|
3501
|
7.0 |
HIGH
Network
|
-
|
-
|
Fedify is a TypeScript library for building federated server apps powered by ActivityPub. Prior to versions 1.9.11, 1.10.10, 2.0.18, 2.1.14, and 2.2.3, an attacker can make use of JSON-LD features to…
|
CWE-180 CWE-347 CWE-436 CWE-1289
Incorrect Behavior Order: Validate Before Canonicalize Improper Verification of Cryptographic Signature Interpretation Conflict Improper Validation of Unsafe Equivalence in Input
|
CVE-2026-42462
|
2026-06-12 00:34 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3502
|
- |
|
-
|
-
|
Boruta is a standalone authorization server that aims to implement OAuth 2.0 and Openid Connect up to decentralized identity specifications. Prior to version 0.9.1, boruta session cookies and the ide…
|
CWE-614
Sensitive Cookie in HTTPS Session Without 'Secure' Attribute
|
CVE-2026-53661
|
2026-06-12 00:34 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3503
|
5.8 |
MEDIUM
Network
|
-
|
-
|
Guzzle Services provides an implementation of the Guzzle Command library that uses Guzzle service descriptions to describe web services, serialize requests, and parse responses into easy to use model…
|
CWE-20 CWE-91
Improper Input Validation Blind XPath Injection
|
CVE-2026-53723
|
2026-06-12 00:34 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3504
|
7.8 |
HIGH
Local
|
microsoft
|
windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2012 windows_server_2016 w…
|
Improper link resolution before file access ('link following') in Windows Collaborative Translation Framework allows an authorized attacker to elevate privileges locally.
|
CWE-59
Link Following
|
CVE-2026-45586
|
2026-06-12 00:33 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3505
|
- |
|
-
|
-
|
A HTTP request smuggling and desynchronization vulnerability affects Kong Gateway Enterprise 3.4, 3.10, 3.11, 3.12, 3.13, and 3.14 series. The vulnerability is caused by a parsing flaw in Kong’s HTTP…
|
CWE-444
HTTP Request Smuggling
|
CVE-2026-6338
|
2026-06-12 00:32 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3506
|
7.7 |
HIGH
Network
|
-
|
-
|
Sharp is a content management framework built for Laravel as a package. Prior to version 9.22.0, Sharp exposes a generic download endpoint that authorizes access only to the supplied Sharp entity ins…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-44692
|
2026-06-12 00:31 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3507
|
4.3 |
MEDIUM
Network
|
-
|
-
|
Sharp is a content management framework built for Laravel as a package. From version 9.0.0 to before version 9.22.3, the create and store endpoints of the Quick Creation Command feature did not enfor…
|
CWE-862
Missing Authorization
|
CVE-2026-53634
|
2026-06-12 00:31 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3508
|
4.3 |
MEDIUM
Network
|
-
|
-
|
Yamcs is a mission control framework. Prior to versions 5.13.0 and 5.12.7, an LDAP injection vulnerability exists in `org.yamcs.security.LdapAuthModule` when constructing search filters. The username…
|
CWE-90
LDAP Injection
|
CVE-2026-42568
|
2026-06-12 00:30 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3509
|
7.6 |
HIGH
Network
|
-
|
-
|
Xibo is an open source digital signage platform with a web content management system and Windows display player software. Prior to 4.4.2, a vulnerability chain consisting of Stored XSS and Iframe San…
|
CWE-79 CWE-116 CWE-346
Cross-site Scripting Improper Encoding or Escaping of Output Origin Validation Error
|
CVE-2026-42558
|
2026-06-12 00:30 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3510
|
4.3 |
MEDIUM
Network
|
-
|
-
|
SQLAdmin is a flexible Admin interface for SQLAlchemy models. Prior to version 0.25.1, the ajax_lookup endpoint in application.py bypasses the is_accessible() access control check that all other endp…
|
CWE-862
Missing Authorization
|
CVE-2026-46645
|
2026-06-12 00:30 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|