|
331
|
- |
|
-
|
-
|
Svelte is a performance oriented web framework. Prior to version 5.55.7, when using spread syntax to render attributes from untrusted data, event handler properties are included in the rendered HTML …
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-42599
|
2026-06-10 02:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
332
|
- |
|
-
|
-
|
Svelte is a performance oriented web framework. Prior to version 5.55.7, Svelte was vulnerable to DOM clobbering of its internal framework state on elements, potentially leading to XSS attacks. This …
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-42573
|
2026-06-10 02:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
333
|
7.5 |
HIGH
Network
|
-
|
-
|
Svelte devalue is a JavaScript library that serializes values into strings when JSON.stringify isn't sufficient for the job. From version 5.6.3 to before version 5.8.1, devalue.parse could, due to qu…
New
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2026-42570
|
2026-06-10 02:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
334
|
- |
|
-
|
-
|
Svelte is a performance oriented web framework. From version 5.51.5 to before version 5.55.7, an internal regex in the Svelte runtime can take exponential time to test in <svelte:element this={tag}><…
New
|
CWE-1333
Inefficient Regular Expression Complexity
|
CVE-2026-42567
|
2026-06-10 02:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
335
|
7.0 |
HIGH
Local
|
-
|
-
|
Heap-based buffer overflow in Microsoft Windows DNS allows an authorized attacker to elevate privileges locally.
New
|
CWE-122
Heap-based Buffer Overflow
|
CVE-2026-41108
|
2026-06-10 02:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
336
|
8.4 |
HIGH
Network
|
-
|
-
|
Improper neutralization of input during web page generation ('cross-site scripting') in Azure Stack Edge allows an authorized attacker to perform spoofing over a network.
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-41098
|
2026-06-10 02:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
337
|
7.8 |
HIGH
Local
|
-
|
-
|
Improper access control in Microsoft Kinect allows an authorized attacker to elevate privileges locally.
New
|
CWE-284
Improper Access Control
|
CVE-2026-41092
|
2026-06-10 02:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
338
|
7.8 |
HIGH
Local
|
-
|
-
|
Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability
New
|
CWE-197
Numeric Truncation Error
|
CVE-2026-40409
|
2026-06-10 02:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
339
|
7.8 |
HIGH
Local
|
-
|
-
|
Windows Universal Disk Format File System Driver (UDFS) Elevation of Privilege Vulnerability
New
|
CWE-122 CWE-197
Heap-based Buffer Overflow Numeric Truncation Error
|
CVE-2026-40404
|
2026-06-10 02:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
340
|
7.5 |
HIGH
Network
|
-
|
-
|
Improper input validation in Visual Studio Code allows an unauthorized attacker to elevate privileges over a network.
New
|
CWE-20
Improper Input Validation
|
CVE-2026-40376
|
2026-06-10 02:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|