|
221
|
- |
|
-
|
-
|
An improper validation of credentials vulnerability in the CommvaultSecurityIQ integration for Cortex XSOAR and Cortex XSIAM allows an unauthenticated attacker to access and modify protected resource…
New
|
CWE-1390
Weak Authentication
|
CVE-2026-0274
|
2026-06-12 00:21 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
222
|
- |
|
-
|
-
|
An incorrect buffer size calculation in the epoch key generator in OpenVPN ovpn-dco-win version 2.0.0 through 2.8.3 allows a remote authenticated peer to trigger a heap-based buffer overflow and kern…
New
|
CWE-122 CWE-131 CWE-787
Heap-based Buffer Overflow Incorrect Calculation of Buffer Size Out-of-bounds Write
|
CVE-2026-11604
|
2026-06-12 00:21 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
223
|
9.8 |
CRITICAL
Network
|
-
|
-
|
Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management). Supported versions that are affected are 8.61 and 8.62. Easily exploit…
New
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2026-35273
|
2026-06-12 00:21 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
224
|
6.4 |
MEDIUM
Network
|
-
|
-
|
Applications that configure the WebFlowELExpressionParser are vulnerable to the use of malicious Unified EL expressions.
Affected versions:
Spring Web Flow 4.0.0; 3.0.0 through 3.0.1; 2.5.0 through …
New
|
CWE-917
Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection')
|
CVE-2026-40985
|
2026-06-12 00:21 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
225
|
4.8 |
MEDIUM
Network
|
-
|
-
|
Spring Web Flow's JavaScript RemotingHandler renders the body of an error response as HTML even when the response is not "text/html", which can result in a scripting attack in the user's browser if t…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-40986
|
2026-06-12 00:21 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
226
|
7.1 |
HIGH
Network
|
-
|
-
|
A malicious or compromised FTP/SFTP/SMB server can write arbitrary files anywhere on the client filesystem (outside the configured local-directory) with attacker-controlled content.
Affected version…
New
|
CWE-22
Path Traversal
|
CVE-2026-40987
|
2026-06-12 00:21 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
227
|
5.0 |
MEDIUM
Adjacent
|
-
|
-
|
Spring Boot's Mail auto-configuration does not enable hostname verification. Applications that set the relevant JavaMail property, such as spring.mail.properties.mail.smtp.ssl.checkserveridentity=tru…
New
|
CWE-295
Improper Certificate Validation
|
CVE-2026-40992
|
2026-06-12 00:21 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
228
|
8.2 |
HIGH
Network
|
-
|
-
|
Wss4jSecurityInterceptor initialized its BSP (WS-I Basic Security Profile) compliance flag so that inbound validation disabled WSS4J BSP enforcement on RequestData. Services that validate WS-Security…
New
|
CWE-1188
Insecure Default Initialization of Resource
|
CVE-2026-40994
|
2026-06-12 00:21 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
229
|
5.4 |
MEDIUM
Network
|
-
|
-
|
X509AuthenticationProvider could issue a fully authenticated X509AuthenticationToken when a presented certificate mapped to UserDetails, without applying Spring Security's standard account lifecycle …
New
|
CWE-287
Improper Authentication
|
CVE-2026-40995
|
2026-06-12 00:21 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
230
|
4.8 |
MEDIUM
Network
|
-
|
-
|
Wss4jSecurityInterceptor defaulted allowRSA15KeyTransportAlgorithm to true, overriding Apache WSS4J's safer default for validation RequestData. Inbound WS-Security decryption could therefore accept R…
New
|
CWE-327
Use of a Broken or Risky Cryptographic Algorithm
|
CVE-2026-40996
|
2026-06-12 00:21 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|