|
2261
|
7.4 |
HIGH
Network
|
-
|
-
|
Tychon includes an OpenSSL component that specifies an OPENSSLDIR variable as a subdirectory that may be controllable by an unprivileged user on Windows. Tychon contains a privileged service that use…
|
-
|
CVE-2022-4991
|
2026-06-3 02:16 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2262
|
5.4 |
MEDIUM
Network
|
-
|
-
|
NamelessMC is website software for Minecraft servers. In versions 2.2.4 and prior, the OAuth callback handling does not validate the state parameter server-side before exchanging the authorization co…
|
CWE-302 CWE-346 CWE-352
Authentication Bypass by Assumed-Immutable Data Origin Validation Error Origin Validation Error
|
CVE-2026-34460
|
2026-06-3 02:15 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2263
|
2.7 |
LOW
Network
|
-
|
-
|
Klaw is a self-service Apache Kafka Topic Management/Governance tool/portal. Prior to version 2.10.4, a vulnerability exists in the user registration and login mechanisms due to inconsistent handling…
|
CWE-20 CWE-178
Improper Input Validation Improper Handling of Case Sensitivity
|
CVE-2026-44367
|
2026-06-3 02:15 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2264
|
- |
|
-
|
-
|
Klaw is a self-service Apache Kafka Topic Management/Governance tool/portal. Prior to version 2.10.4, improper access control allows disclosure of password hash. This issue has been patched in versio…
|
CWE-200 CWE-284
Information Exposure Improper Access Control
|
CVE-2026-45080
|
2026-06-3 02:15 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2265
|
7.5 |
HIGH
Network
|
-
|
-
|
NiceGUI is a Python-based UI framework. Prior to version 3.12.0, ui.restructured_text() renders reStructuredText server-side with Docutils without disabling file insertion directives. When a NiceGUI …
|
CWE-200
Information Exposure
|
CVE-2026-45553
|
2026-06-3 02:15 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2266
|
5.3 |
MEDIUM
Network
|
-
|
-
|
NiceGUI is a Python-based UI framework. Prior to version 3.12.0, two FastAPI routes that serve per-component static assets in NiceGUI accept a sub-path parameter that may resolve to a directory rathe…
|
CWE-248 CWE-770
Uncaught Exception Allocation of Resources Without Limits or Throttling
|
CVE-2026-45554
|
2026-06-3 02:15 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2267
|
7.5 |
HIGH
Network
|
-
|
-
|
Authentication Bypass Using an Alternate Path or Channel vulnerability in Liquid Web / StellarWP BookIt allows Password Recovery Exploitation.
This issue affects BookIt: from n/a before 2.5.4.1.
|
CWE-288
Authentication Bypass Using an Alternate Path or Channel
|
CVE-2026-40780
|
2026-06-3 02:11 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2268
|
7.1 |
HIGH
Network
|
-
|
-
|
Authentication Bypass Using an Alternate Path or Channel vulnerability in WP Swings Wallet System for WooCommerce allows Password Recovery Exploitation.
This issue affects Wallet System for WooComme…
|
CWE-288
Authentication Bypass Using an Alternate Path or Channel
|
CVE-2026-42654
|
2026-06-3 02:11 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2269
|
8.8 |
HIGH
Network
|
tanium
|
connect
|
Tanium addressed an unauthorized code execution vulnerability in Connect.
|
CWE-78
OS Command
|
CVE-2026-9208
|
2026-06-3 01:29 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2270
|
8.8 |
HIGH
Network
|
samsung
|
escargot
|
Out-of-bounds write vulnerability in Samsung Open Source Escargot allows Overflow Buffers.
This issue affects Escargot: 36f5fb58366a67b713c02f6fd985e924fcc09e31.
|
CWE-787
Out-of-bounds Write
|
CVE-2026-8915
|
2026-06-3 01:23 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|