|
1
|
7.5 |
HIGH
Network
|
-
|
-
|
Comodo Internet Security's firewall driver Inspect.sys contains an integer underflow in its IPv6 packet parser. The parser decrements an unsigned 64-bit payload-length value (taken from the IPv6 fixe…
New
|
CWE-191
Integer Underflow (Wrap or Wraparound)
|
CVE-2026-49494
|
2026-06-7 22:16 |
2026-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2
|
3.3 |
LOW
Local
|
-
|
-
|
A security vulnerability has been detected in SecureAge CatchPulse up to 10.9.1. Impacted is an unknown function in the library saappctl.sys of the component IOCTL Handler. The manipulation leads to …
New
|
CWE-200 CWE-284
Information Exposure Improper Access Control
|
CVE-2026-11459
|
2026-06-7 19:16 |
2026-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3
|
5.3 |
MEDIUM
Network
|
-
|
-
|
A weakness has been identified in erzhongxmu JeeWMS up to 141740afb2ba14d441c82a833d0a418d07ca2d69. This issue affects some unknown processing of the file /base-boot/actuator of the component Boot Ac…
New
|
CWE-200 CWE-284
Information Exposure Improper Access Control
|
CVE-2026-11458
|
2026-06-7 18:16 |
2026-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4
|
7.3 |
HIGH
Network
|
-
|
-
|
A security flaw has been discovered in erzhongxmu JeeWMS up to 141740afb2ba14d441c82a833d0a418d07ca2d69. This vulnerability affects unknown code of the file /base-boot/jmreport/testConnection of the …
New
|
CWE-74 CWE-707
Injection Improper Enforcement of Message or Data Structure
|
CVE-2026-11457
|
2026-06-7 18:16 |
2026-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
5
|
7.3 |
HIGH
Network
|
-
|
-
|
A vulnerability was identified in Chanjet CRM 1.0. This affects an unknown part of the file /tools/jxf_dump_systable.php of the component HTTP GET Request Handler. Such manipulation of the argument g…
New
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-11456
|
2026-06-7 18:16 |
2026-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
6
|
5.0 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.2. Affected by this issue is the function check_cmd_exists of the file metagpt/utils/common.py. This manipulation of the argument …
New
|
CWE-74 CWE-77
Injection Command Injection
|
CVE-2026-11455
|
2026-06-7 18:16 |
2026-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
7
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was found in Tiobon Employee Self-Service System up to 7.2. Affected by this vulnerability is an unknown functionality of the file /Blog/BlogSearch.aspx of the component Login Endpoin…
New
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-11453
|
2026-06-7 13:16 |
2026-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
8
|
7.3 |
HIGH
Network
|
-
|
-
|
A vulnerability has been found in GL.iNet GL-MT3000 up to 4.4.5. Affected is the function FUN_0042e200 of the file /cgi-bin/glc of the component SET_USER_PWD Handler. The manipulation of the argument…
New
|
CWE-74 CWE-77
Injection Command Injection
|
CVE-2026-11452
|
2026-06-7 13:16 |
2026-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
9
|
7.3 |
HIGH
Network
|
-
|
-
|
A flaw has been found in GL.iNet GL-MT3000 4.4.5. This impacts the function snprintf of the file /cgi-bin/glc of the component FTP Protocol Handler. Executing a manipulation of the argument media_dir…
New
|
CWE-74 CWE-77
Injection Command Injection
|
CVE-2026-11451
|
2026-06-7 13:16 |
2026-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
10
|
7.3 |
HIGH
Network
|
-
|
-
|
A vulnerability was detected in GL.iNet GL-MT3000 4.4.5. This affects the function dlopen in the library /usr/lib/oui-httpd/rpc/ of the component Path Normalization Handler. Performing a manipulation…
New
|
CWE-74 CWE-77
Injection Command Injection
|
CVE-2026-11450
|
2026-06-7 12:16 |
2026-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
11
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A security vulnerability has been detected in GL.iNet GL-MT3000 4.4.5. The impacted element is the function rpc_sys of the file /cgi-bin/luci/rpc of the component LuCI JSON-RPC Interface. Such manipu…
New
|
CWE-74 CWE-77
Injection Command Injection
|
CVE-2026-11449
|
2026-06-7 12:16 |
2026-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
12
|
4.7 |
MEDIUM
Network
|
-
|
-
|
A weakness has been identified in GL.iNet GL-MT3000 up to 4.4.5. The affected element is the function realpath of the file /rpc of the component Minidlna Service. This manipulation of the argument ku…
New
|
CWE-74 CWE-77
Injection Command Injection
|
CVE-2026-11448
|
2026-06-7 12:16 |
2026-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
13
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A security flaw has been discovered in GL.iNet GL-MT3000 up to 4.4.5. Impacted is the function iwinfo_backend of the file iwinfo.so of the component MTK Backend. The manipulation of the argument devi…
New
|
CWE-74 CWE-77
Injection Command Injection
|
CVE-2026-11447
|
2026-06-7 11:16 |
2026-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
14
|
8.4 |
HIGH
Local
|
-
|
-
|
clash-verge-service-ipc before 2.3.0 has a world-reachable IPC endpoint, leading to local privilege escalation.
