|
631
|
6.5 |
MEDIUM
Network
|
-
|
-
|
An improper neutralization of active SVG content in OTRS or ((OTRS)) Community Edition ticket article rendering allows attackers to inject specially crafted SVG payloads via email content, leading to…
New
|
CWE-400 CWE-791
Uncontrolled Resource Consumption Incomplete Filtering of Special Elements
|
CVE-2026-48208
|
2026-06-2 03:12 |
2026-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
632
|
7.1 |
HIGH
Network
|
-
|
-
|
An improper neutralization of user-controllable input in OTRS or ((OTRS)) Community Edition ticket handling allows authenticated attackers to perform reflected cross-site scripting (XSS) attacks via …
New
|
CWE-79 CWE-116
Cross-site Scripting Improper Encoding or Escaping of Output
|
CVE-2026-48209
|
2026-06-2 03:12 |
2026-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
633
|
7.8 |
HIGH
Local
|
-
|
-
|
A flaw was found in Poppler's Splash backend. A remote attacker could exploit this vulnerability by crafting a malicious PDF file that, when rendered, triggers an integer overflow in the `tilingPatte…
New
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2026-10118
|
2026-06-2 03:12 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
634
|
8.0 |
HIGH
Adjacent
|
mediatek
|
mt6890_firmware mt7615_firmware mt7915_firmware mt7916_firmware mt7981_firmware mt7986_firmware mt7990_firmware mt7992_firmware mt7993_firmware
|
In wlan AP driver, there is a possible memory corruption due to a heap buffer overflow. This could lead to remote (proximal/adjacent) code execution with User execution privileges needed. User intera…
New
|
CWE-122
Heap-based Buffer Overflow
|
CVE-2026-20452
|
2026-06-2 03:12 |
2026-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
635
|
6.7 |
MEDIUM
Local
|
mediatek
|
mt6739_firmware mt6761_firmware mt6765_firmware mt6768_firmware mt6781_firmware mt6789_firmware mt6835_firmware mt6853_firmware mt6855_firmware mt6877_firmware mt6878_fi…
|
In geniezone, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. U…
New
|
CWE-787
Out-of-bounds Write
|
CVE-2026-20453
|
2026-06-2 03:11 |
2026-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
636
|
- |
|
-
|
-
|
A critical Remote Code Execution (RCE) vulnerability exists in Disig Web Signer versions 2.0.3 through 2.5.3.
New
|
CWE-94
Code Injection
|
CVE-2026-8931
|
2026-06-2 03:09 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
637
|
6.4 |
MEDIUM
Local
|
mediatek
|
mt6739_firmware mt6761_firmware mt6765_firmware mt6768_firmware mt6781_firmware mt6789_firmware mt6835_firmware mt6853_firmware mt6855_firmware mt6877_firmware mt6878_fi…
|
In geniezone, there is a possible out of bounds write due to a race condition. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User in…
New
|
CWE-367
Time-of-check Time-of-use (TOCTOU) Race Condition
|
CVE-2026-20454
|
2026-06-2 03:09 |
2026-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
638
|
7.3 |
HIGH
Network
|
-
|
-
|
picoclaw <=v0.1.2 and earlier is vulnerable to OS command injection via the ExecTool component (pkg/tools/shell.go). The guardCommand() function attempts to restrict shell command execution using a d…
Update
|
CWE-78
OS Command
|
CVE-2026-36045
|
2026-06-2 03:09 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
639
|
4.3 |
MEDIUM
Network
|
-
|
-
|
A NULL pointer dereference in GPAC MP4Box: when parsing certain truncated MP4 files, an unknown/invalid stsd entry can result in missing descriptor fields (e.g., codec/mime/profile strings). gf_media…
Update
|
CWE-476
NULL Pointer Dereference
|
CVE-2025-70116
|
2026-06-2 03:09 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
640
|
5.3 |
MEDIUM
Network
|
-
|
-
|
Northern.tech Mender Client 5 before 5.0.4 allows a Cryptographic signature verification bypass.
Update
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2025-67903
|
2026-06-2 03:09 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|