|
1741
|
9.8 |
CRITICAL
Network
|
-
|
-
|
DedeCMS V5.7.118 is vulnerable to Command Execution in file_manage_control.php.
|
CWE-78
OS Command
|
CVE-2026-38615
|
2026-06-11 00:16 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1742
|
9.8 |
CRITICAL
Network
|
-
|
-
|
A lack of cryptographic signature verification in the validateAccessToken function of bookcars v8.3 allows attackers to bypass authentication via a forged JWT token.
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2026-36721
|
2026-06-11 00:16 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1743
|
7.5 |
HIGH
Network
|
-
|
-
|
An information disclosure vulnerability in the /api/v1/user/info endpoint of AgentChat v2.3.0 allows unauthenticated attackers to obtain sensitive information, including SHA256 password hashes, via e…
|
CWE-200
Information Exposure
|
CVE-2026-36719
|
2026-06-11 00:16 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1744
|
8.4 |
HIGH
Local
|
-
|
-
|
Slate Digital Connect 1.37.0 for macOS installs a privileged helper tool, com.slatedigital.connect.privileged.helper.tool, which exposes the XPC service com.slatedigital.connect.privileged.helper.too…
|
CWE-367
Time-of-check Time-of-use (TOCTOU) Race Condition
|
CVE-2026-24067
|
2026-06-11 00:16 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1745
|
8.4 |
HIGH
Local
|
-
|
-
|
Slate Digital Connect 1.37.0 for macOS installs a privileged helper tool, com.slatedigital.connect.privileged.helper.tool, which exposes the XPC service com.slatedigital.connect.privileged.helper.too…
|
CWE-296
Improper Following of a Certificate's Chain of Trust
|
CVE-2026-24066
|
2026-06-11 00:16 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1746
|
7.8 |
HIGH
Local
|
-
|
-
|
Waves Central for macOS versions 13.0.9 through 16.5.5 contain a local privilege escalation vulnerability. A trusted XPC client component included with the product is signed with hardened runtime ent…
|
CWE-426
Untrusted Search Path
|
CVE-2026-24064
|
2026-06-11 00:16 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1747
|
6.5 |
MEDIUM
Network
|
-
|
-
|
A heap buffer overflow flaw was found in 389 Directory Server. When serializing objectclass definitions, the oc_superior (SUP) field length is omitted from buffer size calculations in read_schema_dse…
|
CWE-122
Heap-based Buffer Overflow
|
CVE-2026-11884
|
2026-06-11 00:16 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1748
|
8.3 |
HIGH
Network
|
google
|
chrome
|
Insufficient validation of untrusted input in Drag and Drop in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perfor…
|
CWE-20
Improper Input Validation
|
CVE-2026-11029
|
2026-06-11 00:16 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1749
|
6.7 |
MEDIUM
Local
|
-
|
-
|
During an internal security assessment, a potential out-of-bounds write vulnerability was discovered in the BIOS of some ThinkPad products could allow a privileged local user to execute code in Syste…
|
CWE-787
Out-of-bounds Write
|
CVE-2025-10238
|
2026-06-11 00:16 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1750
|
6.7 |
MEDIUM
Local
|
-
|
-
|
During an internal security assessment, a potential vulnerability was discovered in some ThinkPad embedded controller firmware that could allow a privileged local user to perform arbitrary reads or w…
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2025-10237
|
2026-06-11 00:16 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|