|
2461
|
8.2 |
HIGH
Network
|
mosaic5g
|
flexric
|
FlexRIC v2.0.0 allows a single SCTP connection to bind multiple xapp_ids by sending multiple E42_SETUP_REQUESTs. On disconnect, only the first registered xapp_id's resources are cleaned up; subsequen…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2026-37234
|
2026-06-6 05:42 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2462
|
7.8 |
HIGH
Local
|
trustedfirmware
|
op-tee
|
OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. Starting in version 3.16.0 and prior …
|
CWE-416
Use After Free
|
CVE-2026-40290
|
2026-06-6 05:20 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2463
|
- |
|
-
|
-
|
HAX CMS helps manage microsite universe with PHP or NodeJs backends. A stored cross-site scripting (XSS) vulnerability exists in versions prior to 26.0.0 due to improper sanitization of the `<video-p…
|
CWE-79 CWE-116
Cross-site Scripting Improper Encoding or Escaping of Output
|
CVE-2026-46496
|
2026-06-6 05:17 |
2026-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2464
|
- |
|
-
|
-
|
HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to version 26.0.0, the `hmacBase64()` function in the HAXcms Node.js backend contains two critical cryptographic implementat…
|
CWE-200 CWE-321 CWE-327
Information Exposure Use of Hard-coded Cryptographic Key Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2026-46395
|
2026-06-6 05:17 |
2026-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2465
|
8.7 |
HIGH
Network
|
-
|
-
|
HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to version 26.0.0 of HAX CMS PHP, the `saveFile` endpoint validates upload extensions case-insensitively and writes the file…
|
CWE-178 CWE-434
Improper Handling of Case Sensitivity Unrestricted Upload of File with Dangerous Type
|
CVE-2026-46392
|
2026-06-6 05:17 |
2026-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2466
|
4.3 |
MEDIUM
Network
|
misp
|
misp
|
A visibility control issue in the event template creation workflow allowed non-site-admin users to access private galaxies belonging to other organisations. The event template builder loaded all enab…
|
CWE-200
Information Exposure
|
CVE-2026-10854
|
2026-06-6 04:51 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2467
|
10.0 |
CRITICAL
Network
|
-
|
-
|
UDS Identity Config builds the Keycloak configuration image (realm, plugins, theme, truststore, JARs) consumed by UDS Core's Identity deployment. In versions 0.11.0 through 0.26.0, a logic error in t…
|
CWE-287 CWE-303
Improper Authentication Incorrect Implementation of Authentication Algorithm
|
CVE-2026-46389
|
2026-06-6 04:21 |
2026-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2468
|
9.8 |
CRITICAL
Network
|
-
|
-
|
The Hippoo Mobile App for WooCommerce plugin for WordPress is vulnerable to Authentication Bypass leading to Administrator Account Takeover in all versions up to and including 1.9.4. This is due to a…
|
CWE-285
Improper Authorization
|
CVE-2026-10580
|
2026-06-6 04:20 |
2026-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2469
|
8.8 |
HIGH
Network
|
-
|
-
|
The WP Captcha PRO (the premium version of the Advanced Google reCAPTCHA plugin, both have the same slug) plugin for WordPress is vulnerable to arbitrary file upload in all versions up to, and includ…
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2026-5411
|
2026-06-6 04:20 |
2026-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2470
|
8.8 |
HIGH
Network
|
-
|
-
|
The WP Captcha PRO (the premium version of the Advanced Google reCAPTCHA plugin, both have the same slug) plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and includ…
|
CWE-288
Authentication Bypass Using an Alternate Path or Channel
|
CVE-2026-5415
|
2026-06-6 04:20 |
2026-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|