|
611
|
9.8 |
CRITICAL
Network
|
-
|
-
|
A lack of cryptographic signature verification in the validateAccessToken function of bookcars v8.3 allows attackers to bypass authentication via a forged JWT token.
New
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2026-36721
|
2026-06-11 00:16 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
612
|
7.5 |
HIGH
Network
|
-
|
-
|
An information disclosure vulnerability in the /api/v1/user/info endpoint of AgentChat v2.3.0 allows unauthenticated attackers to obtain sensitive information, including SHA256 password hashes, via e…
New
|
CWE-200
Information Exposure
|
CVE-2026-36719
|
2026-06-11 00:16 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
613
|
8.4 |
HIGH
Local
|
-
|
-
|
Slate Digital Connect 1.37.0 for macOS installs a privileged helper tool, com.slatedigital.connect.privileged.helper.tool, which exposes the XPC service com.slatedigital.connect.privileged.helper.too…
New
|
CWE-367
Time-of-check Time-of-use (TOCTOU) Race Condition
|
CVE-2026-24067
|
2026-06-11 00:16 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
614
|
8.4 |
HIGH
Local
|
-
|
-
|
Slate Digital Connect 1.37.0 for macOS installs a privileged helper tool, com.slatedigital.connect.privileged.helper.tool, which exposes the XPC service com.slatedigital.connect.privileged.helper.too…
New
|
CWE-296
Improper Following of a Certificate's Chain of Trust
|
CVE-2026-24066
|
2026-06-11 00:16 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
615
|
7.8 |
HIGH
Local
|
-
|
-
|
Waves Central for macOS versions 13.0.9 through 16.5.5 contain a local privilege escalation vulnerability. A trusted XPC client component included with the product is signed with hardened runtime ent…
New
|
CWE-426
Untrusted Search Path
|
CVE-2026-24064
|
2026-06-11 00:16 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
616
|
6.5 |
MEDIUM
Network
|
-
|
-
|
A heap buffer overflow flaw was found in 389 Directory Server. When serializing objectclass definitions, the oc_superior (SUP) field length is omitted from buffer size calculations in read_schema_dse…
New
|
CWE-122
Heap-based Buffer Overflow
|
CVE-2026-11884
|
2026-06-11 00:16 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
617
|
8.3 |
HIGH
Network
|
google
|
chrome
|
Insufficient validation of untrusted input in Drag and Drop in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perfor…
Update
|
CWE-20
Improper Input Validation
|
CVE-2026-11029
|
2026-06-11 00:16 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
618
|
5.5 |
MEDIUM
Local
|
-
|
-
|
A NULL pointer dereference in the gf_isom_get_user_data_count function (isomedia/isom_read.c) of GPAC MP4Box v2.4 allows attackers to cause a Denial of Service (DoS) via supplying a crafted MP4 file.
New
|
CWE-476
NULL Pointer Dereference
|
CVE-2025-55651
|
2026-06-11 00:16 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
619
|
6.7 |
MEDIUM
Local
|
-
|
-
|
During an internal security assessment, a potential out-of-bounds write vulnerability was discovered in the BIOS of some ThinkPad products could allow a privileged local user to execute code in Syste…
New
|
CWE-787
Out-of-bounds Write
|
CVE-2025-10238
|
2026-06-11 00:16 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
620
|
6.7 |
MEDIUM
Local
|
-
|
-
|
During an internal security assessment, a potential vulnerability was discovered in some ThinkPad embedded controller firmware that could allow a privileged local user to perform arbitrary reads or w…
New
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2025-10237
|
2026-06-11 00:16 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|