New
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2026-26422
|
2026-06-7 08:16 |
2026-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
15
|
- |
-
|
-
|
-
|
Rejected reason: DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.
New
|
-
|
CVE-2026-36229
|
2026-06-7 06:16 |
2026-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
16
|
6.5 |
MEDIUM
Network
|
-
|
-
|
A missing upper-bound check in the udpif_set_threads() function of Open vSwitch v3.6.90 allows an attacker with OVSDB write access to request an excessive number of handler or revalidation threads. T…
Update
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2026-36499
|
2026-06-7 05:16 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
17
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was identified in theonedev onedev up to 15.0.5. This vulnerability affects the function canAccessIssue of the file /issues/ of the component Pull Request Handler. Such manipulation o…
New
|
CWE-266 CWE-285
Incorrect Privilege Assignment Improper Authorization
|
CVE-2026-11441
|
2026-06-7 03:16 |
2026-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
18
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was determined in theonedev onedev up to 15.0.5. This affects an unknown part of the file /repositories/{projectId}/default-branch of the component REST API. This manipulation of the …
New
|
CWE-266 CWE-285
Incorrect Privilege Assignment Improper Authorization
|
CVE-2026-11440
|
2026-06-7 03:16 |
2026-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
19
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was found in theonedev onedev up to 15.0.5. Affected by this issue is some unknown functionality of the file /projects/ of the component Parent Project Handler. The manipulation of th…
New
|
CWE-266 CWE-285
Incorrect Privilege Assignment Improper Authorization
|
CVE-2026-11439
|
2026-06-7 03:16 |
2026-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
20
|
8.3 |
HIGH
Network
|
-
|
-
|
Use after free in Serial in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HT…
Update
|
CWE-416
Use After Free
|
CVE-2026-11012
|
2026-06-7 03:16 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
21
|
8.3 |
HIGH
Network
|
-
|
-
|
Use after free in WebShare in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted …
Update
|
CWE-416
Use After Free
|
CVE-2026-11010
|
2026-06-7 03:16 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
22
|
9.6 |
CRITICAL
Network
|
-
|
-
|
Use after free in USB in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Medium)
Update
|
CWE-416
Use After Free
|
CVE-2026-11009
|
2026-06-7 03:16 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
23
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Out of bounds read in Dawn in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform an out of bounds memory read via a crafted HTML page. (Chromium security severity: Medium)
Update
|
CWE-125
Out-of-bounds Read
|
CVE-2026-11006
|
2026-06-7 03:16 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
24
|
5.3 |
MEDIUM
Network
|
-
|
-
|
Out of bounds read in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory …
Update
|
CWE-125
Out-of-bounds Read
|
CVE-2026-11004
|
2026-06-7 03:16 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
25
|
8.3 |
HIGH
Network
|
google
|
chrome
|
Use after free in Autofill in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. …
Update
|
CWE-416
Use After Free
|
CVE-2026-11002
|
2026-06-7 03:16 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
26
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability has been found in theonedev onedev up to 15.0.5. Affected by this vulnerability is an unknown functionality of the file /projects. The manipulation of the argument project.forkedFromI…
New
|
CWE-266 CWE-285
Incorrect Privilege Assignment Improper Authorization
|
CVE-2026-11438
|
2026-06-7 02:16 |
2026-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
27
|
7.3 |
HIGH
Network
|
-
|
-
|
A flaw has been found in perfree go-fastdfs-web up to 1.3.7. Affected is the function checkServer of the file /install/checkServer of the component Installation Endpoint. Executing a manipulation can…
