|
501
|
7.5 |
HIGH
Network
|
nlnetlabs
|
nsd
|
When a provide-xfr is given with a tls-auth-name, a secondary requesting a transfer should provide a client certificate with that name. However, no client certificate is needed when the request comes…
New
|
CWE-284 CWE-306
Improper Access Control Missing Authentication for Critical Function
|
CVE-2026-12490
|
2026-06-26 11:08 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
502
|
8.1 |
HIGH
Network
|
nlnetlabs
|
nsd
|
NSD version 4.14.0 introduced a bug where a specially crafted APL RR, with an adflength larger than permitted for the address family will overwrite the stack when the zone is written to disk, with a …
New
|
CWE-20 CWE-120
Improper Input Validation Classic Buffer Overflow
|
CVE-2026-12246
|
2026-06-26 11:07 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
503
|
7.5 |
HIGH
Network
|
nlnetlabs
|
nsd
|
NSD from version 4.13.0 has a heap use-after-free bug in logging errors on TLS connections, causing a crash of the server process, which can be triggered trivially by sending a DNS query over a DoT c…
New
|
CWE-416
Use After Free
|
CVE-2026-12245
|
2026-06-26 11:07 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
504
|
8.8 |
HIGH
Network
|
nlnetlabs
|
nsd
|
If NSD is configured as secondary for a zone, the primary of that zone can crash NSD with an AXFR containing a DNS message with a special crafted SVCB RR with an rdata size of 65512, that let's an (u…
New
|
CWE-122 CWE-190
Heap-based Buffer Overflow Integer Overflow or Wraparound
|
CVE-2026-12244
|
2026-06-26 11:07 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
505
|
8.8 |
HIGH
Network
|
quest
|
netvault_backup
|
Quest NetVault Backup NVBURASDevice SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Quest NetVault…
New
|
CWE-89
SQL Injection
|
CVE-2026-9781
|
2026-06-26 11:04 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
506
|
8.8 |
HIGH
Network
|
quest
|
netvault_backup
|
Quest NetVault Backup addclient3 Cross-Site Scripting Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of Quest NetVa…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-9780
|
2026-06-26 11:04 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
507
|
8.8 |
HIGH
Network
|
quest
|
netvault_backup
|
Quest NetVault Backup NVBUDashboard SQL Injection Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Quest NetVault…
New
|
CWE-89
SQL Injection
|
CVE-2026-7570
|
2026-06-26 11:03 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
508
|
4.3 |
MEDIUM
Network
|
jenkins
|
contrast_continuous_application_security
|
Missing permission checks in Jenkins Contrast Continuous Application Security Plugin 3.11 and earlier allow attackers with Overall/Read permission to enumerate the names of configured Contrast metada…
New
|
CWE-862
Missing Authorization
|
CVE-2026-57299
|
2026-06-26 11:03 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
509
|
4.3 |
MEDIUM
Network
|
jenkins
|
contrast_continuous_application_security
|
A missing permission check in Jenkins Contrast Continuous Application Security Plugin 3.11 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL using an a…
New
|
CWE-862
Missing Authorization
|
CVE-2026-57297
|
2026-06-26 11:02 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
510
|
5.4 |
MEDIUM
Network
|
n8n
|
n8n
|
n8n before 1.123.25 (1.x) and before 2.11.2 (2.x), with the fix also included in 2.12.0, contains a stored cross-site scripting vulnerability in the Form Trigger node's CSS sanitization that allows a…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-56358
|
2026-06-26 11:02 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|