|
421
|
6.3 |
MEDIUM
Network
|
-
|
-
|
Appsmith’s SQL query editor’s autocomplete functionality fails to sanitize database object names before rendering them in innerHTML, allowing an authenticated Developer to inject persistent XSS by a …
New
|
-
|
CVE-2026-7299
|
2026-06-3 02:35 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
422
|
3.1 |
LOW
Network
|
-
|
-
|
HCL iReflection Third party vulnerable and outdated components issue was detected in the web application
New
|
-
|
CVE-2024-42206
|
2026-06-3 02:35 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
423
|
- |
|
-
|
-
|
transmission through 4.1.1 was found to have a clickjacking weakness in the browser-facing WebUI and RPC response paths.
New
|
-
|
CVE-2026-38978
|
2026-06-3 02:35 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
424
|
6.3 |
MEDIUM
Network
|
-
|
-
|
CZ.NIC BIRD Internet Routing Daemon through 2.19.0 contains a stack-based buffer overflow in the BGP AS_PATH mask matching implementation in nest/a-path.c. The as_path_match() function uses a fixed-s…
New
|
CWE-121
Stack-based Buffer Overflow
|
CVE-2026-49943
|
2026-06-3 02:35 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
425
|
7.4 |
HIGH
Adjacent
|
linuxfoundation
|
volcano
|
Volcano is a Kubernetes-native batch scheduling system. Prior to v1.14.2, v1.13.3, and v1.12.4, the Volcano webhook server does not enforce a size limit on incoming HTTP request bodies. Any in-cluste…
Update
|
CWE-400 CWE-770
Uncontrolled Resource Consumption Allocation of Resources Without Limits or Throttling
|
CVE-2026-44247
|
2026-06-3 02:25 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
426
|
7.3 |
HIGH
Network
|
-
|
-
|
A vulnerability was determined in DedeCMS 5.7.88. The affected element is the function TrimMsg of the file /plus/feedback.php of the component Feedback Handler. Executing a manipulation of the argume…
New
|
CWE-74 CWE-89
Injection SQL Injection
|
CVE-2026-10606
|
2026-06-3 02:19 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
427
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Spacelabs Healthcare Sentinel versions 10.5.x and higher and 11.x.x before 11.6.0 contain an unauthenticated remote code execution vulnerability through a deprecated .NET Remoting HTTP channel expose…
New
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2026-0611
|
2026-06-3 02:19 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
428
|
- |
|
-
|
-
|
TP-Link Tapo C200 v5 contains a stack-based buffer overflow flaw in RTSP authentication handling due to improper validation of Authorization header field lengths, which can be triggered by a crafted …
New
|
CWE-121
Stack-based Buffer Overflow
|
CVE-2026-1871
|
2026-06-3 02:19 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
429
|
7.8 |
HIGH
Local
|
-
|
-
|
NVIDIA NVTabular contains a vulnerability where an attacker could cause improper deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampe…
New
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-24221
|
2026-06-3 02:19 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
430
|
7.8 |
HIGH
Local
|
-
|
-
|
NVIDIA NVTabular contains a vulnerability where an attacker could cause improper deserialization of untrusted data. A successful exploit of this vulnerability might lead to code execution, data tampe…
New
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-24237
|
2026-06-3 02:19 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|