New
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-11437
|
2026-06-7 02:16 |
2026-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
28
|
4.2 |
MEDIUM
Network
|
google
|
chrome
|
Inappropriate implementation in Payments in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to perform UI spoofing via a crafted …
Update
|
CWE-290 CWE-451
Authentication Bypass by Spoofing User Interface (UI) Misrepresentation of Critical Information
|
CVE-2026-11001
|
2026-06-7 02:16 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
29
|
6.1 |
MEDIUM
Network
|
google
|
chrome
|
Integer overflow in ANGLE in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from proces…
Update
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2026-10999
|
2026-06-7 02:16 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
30
|
6.5 |
MEDIUM
Network
|
google
|
chrome
|
Uninitialized Use in ANGLE in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium securit…
Update
|
CWE-457
Use of Uninitialized Variable
|
CVE-2026-10994
|
2026-06-7 02:16 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
31
|
6.5 |
MEDIUM
Network
|
google
|
chrome
|
Heap buffer overflow in Skia in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium secur…
Update
|
CWE-122
Heap-based Buffer Overflow
|
CVE-2026-10993
|
2026-06-7 02:16 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
32
|
6.5 |
MEDIUM
Network
|
google
|
chrome
|
Insufficient data validation in Animation in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (C…
Update
|
NVD-CWE-noinfo CWE-20
Improper Input Validation
|
CVE-2026-10992
|
2026-06-7 02:16 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
33
|
8.3 |
HIGH
Network
|
google
|
chrome
|
Use after free in Glic in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chr…
Update
|
CWE-416
Use After Free
|
CVE-2026-10990
|
2026-06-7 02:16 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
34
|
4.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was detected in Mage AI up to 0.9.79. This impacts the function useMutation of the file mage_ai/frontend/components/Sessions/SignForm/index.tsx of the component Sign-in Flow. Performi…
New
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-11436
|
2026-06-7 01:16 |
2026-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
35
|
7.3 |
HIGH
Network
|
-
|
-
|
A security vulnerability has been detected in Jinher OA 1.0. This affects an unknown function of the file nextselectplan.aspx. Such manipulation of the argument httpOID leads to sql injection. The at…
New
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-11435
|
2026-06-7 01:16 |
2026-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
36
|
2.4 |
LOW
Network
|
-
|
-
|
A weakness has been identified in FluentCMS 0.0.5. The impacted element is an unknown function of the file /admin/blocks of the component Blocks Plugin. This manipulation causes cross site scripting.…
New
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-11434
|
2026-06-7 00:16 |
2026-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
37
|
8.8 |
HIGH
Network
|
-
|
-
|
A security vulnerability has been detected in JingDong JD Cloud Box AX6600 4.5.3.r4546. The impacted element is the function set_macfilter of the file /sbin/jdcweb_rpc. The manipulation leads to stac…
New
|
CWE-119 CWE-121
Incorrect Access of Indexable Resource ('Range Error') Stack-based Buffer Overflow
|
CVE-2026-11413
|
2026-06-6 23:16 |
2026-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
38
|
8.8 |
HIGH
Network
|
-
|
-
|
Integer overflow in V8 in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: Medium)
Update
|
CWE-472
External Control of Assumed-Immutable Web Parameter
|
CVE-2026-11211
|
2026-06-6 22:16 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
39
|
5.9 |
MEDIUM
Network
|
google
|
chrome
|
Inappropriate implementation in WebRTC in Google Chrome prior to 149.0.7827.53 allowed an attacker in a privileged network position to leak cross-origin data via malicious network traffic. (Chromium …
Update
|
CWE-20
Improper Input Validation
|
