|
1851
|
5.4 |
MEDIUM
Network
|
microsoft
|
edge_chromium
|
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Edge (Chromium-based) allows an authorized attacker to perform spoofing over a network.
|
CWE-79
Cross-site Scripting
|
CVE-2026-32208
|
2026-06-23 05:33 |
2026-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1852
|
- |
|
-
|
-
|
In AzeoTech DAQFactory versions 21.1 and prior, a Type Confusion vulnerability can be exploited by an attacker using specially crafted .ctl files which can result in code execution.
|
CWE-843
Type Confusion
|
CVE-2026-12390
|
2026-06-23 05:30 |
2026-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1853
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Improper input validation in AVer PTC500S, PTC115, PTC500+, and PTC115+
cameras may allow a remote, unauthenticated attacker to achieve
arbitrary code execution via a specially crafted web request.
|
CWE-552
Files or Directories Accessible to External Parties
|
CVE-2026-40624
|
2026-06-23 05:30 |
2026-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1854
|
6.5 |
MEDIUM
Adjacent
|
-
|
-
|
An attacker within BLE communication range can passively intercept
wireless traffic and obtain sensitive health-related information,
including glucose measurement values.
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2026-50034
|
2026-06-23 05:30 |
2026-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1855
|
6.5 |
MEDIUM
Adjacent
|
-
|
-
|
An attacker within BLE communication range can monopolize the device's
only available BLE connection slot, preventing legitimate users or
applications from establishing a connection.
|
CWE-862
Missing Authorization
|
CVE-2026-52866
|
2026-06-23 05:30 |
2026-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1856
|
6.1 |
MEDIUM
Local
|
-
|
-
|
setupBpmLogs follows symlink for bpm.log open and chown — container-to-host privilege escalation via /etc/shadow. A compromised process inside a bpm container can cause root to chown an arbitrary hos…
|
CWE-59
Link Following
|
CVE-2026-47833
|
2026-06-23 05:23 |
2026-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1857
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Bitnami Cassandra container images are affected by a retained default superuser vulnerability. When a custom administrator account is configured via the CASSANDRA_USER environment variable, the conta…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2026-47846
|
2026-06-23 05:23 |
2026-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1858
|
5.3 |
MEDIUM
Network
|
-
|
-
|
Bitnami MariaDB Galera container images and Helm chart are affected by a hardcoded default credential vulnerability in the Galera replication health-check user. The MARIADB_REPLICATION_USER and MARIA…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2026-47847
|
2026-06-23 05:23 |
2026-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1859
|
8.8 |
HIGH
Network
|
-
|
-
|
SQL injection in pgAdmin 4 across every dialog template that renders ``COMMENT ON ... IS '<description>'`` for a user-supplied description field. The Jinja templates for Domains (and their constraint…
|
CWE-89 CWE-116
SQL Injection Improper Encoding or Escaping of Output
|
CVE-2026-12044
|
2026-06-23 05:23 |
2026-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1860
|
3.5 |
LOW
Network
|
-
|
-
|
HTML injection in pgAdmin 4's cloud deployment module. The verify_credentials, deploy, regions, and update-server endpoints under /rds/, /azure/, /google/, and the top-level /cloud/ blueprint propaga…
|
CWE-79 CWE-116
Cross-site Scripting Improper Encoding or Escaping of Output
|
CVE-2026-12047
|
2026-06-23 05:23 |
2026-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|