|
2271
|
- |
|
-
|
-
|
An Improper Authentication vulnerability in the /api/Cdn/GetFile endpoint of linqi allows unauthenticated, remote attackers to bypass file access controls. The ValidateAnonFileAccess function incorre…
|
CWE-287
Improper Authentication
|
CVE-2026-11345
|
2026-06-6 01:07 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2272
|
- |
|
-
|
-
|
A Server-Side Request Forgery (SSRF) vulnerability in the custom process creation feature of linqi allows an authenticated attacker to probe internal network components. By crafting a specific proces…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-11346
|
2026-06-6 01:07 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2273
|
- |
|
-
|
-
|
The Comment API (GET /api/Comment and POST /api/Comment) in the affected application fails to perform authorization checks to verify that the requesting user has access to the object identified by th…
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-11369
|
2026-06-6 01:07 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2274
|
- |
|
-
|
-
|
An integer underflow in bt_mesh_sol_recv() in the Bluetooth Mesh solicitation handling (subsys/bluetooth/mesh/solicitation.c) leads to an out-of-bounds write. When CONFIG_BT_MESH_OD_PRIV_PROXY_SRV is…
|
CWE-787
Out-of-bounds Write
|
CVE-2026-5589
|
2026-06-6 01:06 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2275
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A potential out-of-bounds write/read exists in the TLS socket connect path of the network sockets subsystem (subsys/net/lib/sockets/sockets_tls.c). When the TLS session cache is enabled, tls_session_…
|
CWE-787
Out-of-bounds Write
|
CVE-2026-5066
|
2026-06-6 01:06 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2276
|
4.5 |
MEDIUM
Local
|
-
|
-
|
In Mimecast Incydr before 2.6.0, arbitrary file access can occur.
|
CWE-732
Incorrect Permission Assignment for Critical Resource
|
CVE-2026-50590
|
2026-06-6 01:06 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2277
|
7.3 |
HIGH
Local
|
-
|
-
|
Graphite before 1.3.15 has an integer underflow and resultant out-of-bounds write via Graphite actions, because slotat does not ensure that an offset is within the allowed slot-map range.
|
CWE-191
Integer Underflow (Wrap or Wraparound)
|
CVE-2026-50593
|
2026-06-6 01:06 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2278
|
6.3 |
MEDIUM
Local
|
-
|
-
|
NAVTOR NavBox through version 4.16.1.20 contains hard-coded credentials within its Windows Communication Foundation (SOAP) implementation. If the SOAP functionality is enabled, a local attacker can e…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2026-21404
|
2026-06-6 01:05 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2279
|
- |
|
-
|
-
|
A vulnerability in the JCE editor extension for Joomla allows the creation of new editor profiles for unauthenticated users, ultimately resulting in PHP code upload and execution.
|
CWE-284
Improper Access Control
|
CVE-2026-48907
|
2026-06-6 01:05 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2280
|
6.3 |
MEDIUM
Network
|
-
|
-
|
Cross Site Scripting (XSS) vulnerability in the "Task in Progress / Recent" page in Arket Globe Document Intelligence 5.0.0.559 due to improper sanitization of user input in text fields when creating…
|
CWE-79
Cross-site Scripting
|
CVE-2025-65640
|
2026-06-6 01:04 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|