|
651
|
- |
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
pinctrl: canaan: k230: Fix NULL pointer dereference when parsing devicetree
When probing the k230 pinctrl driver, the kernel trig…
|
-
|
CVE-2026-46269
|
2026-06-6 05:51 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
652
|
- |
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
coresight: tmc-etr: Fix race condition between sysfs and perf mode
When trying to run perf and sysfs mode simultaneously, the WAR…
|
-
|
CVE-2026-46272
|
2026-06-6 05:51 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
653
|
- |
|
-
|
-
|
A hard-coded cryptographic key is used by Altium Enterprise Server to sign file download URLs in the Vault service. Because the key is identical across all installations, an unauthenticated network a…
|
CWE-22 CWE-798
Path Traversal Use of Hard-coded Credentials
|
CVE-2026-11414
|
2026-06-6 05:49 |
2026-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
654
|
- |
|
-
|
-
|
A path traversal vulnerability exists in the Altium Enterprise Server Vault Service UploadController due to improper validation of a user-controlled path component in image upload requests. An authen…
|
CWE-22 CWE-434
Path Traversal Unrestricted Upload of File with Dangerous Type
|
CVE-2026-11419
|
2026-06-6 05:49 |
2026-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
655
|
- |
|
-
|
-
|
Two path traversal vulnerabilities in the Network Installation Service (NIS) of Altium Enterprise Server allow an unauthenticated network attacker to write arbitrary files to any writable location on…
|
CWE-22 CWE-306
Path Traversal Missing Authentication for Critical Function
|
CVE-2026-11420
|
2026-06-6 05:49 |
2026-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
656
|
8.0 |
HIGH
Network
|
-
|
-
|
An untrusted search path issue in the GlobalDatabasePlugin in the AWS Advanced JDBC Wrapper for Amazon Aurora PostgreSQL will allow a remote authenticated low-privilege actor to escalate privileges t…
|
CWE-426
Untrusted Search Path
|
CVE-2026-11400
|
2026-06-6 05:49 |
2026-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
657
|
8.0 |
HIGH
Network
|
-
|
-
|
An untrusted search path issue in the GlobalDatabasePlugin in the AWS Advanced Go Wrapper for Amazon Aurora PostgreSQL will allow a remote authenticated low-privilege actor to escalate privileges to …
|
CWE-426
Untrusted Search Path
|
CVE-2026-11401
|
2026-06-6 05:49 |
2026-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
658
|
6.0 |
MEDIUM
Network
|
-
|
-
|
An encrypted password command injection vulnerability exists in the Captive Portal application framework of Arista Edge Threat Management - Arista Next Generation Firewall (NGFW). This issue uniquely…
|
CWE-78
OS Command
|
CVE-2026-25620
|
2026-06-6 05:48 |
2026-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
659
|
6.0 |
MEDIUM
Network
|
-
|
-
|
A Reports application infrastructure vulnerability exists in Arista Edge Threat Management - Arista Next Generation Firewall (NGFW) due to insecure input validation. This issue uniquely affects versi…
|
CWE-78
OS Command
|
CVE-2026-25621
|
2026-06-6 05:48 |
2026-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
660
|
6.0 |
MEDIUM
Network
|
-
|
-
|
A Captive Portal Custom Handler command injection vulnerability exists in Arista Edge Threat Management - Arista Next Generation Firewall (NGFW). On affected platforms, an administrative account logg…
|
CWE-78
OS Command
|
CVE-2026-25622
|
2026-06-6 05:48 |
2026-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|