|
1141
|
4.3 |
MEDIUM
Network
|
apache
|
activemq activemq_broker
|
Incomplete authorization by Apache ActiveMQ server before versions v6.2.6 and v5.19.7 allows authenticated connections to remove existing destinations with proper permissions.
This issue affects Apa…
New
|
CWE-285
Improper Authorization
|
CVE-2026-46605
|
2026-06-2 02:07 |
2026-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1142
|
7.5 |
HIGH
Network
|
-
|
-
|
CORS misconfiguration in the REST API of Network Optix Nx Witness VMS before version 6.1.2, when running in the default Standard security mode, on Linux and Windows allows an unauthenticated remote a…
Update
|
CWE-942
Permissive Cross-domain Policy with Untrusted Domains
|
CVE-2026-10056
|
2026-06-2 02:06 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1143
|
9.1 |
CRITICAL
Network
|
-
|
-
|
There is an authentication bypass vulnerability in the NI SystemLink Enterprise Dashboard application that may allow an unauthenticated remote attacker to bypass authentication controls leading to pr…
Update
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2026-9051
|
2026-06-2 02:06 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1144
|
5.4 |
MEDIUM
Network
|
-
|
-
|
Firefox for iOS Reader View replaced page content in its HTML template before replacing other internal placeholders. A malicious page could include a placeholder string that was later substituted wit…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-9308
|
2026-06-2 02:06 |
2026-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1145
|
5.4 |
MEDIUM
Network
|
-
|
-
|
Firefox for iOS Reader View did not properly escape HTML tags in JSON-LD metadata. A malicious page could inject markup that changed Reader View behavior and leaked sensitive URL parameters. These pa…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-9309
|
2026-06-2 02:06 |
2026-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1146
|
3.1 |
LOW
Network
|
apache
|
airflow
|
The structure_data endpoint in the Airflow UI returned external dependency graph nodes for linked Dags without checking whether the caller had read permission on those linked Dags. An authenticated U…
New
|
CWE-285
Improper Authorization
|
CVE-2026-40963
|
2026-06-2 02:06 |
2026-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1147
|
6.1 |
MEDIUM
Network
|
apache
|
activemq activemq_web
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache ActiveMQ, Apache ActiveMQ Web.
The MessageServlet in the ActiveMQ web console API copies …
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-42253
|
2026-06-2 02:06 |
2026-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1148
|
6.5 |
MEDIUM
Network
|
apache
|
airflow
|
A bug in Apache Airflow's rendered-template field handling caused nested sensitive-key masking (e.g. nested `password` / `token` / `secret` / `api_key` keys inside a JSON template structure) to be by…
New
|
CWE-200
Information Exposure
|
CVE-2026-42360
|
2026-06-2 02:06 |
2026-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1149
|
8.1 |
HIGH
Network
|
apache
|
activemq activemq_broker
|
Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ.
Apache ActiveMQ Classic exposes th…
New
|
CWE-20 CWE-94
Improper Input Validation Code Injection
|
CVE-2026-42588
|
2026-06-2 02:06 |
2026-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1150
|
5.8 |
MEDIUM
Network
|
-
|
-
|
A flaw was found in Clair. The fetcher component makes outbound HTTP requests to attacker-supplied URIs from manifest layer descriptors without IP or scheme filtering. When PSK authentication is not …
New
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-10517
|
2026-06-2 01:57 |
2026-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|