|
1251
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Exposure of sensitive information to an unauthorized actor in Windows NTLM allows an unauthorized attacker to perform spoofing over a network.
New
|
CWE-200
Information Exposure
|
CVE-2026-50508
|
2026-06-10 02:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1252
|
8.8 |
HIGH
Network
|
-
|
-
|
Hermes WebUI before version 0.51.311 contains a remote code execution vulnerability that allows authenticated attackers to execute arbitrary commands by placing malicious executable Git configuration…
New
|
CWE-78
OS Command
|
CVE-2026-49959
|
2026-06-10 02:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1253
|
5.0 |
MEDIUM
Local
|
-
|
-
|
Hermes WebUI before version 0.51.303 contains a time-of-check time-of-use (TOCTOU) race condition vulnerability in the git_discard function within api/workspace_git.py that allows attackers to delete…
New
|
CWE-367
Time-of-check Time-of-use (TOCTOU) Race Condition
|
CVE-2026-49958
|
2026-06-10 02:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1254
|
5.3 |
MEDIUM
Network
|
-
|
-
|
Hermes WebUI before version 0.51.270 contains a resource exhaustion vulnerability that allows unauthenticated remote attackers to degrade service availability by repeatedly calling the passkey option…
New
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2026-49955
|
2026-06-10 02:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1255
|
7.8 |
HIGH
Local
|
-
|
-
|
Improper access control in Microsoft PC Manager allows an authorized attacker to bypass a security feature locally.
New
|
CWE-284
Improper Access Control
|
CVE-2026-49161
|
2026-06-10 02:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1256
|
9.8 |
CRITICAL
Network
|
-
|
-
|
External control of file name or path in Azure Stack Edge allows an unauthorized attacker to execute code over a network.
New
|
CWE-73
External Control of File Name or Path
|
CVE-2026-47643
|
2026-06-10 02:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1257
|
8.1 |
HIGH
Network
|
-
|
-
|
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-47631
|
2026-06-10 02:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1258
|
7.0 |
HIGH
Local
|
-
|
-
|
Use after free in Microsoft Office Click-To-Run allows an authorized attacker to elevate privileges locally.
New
|
CWE-416
Use After Free
|
CVE-2026-47293
|
2026-06-10 02:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1259
|
7.8 |
HIGH
Local
|
-
|
-
|
Inclusion of functionality from untrusted control sphere in Visual Studio Code allows an unauthorized attacker to elevate privileges locally.
New
|
CWE-94 CWE-829
Code Injection Inclusion of Functionality from Untrusted Control Sphere
|
CVE-2026-47292
|
2026-06-10 02:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1260
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Relative path traversal in Visual Studio Code allows an unauthorized attacker to perform tampering over a network.
New
|
CWE-23
Relative Path Traversal
|
CVE-2026-47287
|
2026-06-10 02:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|