|
2261
|
- |
|
-
|
-
|
syracom AG Secure Login (2FA) for Atlassian Jira, Confluence, and Bitbucket 3.4.0.x contains an authentication bypass vulnerability. An attacker with valid credentials for a user account can bypass t…
|
CWE-288
Authentication Bypass Using an Alternate Path or Channel
|
CVE-2026-12225
|
2026-06-17 00:36 |
2026-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2262
|
- |
|
-
|
-
|
A session fixation vulnerability has been identified in osTicket v1.18.2. This security flaw allows an attacker to hijack a victim’s account by keeping the initial session identifier (OSTSESSID) acti…
|
CWE-38
|
CVE-2026-9507
|
2026-06-17 00:36 |
2026-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2263
|
- |
|
-
|
-
|
Actual is a local-first personal finance tool. The `POST /openid/config` endpoint in Actual Budget's sync-server versions <= 26.4.0 exposes the full OpenID Connect configuration—including the OAuth2 …
|
CWE-863
Incorrect Authorization
|
CVE-2026-42604
|
2026-06-17 00:35 |
2026-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2264
|
- |
|
-
|
-
|
Actual is an open-source personal finance application. In the macOS desktop application version 25.x (built on Electron 39.2.7), the ELECTRON_RUN_AS_NODE fuse is not disabled, allowing an attacker wh…
|
CWE-94
Code Injection
|
CVE-2026-42890
|
2026-06-17 00:35 |
2026-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2265
|
- |
|
-
|
-
|
Actual is an open-source personal finance application. Prior to version 26.5.0, several endpoints are affected by a path traversal vulnerability. Version 26.5.0 fixes the issue.
|
CWE-22
Path Traversal
|
CVE-2026-43872
|
2026-06-17 00:35 |
2026-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2266
|
9.1 |
CRITICAL
Network
|
-
|
-
|
In OCaml-TLS before 2.1.0, the client implementation does insufficient checks of the certificate provided by the server, which allows impersonation with certificates that are not meant for server aut…
|
CWE-295
Improper Certificate Validation
|
CVE-2026-45388
|
2026-06-17 00:35 |
2026-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2267
|
9.1 |
CRITICAL
Network
|
-
|
-
|
In OCaml-TLS before 2.1.0, the server implementation does insufficient checks of the certificate provided by the client (when doing client authentication), which allows impersonation with certificate…
|
-
|
CVE-2026-45389
|
2026-06-17 00:35 |
2026-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2268
|
9.1 |
CRITICAL
Network
|
-
|
-
|
In OCaml-tar before 3.4.0, a crafted archive with ../ path segments in its name allows escaping the current working directory. This is not desired behavior, and tar(1) rejects such extractions, but o…
|
CWE-22
Path Traversal
|
CVE-2026-45390
|
2026-06-17 00:35 |
2026-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2269
|
7.5 |
HIGH
Network
|
-
|
-
|
An issue in the attachment handling component of Feuerhamster MailForm v1.1.0 allows attackers to cause a Denial of Service (DoS) via a crafted request.
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2026-50878
|
2026-06-17 00:35 |
2026-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2270
|
7.5 |
HIGH
Network
|
-
|
-
|
An issue in the uploadPostHandler component of Andrei Marcu linx-server v2.3.8 allows attackers to cause a Denial of Service (DoS) via a crafted POST request.
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2026-50879
|
2026-06-17 00:35 |
2026-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|