|
1541
|
8.8 |
HIGH
Network
|
-
|
-
|
IBM i Access Family 1.1.5.0 through 1.1.9.12 IBM i Access Client Solutions (ACS) is vulnerable to remote code execution when configured to listen for requests from IBM i Navigator.
|
CWE-74
Injection
|
CVE-2026-7770
|
2026-06-2 23:01 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1542
|
8.8 |
HIGH
Network
|
-
|
-
|
An Improper Access Control vulnerability in Ivanti Neurons for ITSM (cloud and on-premises) allows a remote authenticated attacker to gain administrative access.
|
CWE-284
Improper Access Control
|
CVE-2026-9614
|
2026-06-2 23:01 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1543
|
8.8 |
HIGH
Network
|
bentoml
|
bentoml
|
BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4.39, src/bentoml/_internal/container/frontend/dockerfile/templates/base_v2.j2 in…
|
CWE-78
OS Command
|
CVE-2026-44345
|
2026-06-2 22:59 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1544
|
- |
|
-
|
-
|
Server-Side Template Injection (SSTI) in Wirtualna Uczelnia allows an unauthenticated attacker to perform Remote Code Execution (RCE). In the endpoint redirectToUrl and parameter redirectUrlParameter…
|
CWE-1336
Improper Neutralization of Special Elements Used in a Template Engine
|
CVE-2026-34906
|
2026-06-2 22:54 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1545
|
- |
|
-
|
-
|
Wirtualna Uczelnia is vulnerable to Reflected Cross‑Site Scripting (XSS) due to insecure handling of the locale parameter across multiple endpoints. An attacker can craft a malicious URL with JavaScr…
|
CWE-79
Cross-site Scripting
|
CVE-2026-34907
|
2026-06-2 22:54 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1546
|
8.8 |
HIGH
Network
|
bentoml
|
bentoml
|
BentoML is a Python library for building online serving systems optimized for AI apps and model inference. Prior to 1.4.39, a malicious bentofile.yaml containing a newline-injected value in envs[*].n…
|
CWE-78 CWE-94
OS Command Code Injection
|
CVE-2026-44346
|
2026-06-2 22:48 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1547
|
7.5 |
HIGH
Network
|
botan_project
|
botan
|
Botan is a C++ cryptography library. Prior to 3.12.0, certain patterns of indefinite length encodings in BER data could cause quadratic behavior in the parser, resulting in a denial of service. Such …
|
CWE-407
Inefficient Algorithmic Complexity
|
CVE-2026-44378
|
2026-06-2 22:42 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1548
|
7.2 |
HIGH
Network
|
tp-link
|
archer_be450_firmware archer_be7200_firmware
|
An authenticated command injection vulnerability exists in the Archer BE450 v1 and BE7200 v1 router that allows an administrator to execute arbitrary system commands through the web management interf…
|
CWE-20 CWE-77
Improper Input Validation Command Injection
|
CVE-2026-5509
|
2026-06-2 22:40 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1549
|
8.8 |
HIGH
Network
|
jetbrains
|
teamcity
|
In JetBrains TeamCity before 2026.1 remote code execution was possible via Perforce connection settings
|
CWE-88
Argument Injection
|
CVE-2026-49373
|
2026-06-2 22:13 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1550
|
7.6 |
HIGH
Network
|
jetbrains
|
teamcity
|
In JetBrains TeamCity before 2026.1 improper permission checks exposed build configuration parameters
|
CWE-862
Missing Authorization
|
CVE-2026-49374
|
2026-06-2 22:12 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|