|
691
|
4.3 |
MEDIUM
Network
|
strawberry
|
strawberry_graphql
|
Strawberry GraphQL is a library for creating GraphQL APIs. In versions 0.288.4 through 0.315.3, Strawberry's bundled GraphiQL template wrote values from the GraphiQL headers editor into the browser U…
Update
|
CWE-200 CWE-201
Information Exposure Insertion of Sensitive Information Into Sent Data
|
CVE-2026-45739
|
2026-06-6 03:43 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
692
|
4.3 |
MEDIUM
Network
|
synology
|
hyper_backup
|
An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in Backup Task functionality in Synology Hyper Backup before 4.1.2-4036 allows remote authenticated use…
Update
|
CWE-22
Path Traversal
|
CVE-2024-47273
|
2026-06-6 03:32 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
693
|
4.1 |
MEDIUM
Network
|
synology
|
hyper_backup
|
An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in Backup.Repository webapi component in Synology Hyper Backup before 4.1.2-4036 allows remote authenti…
Update
|
CWE-22
Path Traversal
|
CVE-2024-47263
|
2026-06-6 03:31 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
694
|
5.9 |
MEDIUM
Network
|
synology
|
note_station_client
|
A cleartext transmission of sensitive information vulnerability in Synology Note Station Client before 2.2.4-703 allows man-in-the-middle attackers to obtain user credential.
Update
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2023-52951
|
2026-06-6 03:20 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
695
|
7.8 |
HIGH
Local
|
synology
|
hyper_backup_explorer
|
An inclusion of functionality from untrusted control sphere vulnerability in MinGW DLL component in Synology Hyper Backup Explorer before 3.0.1-0156 allows local users to execute arbitrary code via u…
Update
|
CWE-829
Inclusion of Functionality from Untrusted Control Sphere
|
CVE-2022-49042
|
2026-06-6 03:19 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
696
|
- |
|
-
|
-
|
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
New
|
-
|
CVE-2026-6209
|
2026-06-6 03:17 |
2026-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
697
|
- |
|
-
|
-
|
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
New
|
-
|
CVE-2026-6208
|
2026-06-6 03:17 |
2026-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
698
|
- |
|
-
|
-
|
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
New
|
-
|
CVE-2026-6207
|
2026-06-6 03:17 |
2026-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
699
|
8.2 |
HIGH
Network
|
-
|
-
|
TinyIce is a streaming server for audio and video. In versions 0.8.95 through 2.4.1, missing authentication on WebRTC ingest endpoint allows unauthenticated stream injection. Version 2.5.0 fixes the …
New
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2026-45327
|
2026-06-6 03:17 |
2026-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
700
|
7.5 |
HIGH
Network
|
-
|
-
|
Cloudburst Network provides network components used within Cloudburst projects. A vulnerability in versions prior to `1.0.0.CR3-20260418.124334-32` impacts publicly accessible software depending on t…
New
|
CWE-20
Improper Input Validation
|
CVE-2026-45291
|
2026-06-6 03:17 |
2026-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|