|
2941
|
7.3 |
HIGH
Network
|
-
|
-
|
A vulnerability was determined in ShopXO up to 6.7.1. This vulnerability affects the function OrderClose/OrderSuccess/PayLogOrderClose/GoodsGiveIntegral of the file app/api/controller/Crontab.php of …
|
CWE-285 CWE-639
Improper Authorization Authorization Bypass Through User-Controlled Key
|
CVE-2026-12204
|
2026-06-15 11:16 |
2026-06-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2942
|
5.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was found in HKUDS AI-Trader up to 74caf996f78dcc0c657df8365c8544678a16e215. This affects an unknown part of the file /api/research/agents.csv of the component Research Export. Perfor…
|
CWE-200 CWE-284
Information Exposure Improper Access Control
|
CVE-2026-12203
|
2026-06-15 11:16 |
2026-06-15 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2943
|
7.5 |
HIGH
Network
|
netty
|
netty
|
Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, SslClientHelloHandler.decode() reads the 24-bit TLS handsha…
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2026-45416
|
2026-06-15 11:15 |
2026-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2944
|
4.0 |
MEDIUM
Local
|
netty
|
netty
|
Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, netty_unix_socket_recvFd sets msg_control to `char control[…
|
CWE-200 CWE-772
Information Exposure Missing Release of Resource after Effective Lifetime
|
CVE-2026-45536
|
2026-06-15 11:14 |
2026-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2945
|
6.8 |
MEDIUM
Network
|
netty
|
netty
|
Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, Netty's DNS resolver uses a predictable PRNG for generating…
|
CWE-330 CWE-340
Use of Insufficiently Random Values Generation of Predictable Numbers or Identifiers
|
CVE-2026-45673
|
2026-06-15 11:14 |
2026-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2946
|
10.0 |
CRITICAL
Network
|
netty
|
netty
|
Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, Netty's DnsResolveContext fails to validate the origin (bai…
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2026-45674
|
2026-06-15 11:13 |
2026-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2947
|
7.5 |
HIGH
Network
|
netty
|
netty
|
Netty is a network application framework for development of protocol servers and clients. In versions of netty-transport-sctp prior to 4.1.135.Final and 4.2.15.Final, for each non-complete SctpMessag…
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2026-46340
|
2026-06-15 11:12 |
2026-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2948
|
5.3 |
MEDIUM
Network
|
netty
|
netty
|
Netty is a network application framework for development of protocol servers and clients. Prior to versions 4.1.135.Final and 4.2.15.Final, DefaultHttp2Connection.DefaultEndpoint initialises maxActiv…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2026-47244
|
2026-06-15 11:11 |
2026-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2949
|
8.2 |
HIGH
Network
|
nuxt
|
nuxt
|
Nuxt is an open-source web development framework for Vue.js. From versions 3.11.0 to before 3.21.7 and 4.0.0 to before 4.4.7, there is a route-rule middleware bypass via case-sensitivity mismatch bet…
|
CWE-178 CWE-863
Improper Handling of Case Sensitivity Incorrect Authorization
|
CVE-2026-53721
|
2026-06-15 11:11 |
2026-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2950
|
5.4 |
MEDIUM
Network
|
nuxt
|
nuxt
|
Nuxt is an open-source web development framework for Vue.js. Prior to versions 3.21.7 and 4.4.7, <NuxtLink> did not validate the URL scheme of values bound to its to or href props before rendering th…
|
CWE-79 CWE-83
Cross-site Scripting Improper Neutralization of Script in Attributes in a Web Page
|
CVE-2026-53722
|
2026-06-15 11:10 |
2026-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|