|
571
|
7.8 |
HIGH
Local
|
microsoft
|
windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2012 windows_server_2016 w…
|
Improper link resolution before file access ('link following') in Windows Collaborative Translation Framework allows an authorized attacker to elevate privileges locally.
New
|
CWE-59
Link Following
|
CVE-2026-45586
|
2026-06-12 00:33 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
572
|
- |
|
-
|
-
|
A HTTP request smuggling and desynchronization vulnerability affects Kong Gateway Enterprise 3.4, 3.10, 3.11, 3.12, 3.13, and 3.14 series. The vulnerability is caused by a parsing flaw in Kong’s HTTP…
New
|
CWE-444
HTTP Request Smuggling
|
CVE-2026-6338
|
2026-06-12 00:32 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
573
|
7.7 |
HIGH
Network
|
-
|
-
|
Sharp is a content management framework built for Laravel as a package. Prior to version 9.22.0, Sharp exposes a generic download endpoint that authorizes access only to the supplied Sharp entity ins…
New
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-44692
|
2026-06-12 00:31 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
574
|
4.3 |
MEDIUM
Network
|
-
|
-
|
Sharp is a content management framework built for Laravel as a package. From version 9.0.0 to before version 9.22.3, the create and store endpoints of the Quick Creation Command feature did not enfor…
New
|
CWE-862
Missing Authorization
|
CVE-2026-53634
|
2026-06-12 00:31 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
575
|
7.6 |
HIGH
Network
|
-
|
-
|
Xibo is an open source digital signage platform with a web content management system and Windows display player software. Prior to 4.4.2, a vulnerability chain consisting of Stored XSS and Iframe San…
New
|
CWE-79 CWE-116 CWE-346
Cross-site Scripting Improper Encoding or Escaping of Output Origin Validation Error
|
CVE-2026-42558
|
2026-06-12 00:30 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
576
|
4.3 |
MEDIUM
Network
|
-
|
-
|
Yamcs is a mission control framework. Prior to versions 5.13.0 and 5.12.7, an LDAP injection vulnerability exists in `org.yamcs.security.LdapAuthModule` when constructing search filters. The username…
New
|
CWE-90
LDAP Injection
|
CVE-2026-42568
|
2026-06-12 00:30 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
577
|
4.3 |
MEDIUM
Network
|
-
|
-
|
SQLAdmin is a flexible Admin interface for SQLAlchemy models. Prior to version 0.25.1, the ajax_lookup endpoint in application.py bypasses the is_accessible() access control check that all other endp…
New
|
CWE-862
Missing Authorization
|
CVE-2026-46645
|
2026-06-12 00:30 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
578
|
7.8 |
HIGH
Local
|
-
|
-
|
A local privilege escalation vulnerability exists in Check Point Identity Agent Full for Windows OS. An authenticated local user may be able to execute arbitrary code with SYSTEM privileges due to im…
New
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2026-10847
|
2026-06-12 00:30 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
579
|
6.6 |
MEDIUM
Local
|
-
|
-
|
Authentication bypass by primary weakness vulnerability in ABB Freelance.
This issue affects Freelance: through 2013, 2013 SP1, 2016, 2016 SP1, 2019, 2019 SP1, 2019 SP1 FP1, 2024.
New
|
CWE-305
Authentication Bypass by Primary Weakness
|
CVE-2025-7064
|
2026-06-12 00:28 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
580
|
- |
|
-
|
-
|
Golem OEE MES is vulnerable to an unauthenticated path traversal flaw. This vulnerability allows an attacker in the same local network to read arbitrary files from the server's operating system by ma…
New
|
CWE-22
Path Traversal
|
CVE-2026-8464
|
2026-06-12 00:28 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|