|
581
|
7.5 |
HIGH
Network
|
apache
|
fluss
|
Apache Fluss versions prior to 0.9.1 configure the Netty LengthFieldBasedFrameDecoder with Integer.MAX_VALUE as the maximum frame length, allowing unauthenticated remote attackers to exhaust JVM heap…
New
|
CWE-400 CWE-770
Uncontrolled Resource Consumption Allocation of Resources Without Limits or Throttling
|
CVE-2026-49361
|
2026-06-2 03:24 |
2026-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
582
|
8.0 |
HIGH
Network
|
openclaw
|
openclaw
|
OpenClaw before 2026.5.18 contains an authorization bypass vulnerability in QQBot native approval buttons that fails to enforce configured approver identity. Non-approver users can click approval but…
Update
|
CWE-862
Missing Authorization
|
CVE-2026-35630
|
2026-06-2 03:23 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
583
|
8.2 |
HIGH
Network
|
-
|
-
|
GuardDog is a CLI tool to identify malicious PyPI packages. From 1.0.0 to 2.9.0, the programmatic remote project scanning path rewrites attacker-controlled repository URLs using a blind string replac…
Update
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-44971
|
2026-06-2 03:23 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
584
|
6.2 |
MEDIUM
Local
|
-
|
-
|
go-ipld-prime is an implementation of the InterPlanetary Linked Data (IPLD) spec interfaces, a batteries-included codec implementations of IPLD for CBOR and JSON, and tooling for basic operations on …
Update
|
CWE-674
Uncontrolled Recursion
|
CVE-2026-42328
|
2026-06-2 03:23 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
585
|
8.8 |
HIGH
Network
|
-
|
-
|
elFinder is an open-source file manager for web, written in JavaScript using jQuery UI. Prior to 2.1.68, an authenticated SQL injection vulnerability in the elFinder MySQL volume driver (elFinderVolu…
Update
|
CWE-89
SQL Injection
|
CVE-2026-44521
|
2026-06-2 03:23 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
586
|
- |
|
-
|
-
|
Cinny is a Matrix client. Prior to 4.10.3, A remote authenticated attacker who shares a room with a victim and has permissions to create room emotes (for example in a DM) can cause the victim's clien…
Update
|
CWE-20
Improper Input Validation
|
CVE-2026-42553
|
2026-06-2 03:23 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
587
|
6.5 |
MEDIUM
Network
|
openclaw
|
openclaw
|
OpenClaw before 2026.4.29 contains an SSRF policy bypass vulnerability in browser debug and export routes that allows reuse of already-open blocked tabs. Attackers with access to these routes can byp…
Update
|
CWE-863
Incorrect Authorization
|
CVE-2026-35673
|
2026-06-2 03:23 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
588
|
5.0 |
MEDIUM
Network
|
google
|
chrome
|
Insufficient validation of untrusted input in Printing in Google Chrome prior to 148.0.7778.216 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a craft…
Update
|
CWE-20 NVD-CWE-noinfo
Improper Input Validation
|
CVE-2026-9980
|
2026-06-2 03:23 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
589
|
8.8 |
HIGH
Network
|
openclaw
|
openclaw
|
OpenClaw before 2026.5.18 contains a scope bypass vulnerability in the Gateway chat.send route that allows scoped clients to execute privileged commands. Attackers with operator.write scope can deliv…
Update
|
CWE-863
Incorrect Authorization
|
CVE-2026-35674
|
2026-06-2 03:22 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
590
|
6.5 |
MEDIUM
Network
|
google
|
chrome
|
Inappropriate implementation in Skia in Google Chrome prior to 148.0.7778.216 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chrom…
Update
|
CWE-200
Information Exposure
|
CVE-2026-9981
|
2026-06-2 03:22 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|