|
2211
|
7.1 |
HIGH
Network
|
ibm
|
engineering_lifecycle_management
|
IBM Engineering Lifecycle Management 7.0.3 Interim Fix 001 through Interim Fix 021, 7.1.0 Interim Fix 001 through Interim Fix 009, and 7.2.0 and 7.2.0 Interim Fix 001 is vulnerable to an XML exter…
|
CWE-611
XXE
|
CVE-2026-3603
|
2026-06-3 03:44 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2212
|
7.5 |
HIGH
Network
|
viewcomponent
|
view_component
|
view_component is a framework for building reusable, testable, and encapsulated view components in Ruby on Rails. From 3.0.0 to 4.9.0, the system test entrypoint canonicalizes a user-controlled file …
|
CWE-187
Partial String Comparison
|
CVE-2026-44837
|
2026-06-3 03:43 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2213
|
3.3 |
LOW
Local
|
google
|
android
|
In updateProvidersWhenServiceRemoved of CredentialManagerService.java, there is a possible way to override settings across users due to a permissions bypass. This could lead to local information disc…
|
CWE-269
Improper Privilege Management
|
CVE-2026-0016
|
2026-06-3 03:41 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2214
|
7.5 |
HIGH
Network
|
ibm
|
websphere_application_server
|
IBM Web Server Plug-ins for WebSphere Application Server and WebSphere Liberty 8.5, 9.0 IBM WebSphere Application Server and WebSphere Application Server Liberty are vulnerable to HTTP request smuggl…
|
CWE-444
HTTP Request Smuggling
|
CVE-2026-8620
|
2026-06-3 03:40 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2215
|
9.8 |
CRITICAL
Network
|
shepherdwind
|
velocity.js
|
Velocity.js is a JavaScript implementation of the Apache Velocity template engine. In 2.1.5 and earlier, a prototype pollution vulnerability was discovered in velocityjs. This issue occurs during the…
|
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
|
CVE-2026-44966
|
2026-06-3 03:40 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2216
|
8.2 |
HIGH
Network
|
github
|
enterprise_server
|
A server-side request forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to send crafted requests to internal services by exploiting insu…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-9312
|
2026-06-3 03:31 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2217
|
7.5 |
HIGH
Network
|
osgeo
|
mapserver
|
MapServer is a system for developing web-based GIS applications. From 6.4.0 to before 8.6.3, msSLDParseUserStyle always calls _SLDApplyRuleValues(psRule, psLayer, 1); for any <Rule> carrying <ElseFil…
|
CWE-129 CWE-476
Improper Validation of Array Index NULL Pointer Dereference
|
CVE-2026-45104
|
2026-06-3 03:19 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2218
|
5.5 |
MEDIUM
Local
|
google
|
android
|
In verifySignature of ApkChecksums.java, there is a possible way to cause a crash due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2026-0069
|
2026-06-3 03:06 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2219
|
6.5 |
MEDIUM
Adjacent
|
qualcomm
|
fastconnect_7800_firmware qca7005_firmware snapdragon_ar1_gen_1_platform_firmware wcd9380_firmware wcd9385_firmware wsa8830_firmware wsa8832_firmware wsa8835_firmware
|
Information Disclosure when resetting device to factory default settings through powerline interface allows unauthorized access to device configuration.
|
CWE-1230
Exposure of Sensitive Information Through Metadata
|
CVE-2025-59601
|
2026-06-3 03:00 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2220
|
7.8 |
HIGH
Local
|
qualcomm
|
snapdragon_480_5g_mobile_platform_firmware snapdragon_480\+_5g_mobile_platform_firmware snapdragon_6_gen_1_mobile_platform_firmware snapdragon_6_gen_3_mobile_platform_firmware snapdragon_…
|
Memory Corruption when running a memory copy operation due to invalid writes caused by a null pointer.
|
CWE-476
NULL Pointer Dereference
|
CVE-2025-59604
|
2026-06-3 03:00 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|