vulnerability allows physical memory allocat…
|
CWE-416
Use After Free
|
CVE-2026-34192
|
2026-06-23 05:40 |
2026-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1850
|
7.7 |
HIGH
Local
|
-
|
-
|
Software installed and run as a non-privileged user may conduct improper GPU system calls to cause mismanagement of resources creating a write use after free scenario.
A shared resource (memory pa…
|
CWE-416
Use After Free
|
CVE-2026-41156
|
2026-06-23 05:40 |
2026-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|