|
161
|
9.8 |
CRITICAL
Network
|
anysphere
|
cursor
|
Cursor is a code editor built for programming with AI. Prior to 3.0, Cursor runs agent terminal commands in a sandbox by default, and the sandbox grants write access to the command's working director…
New
|
CWE-22
Path Traversal
|
CVE-2026-50548
|
2026-06-27 01:51 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
162
|
6.5 |
MEDIUM
Network
|
wolfssl
|
wolfssl
|
Bleichenbacher padding oracle in PKCS#7 KTRI decryption. When decrypting PKCS#7 EnvelopedData using RSA PKCS#1 v1.5 key transport, wolfSSL returned distinguishable error codes depending on whether RS…
New
|
CWE-208
Information Exposure Through Timing Discrepancy
|
CVE-2026-6291
|
2026-06-27 01:51 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
163
|
9.1 |
CRITICAL
Network
|
wolfssl
|
wolfssl
|
Heap buffer overread in wc_PKCS7_DecodeEnvelopedData when parsing crafted PKCS7 EnvelopedData. This could theoretically be triggered by attacker-supplied data delivered via S/MIME or CMS.
New
|
CWE-125
Out-of-bounds Read
|
CVE-2026-6094
|
2026-06-27 01:51 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
164
|
6.5 |
MEDIUM
Network
|
wolfssl
|
wolfssl
|
Partial-chain certificate verification may accept chains that terminate at a peer-supplied, untrusted intermediate certificate rather than a trusted anchor. An attacker could present a chain that end…
New
|
CWE-295
Improper Certificate Validation
|
CVE-2026-6091
|
2026-06-27 01:50 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
165
|
7.5 |
HIGH
Network
|
wolfssl
|
wolfssl
|
AES-GCM encryption/decryption with extremely large cumulative single message sizes (>64 GiB) were not properly rejected by the streaming APIs, allowing counter wrap, keystream reuse, and consequent p…
New
|
CWE-323
Reusing a Nonce, Key Pair in Encryption
|
CVE-2026-55967
|
2026-06-27 01:50 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
166
|
7.5 |
HIGH
Network
|
wolfssl
|
wolfssl
|
wolfSSL_PKCS7_verify() returning success for a degenerate (certs-only) PKCS#7 object that contains no signer. Such an object has empty signerInfos, so the underlying signed-data verification succeeds…
New
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2026-55961
|
2026-06-27 01:50 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
167
|
7.5 |
HIGH
Network
|
wolfssl
|
wolfssl
|
X.509 trust-chain bypass (path-depth exhaustion) in the OpenSSL compatibility certificate verifier (wolfSSL_X509_verify_cert()). This affects only builds with --enable-opensslextra whose application …
New
|
CWE-295
Improper Certificate Validation
|
CVE-2026-11999
|
2026-06-27 01:50 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
168
|
9.8 |
CRITICAL
Network
|
dest-unreach
|
socat
|
socat versions 1.8.0.0 through 1.8.1.1 contain a heap-based buffer overflow vulnerability that allows a malicious SOCKS5 proxy server to overwrite adjacent heap memory by exploiting a sign-extension …
New
|
CWE-122
Heap-based Buffer Overflow
|
CVE-2026-56123
|
2026-06-27 01:50 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
169
|
3.3 |
LOW
Local
|
tenable
|
nessus
|
A SQL injection vulnerability in Nessus allows an attacker to craft a malicious scan result file that, when imported by a privileged user, injects malicious SQL into the scan results database, potent…
New
|
CWE-89
SQL Injection
|
CVE-2026-57588
|
2026-06-27 01:48 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
170
|
5.3 |
MEDIUM
Network
|
tenable
|
nessus
|
A SQL injection vulnerability in Nessus allows a remote, unauthenticated attacker who controls reverse DNS records for a scanned host to inject malicious SQL into the scan results database, potential…
New
|
CWE-89
SQL Injection
|
CVE-2026-57587
|
2026-06-27 01:47 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|