|
721
|
7.5 |
HIGH
Network
|
-
|
-
|
NiceGUI is a Python-based UI framework. Prior to version 3.12.0, ui.restructured_text() renders reStructuredText server-side with Docutils without disabling file insertion directives. When a NiceGUI …
New
|
CWE-200
Information Exposure
|
CVE-2026-45553
|
2026-06-3 02:15 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
722
|
5.3 |
MEDIUM
Network
|
-
|
-
|
NiceGUI is a Python-based UI framework. Prior to version 3.12.0, two FastAPI routes that serve per-component static assets in NiceGUI accept a sub-path parameter that may resolve to a directory rathe…
New
|
CWE-248 CWE-770
Uncaught Exception Allocation of Resources Without Limits or Throttling
|
CVE-2026-45554
|
2026-06-3 02:15 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
723
|
- |
|
-
|
-
|
The Bitdefender Napoca bare-metal hypervisor contains an out-of-bounds write vulnerability in the real-mode hook handler, implemented in napoca/kernel/handler.c. The handler uses a guest-controlled S…
New
|
CWE-787
Out-of-bounds Write
|
CVE-2026-10047
|
2026-06-3 02:14 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
724
|
- |
|
-
|
-
|
Bitdefender Napoca bare-metal hypervisor contains an out-of-bounds write vulnerability in the BIOS INT 0x15 / E820 memory map handler, implemented in napoca/guests/bios_handlers.c. The handler comput…
New
|
CWE-787
Out-of-bounds Write
|
CVE-2026-10046
|
2026-06-3 02:14 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
725
|
7.5 |
HIGH
Network
|
-
|
-
|
Authentication Bypass Using an Alternate Path or Channel vulnerability in Liquid Web / StellarWP BookIt allows Password Recovery Exploitation.
This issue affects BookIt: from n/a before 2.5.4.1.
New
|
CWE-288
Authentication Bypass Using an Alternate Path or Channel
|
CVE-2026-40780
|
2026-06-3 02:11 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
726
|
7.1 |
HIGH
Network
|
-
|
-
|
Authentication Bypass Using an Alternate Path or Channel vulnerability in WP Swings Wallet System for WooCommerce allows Password Recovery Exploitation.
This issue affects Wallet System for WooComme…
New
|
CWE-288
Authentication Bypass Using an Alternate Path or Channel
|
CVE-2026-42654
|
2026-06-3 02:11 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
727
|
8.8 |
HIGH
Network
|
tanium
|
connect
|
Tanium addressed an unauthorized code execution vulnerability in Connect.
Update
|
CWE-78
OS Command
|
CVE-2026-9208
|
2026-06-3 01:29 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
728
|
8.8 |
HIGH
Network
|
samsung
|
escargot
|
Out-of-bounds write vulnerability in Samsung Open Source Escargot allows Overflow Buffers.
This issue affects Escargot: 36f5fb58366a67b713c02f6fd985e924fcc09e31.
Update
|
CWE-787
Out-of-bounds Write
|
CVE-2026-8915
|
2026-06-3 01:23 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
729
|
8.2 |
HIGH
Network
|
-
|
-
|
A flaw was found in libgnutls. A remote attacker, by sending an extremely short premaster secret during an RSA key exchange to a server using an RSA key backed by a PKCS#11 token, could trigger a sho…
Update
|
CWE-1284
Improper Validation of Specified Quantity in Input
|
CVE-2026-5260
|
2026-06-3 01:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
730
|
4.3 |
MEDIUM
Network
|
-
|
-
|
Thor Vector Graphics (ThorVG) is a production-ready vector graphics engine. Prior to version 1.0.5, a null pointer dereference in SvgLoader::run() allows any caller that passes untrusted SVG data to …
New
|
CWE-476
NULL Pointer Dereference
|
CVE-2026-45729
|
2026-06-3 01:16 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|