|
431
|
7.4 |
HIGH
Local
|
-
|
-
|
sys/kern/sysv_sem.c in OpenBSD through 7.9 has a use-after-free allowing local privilege escalation to root. This is a context switch use-after-free after tsleep in sys_semget().
New
|
CWE-416
Use After Free
|
CVE-2026-57589
|
2026-06-26 14:16 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
432
|
7.8 |
HIGH
Local
|
vim
|
vim
|
Vim is an open source, command line text editor. Prior to 9.2.0699, Vim's Python omni-completion (runtime/autoload/python3complete.vim and the legacy pythoncomplete.vim) executes reconstructed functi…
New
|
CWE-94
Code Injection
|
CVE-2026-57456
|
2026-06-26 14:16 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
433
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Feast before 0.63.0 contains an unsafe deserialization vulnerability that allows unauthenticated or unauthorized attackers to achieve remote code execution by sending a crafted gRPC request to the re…
New
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-56121
|
2026-06-26 14:16 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
434
|
7.8 |
HIGH
Local
|
vim
|
vim
|
Vim is an open source, command line text editor. Prior to 9.2.0663, a Vimscript code injection vulnerability exists in s:NetrwLocalRmFile() in the netrw plugin (runtime/pack/dist/opt/netrw/autoload/n…
New
|
CWE-78 CWE-94
OS Command Code Injection
|
CVE-2026-55895
|
2026-06-26 14:16 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
435
|
7.4 |
HIGH
Network
|
-
|
-
|
Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.1, 8.4.4, 8.3.6, 8.2.6, 8.1.6, 8.0.7, and 7.10.13, Rocket.Chat's Apple Sign-In handler verifies JWT sig…
New
|
CWE-287 CWE-294
Improper Authentication Authentication Bypass by Capture-replay
|
CVE-2026-55759
|
2026-06-26 14:16 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
436
|
8.8 |
HIGH
Network
|
-
|
-
|
pnpm is a package manager. Prior to 10.34.2 and 11.5.3, pnpm can persist package-manager bootstrap metadata in the first YAML document of pnpm-lock.yaml. Before the patch, direct pnpm execution trust…
New
|
CWE-345 CWE-494 CWE-829
Insufficient Verification of Data Authenticity Download of Code Without Integrity Check Inclusion of Functionality from Untrusted Control Sphere
|
CVE-2026-55698
|
2026-06-26 14:16 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
437
|
7.5 |
HIGH
Network
|
-
|
-
|
pnpm is a package manager. Prior to 10.34.2 and 11.5.3, pnpm can install configDependencies declared in pnpm-workspace.yaml before command dispatch. Before the patch, a repository could declare pacqu…
New
|
CWE-78 CWE-494 CWE-829
OS Command Download of Code Without Integrity Check Inclusion of Functionality from Untrusted Control Sphere
|
CVE-2026-55697
|
2026-06-26 14:16 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
438
|
- |
|
-
|
-
|
Rocket.Chat is an open-source, secure, fully customizable communications platform. Prior to 8.5.1, 8.4.4, 8.3.6, 8.2.6, 8.1.6, 8.0.7, and 7.10.13, in apps/meteor/app/apple/server/loginHandler.ts, han…
New
|
CWE-287 CWE-288
Improper Authentication Authentication Bypass Using an Alternate Path or Channel
|
CVE-2026-55666
|
2026-06-26 14:16 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
439
|
10.0 |
CRITICAL
Network
|
-
|
-
|
Gogs is an open source self-hosted Git service. Prior to 0.14.3, organization names containing path traversal sequences (../) are accepted by Gogs, and repositories under them are written to paths fo…
New
|
CWE-23
Relative Path Traversal
|
CVE-2026-52813
|
2026-06-26 14:16 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
440
|
- |
|
-
|
-
|
Gogs is an open source self-hosted Git service. Prior to 0.14.3, (*Repository).UploadRepoFiles checks for symlinks only on the leaf of the upload target (osx.IsSymlink(targetPath)). The siblings Upda…
New
|
CWE-22 CWE-59 CWE-61
Path Traversal Link Following UNIX Symbolic Link (Symlink) Following
|
CVE-2026-52811
|
2026-06-26 14:16 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|