|
721
|
6.2 |
MEDIUM
Local
|
adobe
|
c2pa c2pa-web
|
CAI Content Credentials versions c2pa-web@0.7.1, c2pa-v0.80.1 and earlier are affected by an Improper Input Validation vulnerability. An attacker could exploit this vulnerability to crash the applica…
Update
|
CWE-20
Improper Input Validation
|
CVE-2026-47903
|
2026-06-16 02:42 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
722
|
6.2 |
MEDIUM
Local
|
adobe
|
c2pa c2pa-web
|
CAI Content Credentials versions c2pa-web@0.7.1, c2pa-v0.80.1 and earlier are affected by an Uncontrolled Resource Consumption vulnerability. An attacker could exploit this vulnerability to exhaust s…
Update
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2026-47905
|
2026-06-16 02:42 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
723
|
6.2 |
MEDIUM
Local
|
adobe
|
c2pa c2pa-web
|
CAI Content Credentials versions c2pa-web@0.7.1, c2pa-v0.80.1 and earlier are affected by an Uncontrolled Resource Consumption vulnerability. An attacker could exploit this vulnerability to exhaust s…
Update
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2026-47904
|
2026-06-16 02:42 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
724
|
6.5 |
MEDIUM
Network
|
mongodb
|
mongodb
|
The $_internalConvertBucketIndexStats stage used PauseExecution as a way to signal "skip this document" when an index stats conversion failed. But PauseExecution is not a general purpose skip mechani…
Update
|
CWE-617
Reachable Assertion
|
CVE-2026-9748
|
2026-06-16 02:10 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
725
|
6.5 |
MEDIUM
Network
|
mongodb
|
mongodb
|
An authenticated user can cause a MongoDB server to crash or return incorrect results by creating documents that interfere with internal metadata processing during query execution. This stems from in…
Update
|
CWE-617
Reachable Assertion
|
CVE-2026-9750
|
2026-06-16 02:10 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
726
|
7.5 |
HIGH
Network
|
image-size
|
image-size
|
image-size through 2.0.2 contains a denial of service vulnerability that allows remote attackers to permanently block the Node.js event loop by supplying a specially crafted image buffer with a zero-…
Update
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2025-71329
|
2026-06-16 02:09 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
727
|
8.8 |
HIGH
Network
|
splunk
|
splunk splunk_cloud_platform splunk_secure_gateway
|
In Splunk Enterprise versions below 10.2.4, 10.0.7, 9.4.12, and 9.3.13, Splunk Cloud Platform versions below 10.3.2512.12, 10.2.2510.14, 10.1.2507.22, and 9.3.2411.132, and Splunk Secure Gateway vers…
Update
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-20251
|
2026-06-16 02:08 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
728
|
7.5 |
HIGH
Network
|
image-size
|
image-size
|
image-size through 2.0.2 contains a denial of service vulnerability that allows remote attackers to permanently block the Node.js event loop by supplying a specially crafted ICNS image buffer. Attack…
Update
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2025-71330
|
2026-06-16 02:00 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
729
|
6.5 |
MEDIUM
Network
|
mongodb
|
mongodb
|
Adding fromRouter:true and runtimeConstants.userRoles could cause aggregations to crash mongodb server.
Update
|
CWE-617
Reachable Assertion
|
CVE-2026-9747
|
2026-06-16 01:58 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
730
|
6.5 |
MEDIUM
Network
|
mongodb
|
mongodb
|
In MongoDB Server 8.0, an aggregation stage can leave its _subPipeline field null during processing of certain pipelines. If a getMore is subsequently issued on the same cursor, the server may derefe…
Update
|
CWE-476
NULL Pointer Dereference
|
CVE-2026-9743
|
2026-06-16 01:56 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|