|
581
|
4.4 |
MEDIUM
Local
|
-
|
-
|
Uncontrolled Search Path Element vulnerability in ABB Control Builder A, ABB 800xA for Advant Master.
This issue affects Control Builder A: through 1.4/4; 800xA for Advant Master: through 6.0.3-1, t…
New
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2025-13162
|
2026-06-26 05:12 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
582
|
- |
|
-
|
-
|
Improper bounds validation in EmberZNet SDK versions 9.0.2 and earlier may result in crashes or dynamic memory leakage.
New
|
CWE-130
Improper Handling of Length Parameter Inconsistency
|
CVE-2026-6432
|
2026-06-26 05:12 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
583
|
- |
|
-
|
-
|
Improper output neutralization for logs vulnerability in upKeeper Solutions upKeeper Instant Privilege Access on Windows allows Log Injection-Tampering-Forging.
This issue affects upKeeper Instant P…
New
|
CWE-117
Improper Output Neutralization for Logs
|
CVE-2026-10745
|
2026-06-26 05:11 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
584
|
- |
|
-
|
-
|
A critical vulnerability in Admin GUI in Payara Server Full 4.x, 5.x, 6.x, 7.x, 7.2026.x, 6.2025.x, 6.2024.x on All platforms that allows the attacker to leak the admin gfresttoken to an attacker-con…
New
|
CWE-352 CWE-918
Origin Validation Error Server-Side Request Forgery (SSRF)
|
CVE-2026-12986
|
2026-06-26 05:11 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
585
|
- |
|
-
|
-
|
Permissions where checked incorrectly during room creation, allowing attackers to create rooms of types they shouldn't be allowed to create.
New
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-13350
|
2026-06-26 05:11 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
586
|
10.0 |
CRITICAL
Network
|
-
|
-
|
Unrestricted Upload of File with Dangerous Type vulnerability in Daan.Dev OMGF Pro allows Using Malicious Files.
This issue affects OMGF Pro: from n/a through 5.2.6.
New
|
CWE-434
Unrestricted Upload of File with Dangerous Type
|
CVE-2026-57700
|
2026-06-26 05:11 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
587
|
6.5 |
MEDIUM
Network
|
-
|
-
|
GPAC MP4Box v2.4 was discovered to contain a NULL pointer dereference in the gf_isom_add_track_kind() function at isomedia/isom_write.c. This vulnerability allows attackers to cause a Denial of Servi…
New
|
CWE-476
NULL Pointer Dereference
|
CVE-2025-55639
|
2026-06-26 04:59 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
588
|
5.8 |
MEDIUM
Local
|
-
|
-
|
K3s is a fully conformant production-ready Kubernetes distribution. Prior to 1.35.3+k3s1, 1.34.6+k3s1, v1.33.10+k3s1, a path traversal vulnerability exists in K3s's etcd snapshot decompression functi…
New
|
CWE-22
Path Traversal
|
CVE-2026-54250
|
2026-06-26 04:59 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
589
|
8.1 |
HIGH
Network
|
-
|
-
|
An issue in Pivotal CRM v.6.6.04.08 allows a remote attacker to execute arbitrary code via the Pivotal.Core.Common.dll and Pivotal.Engine.Client.Services.Conversion.dll components.
New
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-39253
|
2026-06-26 04:58 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
590
|
- |
|
-
|
-
|
FOSSBilling is a billing and client management system that automates invoicing, payments, and communication for online service businesses. Versions 0.6.21 through 0.7.2 are vulnerable to IDOR through…
New
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2025-64105
|
2026-06-26 04:58 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|