|
3981
|
6.5 |
MEDIUM
Adjacent
|
-
|
-
|
aiograpi is an asynchronous Instagram API for Python. aiograpi versions before 0.9.10 accepted server-supplied signup challenge paths and used them to build request URLs before validating that the pa…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-47157
|
2026-06-12 03:16 |
2026-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3982
|
5.3 |
MEDIUM
Network
|
-
|
-
|
Fediverse Embeds embeds fediverse posts on WordPress sites. Prior to version 1.5.9, Fediverse Embeds registered the unauthenticated AJAX action wp_ajax_nopriv_ftf_get_site_info (includes/Site_Info.ph…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-46698
|
2026-06-12 03:16 |
2026-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3983
|
7.5 |
HIGH
Network
|
-
|
-
|
Fediverse Embeds embeds fediverse posts on WordPress sites. Prior to version 1.5.8, Fediverse Embeds registered an unauthenticated REST route ftf/media-proxy (includes/Media_Proxy.php) with permissio…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-46697
|
2026-06-12 03:16 |
2026-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3984
|
- |
|
-
|
-
|
A remote unauthenticated attacker may be able to conduct credential-guessing attacks against user accounts in Sonatype Nexus Repository via authentication endpoints.
|
CWE-307
mproper Restriction of Excessive Authentication Attempts
|
CVE-2026-3329
|
2026-06-12 03:16 |
2026-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3985
|
4.9 |
MEDIUM
Network
|
-
|
-
|
A flaw was found in the admin-ui-ext component of Keycloak, which provides extended administrative user interface capabilities. The issue occurs because certain bulk role-removal endpoints fail to pe…
|
CWE-425
Direct Request ('Forced Browsing')
|
CVE-2026-11986
|
2026-06-12 03:16 |
2026-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3986
|
8.8 |
HIGH
Local
|
espressif
|
esp-idf
|
ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.4 and 6.0, the esp_tee component exposes secure-service wrappers in esp_secure_services.c and esp_secure_servi…
|
CWE-20 CWE-787
Improper Input Validation Out-of-bounds Write
|
CVE-2026-45328
|
2026-06-12 03:15 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3987
|
7.5 |
HIGH
Network
|
espressif
|
esp-idf
|
ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.2.6, 5.3.5, 5.4.4, 5.5.4, and 6.0, a NULL-pointer dereference exists in the WebSocket subprotocol-negotiation pa…
|
CWE-476
NULL Pointer Dereference
|
CVE-2026-45541
|
2026-06-12 03:05 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3988
|
6.5 |
MEDIUM
Local
|
espressif
|
esp-idf
|
ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.4 and 6.0, several ESP-TEE secure-service wrappers in esp_secure_services.c and esp_secure_services_iram.c val…
|
CWE-20 CWE-125 CWE-200
Improper Input Validation Out-of-bounds Read Information Exposure
|
CVE-2026-45329
|
2026-06-12 03:04 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3989
|
6.5 |
MEDIUM
Network
|
7-zip
|
7-zip
|
7-Zip is a file archiver with a high compression ratio. Versions 9.21 through 26.00 contain an An uninitialized memory disclosure vulnerability in the UEFI capsule (.scap) parser in 7-Zip. The OpenCa…
|
CWE-908
Use of Uninitialized Resource
|
CVE-2026-48101
|
2026-06-12 03:02 |
2026-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3990
|
7.8 |
HIGH
Local
|
microsoft
|
windows_10_21h2 windows_10_22h2 windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2022 windows_server_2025
|
Out-of-bounds read in Windows Hyper-V allows an unauthorized attacker to execute code locally.
|
CWE-843 CWE-125
Type Confusion Out-of-bounds Read
|
CVE-2026-45641
|
2026-06-12 02:42 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|