|
691
|
5.0 |
MEDIUM
Network
|
flowiseai
|
flowise
|
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, a mass assignment vulnerability exists in the tool update endpoint of FlowiseAI. The e…
Update
|
CWE-284 CWE-639 CWE-915
Improper Access Control Authorization Bypass Through User-Controlled Key Improperly Controlled Modification of Dynamically-Determined Object Attributes
|
CVE-2026-42862
|
2026-06-11 12:56 |
2026-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
692
|
9.6 |
CRITICAL
Network
|
flowiseai
|
flowise
|
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, a mass assignment vulnerability exists in the variable update endpoint of FlowiseAI. T…
Update
|
CWE-284 CWE-639 CWE-915
Improper Access Control Authorization Bypass Through User-Controlled Key Improperly Controlled Modification of Dynamically-Determined Object Attributes
|
CVE-2026-42861
|
2026-06-11 12:53 |
2026-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
693
|
5.4 |
MEDIUM
Network
|
microsoft
|
sharepoint_server
|
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-45468
|
2026-06-11 11:43 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
694
|
7.5 |
HIGH
Network
|
-
|
-
|
Race in V8 in Google Chrome prior to 144.0.7559.99 allowed a remote attacker to potentially exploit type confusion via a crafted HTML page. (Chromium security severity: High)
New
|
CWE-362
Race Condition
|
CVE-2026-1220
|
2026-06-11 07:16 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
695
|
4.3 |
MEDIUM
Network
|
buffalo
|
open_xdmod
|
OpenXDMoD is an open framework for collecting and analyzing HPC metrics. Prior to version 11.0.3, a flaw in Open XDMoD's access control logic allows an attacker to submit a crafted HTTPS POST request…
Update
|
CWE-284 NVD-CWE-noinfo
Improper Access Control
|
CVE-2026-45776
|
2026-06-11 06:07 |
2026-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
696
|
9.8 |
CRITICAL
Network
|
buffalo
|
open_xdmod
|
OpenXDMoD is an open framework for collecting and analyzing HPC metrics. Starting in version 9.5.0 and prior to version 11.0.3, an attacker can remotely execute arbitrary system commands on the web s…
Update
|
CWE-78
OS Command
|
CVE-2026-45777
|
2026-06-11 06:06 |
2026-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
697
|
5.4 |
MEDIUM
Network
|
buffalo
|
open_xdmod
|
OpenXDMoD is an open framework for collecting and analyzing HPC metrics. Prior to version 11.0.3, an authenticated attacker can inject malicious JavaScript into their Open XDMoD user profile and abus…
Update
|
CWE-79
Cross-site Scripting
|
CVE-2026-45778
|
2026-06-11 06:05 |
2026-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
698
|
9.8 |
CRITICAL
Network
|
buffalo
|
open_xdmod
|
OpenXDMoD is an open framework for collecting and analyzing HPC metrics. An SQL injection vulnerability exists in Open XDMoD versions prior to 10.0.3 that allows an unauthenticated remote attacker to…
Update
|
CWE-89
SQL Injection
|
CVE-2026-45779
|
2026-06-11 06:04 |
2026-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
699
|
6.8 |
MEDIUM
Physics
|
microsoft
|
windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2012 windows_server_2016 w…
|
Protection mechanism failure in Windows BitLocker allows an unauthorized attacker to bypass a security feature with a physical attack.
New
|
CWE-284 NVD-CWE-noinfo
Improper Access Control
|
CVE-2026-45658
|
2026-06-11 05:59 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
700
|
- |
|
-
|
-
|
A vulnerability allowing remote code execution (RCE) on the Backup Server by an authenticated domain user.
New
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-44963
|
2026-06-11 05:58 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|