CVE-2026-11199
|
2026-06-6 22:16 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
40
|
7.8 |
HIGH
Local
|
-
|
-
|
Inappropriate implementation in Installer in Google Chrome on Windows prior to 149.0.7827.53 allowed a local attacker to perform OS-level privilege escalation via a malicious file. (Chromium security…
Update
|
CWE-269
Improper Privilege Management
|
CVE-2026-11103
|
2026-06-6 22:16 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
41
|
7.8 |
HIGH
Local
|
-
|
-
|
Use after free in WebView in Google Chrome on Android prior to 149.0.7827.53 allowed a local attacker to execute arbitrary code via a malicious file. (Chromium security severity: Medium)
Update
|
CWE-416
Use After Free
|
CVE-2026-11072
|
2026-06-6 22:16 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
42
|
8.3 |
HIGH
Network
|
google
|
chrome
|
Insufficient validation of untrusted input in Printing in Google Chrome on Windows prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a s…
Update
|
CWE-20
Improper Input Validation
|
CVE-2026-10971
|
2026-06-6 22:16 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
43
|
6.1 |
MEDIUM
Physics
|
-
|
-
|
Inappropriate implementation in Enterprise in Google Chrome prior to 149.0.7827.53 allowed a local attacker to perform privilege escalation via physical access to the device. (Chromium security sever…
Update
|
CWE-269
Improper Privilege Management
|
CVE-2026-11229
|
2026-06-6 21:16 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
44
|
- |
-
|
-
|
-
|
Protocol::HTTP2 versions through 1.12 for Perl is vulnerable to a HTTP/2 Bomb.
Protocol::HTTP2's inbound HPACK path has no header-list size limit, so a small HTTP/2 request can expand into large ser…
New
|
CWE-409
Improper Handling of Highly Compressed Data (Data Amplification)
|
CVE-2026-10725
|
2026-06-6 21:16 |
2026-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
45
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A weakness has been identified in Jinher OA C6. The affected element is an unknown function of the file /C6/JHSoft.Web.ModuleCount/GetFormSn.aspx. Executing a manipulation of the argument queryID can…
New
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-11412
|
2026-06-6 20:16 |
2026-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
46
|
4.4 |
MEDIUM
Local
|
-
|
-
|
A security flaw has been discovered in iAI Lab PDF AI App 4.21.0 on Android. Impacted is the function getExternalCacheDir of the component chatpdf.pro. Performing a manipulation of the argument _disp…
New
|
CWE-22
Path Traversal
|
CVE-2026-11411
|
2026-06-6 20:16 |
2026-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
47
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was identified in vertex-app vertex up to 2026.02.12. This issue affects some unknown processing of the file app/model/LogMod.js of the component Log Viewer Endpoint. Such manipulatio…
New
|
CWE-77 CWE-78
Command Injection OS Command
|
CVE-2026-11408
|
2026-06-6 20:16 |
2026-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
48
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was determined in GL.iNet MT3000 up to 4.4.5. This vulnerability affects unknown code of the file ovpnclient.sh of the component OpenVPN Client Import Workflow. This manipulation caus…
New
|
CWE-74 CWE-77
Injection Command Injection
|
CVE-2026-11406
|
2026-06-6 19:16 |
2026-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
49
|
5.3 |
MEDIUM
Network
|
-
|
-
|
In OpenStack Ironic 32 before 37.0.0, an unauthenticated malicious user could submit a crafted JSON string to some endpoints on the API or JSON-RPC service and effect a service crash.
Update
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2026-50589
|
2026-06-6 15:16 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
50
|
- |
-
|
-
|
-
|
DBI versions before 1.648 for Perl have a heap overflow when preparsing SQL statements with more than 9 binders.
The preparse method expands SQL placeholder characters to numbered binders of the for…
New
|
CWE-787
Out-of-bounds Write
|
CVE-2026-10879
|
2026-06-6 15:16 |
2026-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|