|
871
|
8.2 |
HIGH
Network
|
nuxt
|
nuxt
|
Nuxt is an open-source web development framework for Vue.js. From versions 3.11.0 to before 3.21.7 and 4.0.0 to before 4.4.7, there is a route-rule middleware bypass via case-sensitivity mismatch bet…
Update
|
CWE-178 CWE-863
Improper Handling of Case Sensitivity Incorrect Authorization
|
CVE-2026-53721
|
2026-06-15 11:11 |
2026-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
872
|
5.4 |
MEDIUM
Network
|
nuxt
|
nuxt
|
Nuxt is an open-source web development framework for Vue.js. Prior to versions 3.21.7 and 4.4.7, <NuxtLink> did not validate the URL scheme of values bound to its to or href props before rendering th…
Update
|
CWE-79 CWE-83
Cross-site Scripting Improper Neutralization of Script in Attributes in a Web Page
|
CVE-2026-53722
|
2026-06-15 11:10 |
2026-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
873
|
5.3 |
MEDIUM
Network
|
ironmansoftware
|
powershell_universal
|
Improper access control in Devolutions PowerShell Universal 2026.1.7 and earlier allows an unauthenticated remote attacker to obtain the OpenAPI specification of user-defined REST endpoints.
Update
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2026-8694
|
2026-06-15 11:09 |
2026-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
874
|
10.0 |
CRITICAL
Network
|
netty
|
netty
|
Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, Netty's `DnsResolveContext` insufficiently validates the ba…
Update
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2026-47691
|
2026-06-15 10:57 |
2026-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
875
|
7.5 |
HIGH
Network
|
netty
|
netty
|
Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, the RedisArrayAggregator handler permanently leaks pooled d…
Update
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2026-48006
|
2026-06-15 10:56 |
2026-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
876
|
7.5 |
HIGH
Network
|
netty
|
netty
|
Netty is a network application framework for development of protocol servers and clients. In netty-codec-http2 prior to versions 4.1.135.Final and 4.2.15.Final, the `DelegatingDecompressorFrameListen…
Update
|
CWE-400 CWE-401
Uncontrolled Resource Consumption Missing Release of Memory after Effective Lifetime
|
CVE-2026-48043
|
2026-06-15 10:56 |
2026-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
877
|
7.5 |
HIGH
Network
|
netty
|
netty
|
Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, the HAProxy PROXY protocol v2 codec in netty leaks native o…
Update
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2026-48059
|
2026-06-15 10:56 |
2026-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
878
|
5.4 |
MEDIUM
Network
|
gitlab
|
gitlab
|
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 15.10 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions could have allowed an authe…
Update
|
CWE-863
Incorrect Authorization
|
CVE-2026-6269
|
2026-06-15 10:47 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
879
|
3.1 |
LOW
Network
|
gitlab
|
gitlab
|
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 12.0 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions could have allowed an authen…
Update
|
CWE-863
Incorrect Authorization
|
CVE-2026-3553
|
2026-06-15 10:47 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
880
|
6.5 |
MEDIUM
Network
|
gitlab
|
gitlab
|
GitLab has remediated an issue in GitLab CE/EE affecting all versions from 17.10 before 18.10.8, 18.11 before 18.11.5, and 19.0 before 19.0.2 that under certain conditions could have allowed an authe…
Update
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2026-1500
|
2026-06-15 10:46 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|