|
3411
|
5.5 |
MEDIUM
Local
|
adobe
|
acrobat acrobat_reader
|
Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this v…
|
CWE-125
Out-of-bounds Read
|
CVE-2026-47961
|
2026-06-12 23:43 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3412
|
7.8 |
HIGH
Local
|
adobe
|
acrobat acrobat_reader
|
Acrobat Reader versions 24.001.30365, 26.001.21651 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current …
|
CWE-121
Stack-based Buffer Overflow
|
CVE-2026-47959
|
2026-06-12 23:41 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3413
|
- |
|
-
|
-
|
Rejected reason: Reserved but no longer needed.
|
-
|
CVE-2026-54102
|
2026-06-12 23:16 |
2026-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3414
|
- |
|
-
|
-
|
Rejected reason: Reserved but no longer needed.
|
-
|
CVE-2026-54101
|
2026-06-12 23:16 |
2026-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3415
|
9.9 |
CRITICAL
Network
|
-
|
-
|
Fission is an open-source, Kubernetes-native serverless framework that simplifies the deployment of functions and applications on Kubernetes. Prior to version 1.24.0, a tenant with environments.fissi…
|
CWE-250 CWE-269
Execution with Unnecessary Privileges Improper Privilege Management
|
CVE-2026-50566
|
2026-06-12 23:16 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3416
|
8.8 |
HIGH
Network
|
-
|
-
|
A privilege escalation vulnerability in Apache OFBiz allows a low-privileged authenticated user to obtain higher privileges
This issue affects Apache OFBiz: before 24.09.07.
Users are recommended…
|
CWE-285
Improper Authorization
|
CVE-2026-47342
|
2026-06-12 23:16 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3417
|
- |
|
-
|
-
|
Atril Document Viewer is the default document reader of the MATE desktop environment for Linux. A single-click remote code execution vulnerability in versions prior to 1.26.3 and 1.28.4 allows an att…
|
CWE-77 CWE-88 CWE-829
Command Injection Argument Injection Inclusion of Functionality from Untrusted Control Sphere
|
CVE-2026-46529
|
2026-06-12 23:16 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3418
|
7.0 |
HIGH
Network
|
-
|
-
|
Axios is a promise based HTTP client for the browser and Node.js. From 0.19.0 to before 0.31.1 and 1.15.2, Axios contains prototype-pollution gadgets in request config processing. If another vulnerab…
|
CWE-94 CWE-1321
Code Injection Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
|
CVE-2026-44495
|
2026-06-12 23:16 |
2026-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3419
|
7.5 |
HIGH
Network
|
vmware
|
spring_for_graphql
|
The Spring GraphQL annotation detection mechanism for @Controller data fetchers may not correctly resolve annotations on methods within type hierarchies. This can be an issue if such annotations are …
|
CWE-284
Improper Access Control
|
CVE-2026-41856
|
2026-06-12 23:14 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
3420
|
8.1 |
HIGH
Network
|
vmware
|
spring_for_graphql
|
Spring for GraphQL applications that have enabled the WebSocket transport are vulnerable to Cross-Site WebSocket Hijacking. An attacker can trick an authenticated user into visiting a malicious page,…
|
CWE-346
Origin Validation Error
|
CVE-2026-41700
|
2026-06-12 23:13 |
2026-06-11 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|