|
661
|
7.5 |
HIGH
Network
|
microsoft
|
remote_desktop_client windows_app windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows…
|
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
Update
|
CWE-122
Heap-based Buffer Overflow
|
CVE-2026-44799
|
2026-06-16 05:04 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
662
|
5.3 |
MEDIUM
Network
|
vmware
|
spring_framework
|
Spring MVC and WebFlux applications are vulnerable to Multipart request smuggling attacks.
Affected versions:
Spring Framework 7.0.0 through 7.0.7; 6.2.0 through 6.2.18; 6.1.0 through 6.1.27; 5.3.0 …
Update
|
CWE-444
HTTP Request Smuggling
|
CVE-2026-41853
|
2026-06-16 04:50 |
2026-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
663
|
6.1 |
MEDIUM
Network
|
microsoft
|
exchange_server exchange_server_subscription_edition
|
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.
Update
|
CWE-918 CWE-79
Server-Side Request Forgery (SSRF) Cross-site Scripting
|
CVE-2026-45501
|
2026-06-16 04:27 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
664
|
5.0 |
MEDIUM
Network
|
microsoft
|
exchange_server exchange_server_subscription_edition
|
Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to disclose information over a network.
Update
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-45502
|
2026-06-16 04:24 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
665
|
6.5 |
MEDIUM
Network
|
microsoft
|
exchange_server exchange_server_subscription_edition
|
Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to disclose information over a network.
Update
|
CWE-285 CWE-918
Improper Authorization Server-Side Request Forgery (SSRF)
|
CVE-2026-45503
|
2026-06-16 04:23 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
666
|
8.8 |
HIGH
Network
|
microsoft
|
exchange_server exchange_server_subscription_edition
|
Server-side request forgery (ssrf) in Microsoft Exchange Server allows an authorized attacker to elevate privileges over a network.
Update
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-45504
|
2026-06-16 04:20 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
667
|
6.5 |
MEDIUM
Network
|
vmware
|
spring_framework
|
Due to incorrect host parsing, applications that rely on UriComponentsBuilder to parse and validate an externally provided URL string may be exposed to a server-side request forgery (SSRF) attack.
A…
Update
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-41854
|
2026-06-16 04:10 |
2026-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
668
|
5.4 |
MEDIUM
Network
|
vmware
|
aria_operations cloud_foundation telco_cloud_platform
|
VMware Cloud Foundation Operations contains multiple stored cross-site scripting vulnerabilities.A malicious actor with privileges to create policies, views or text-widgets may be able to inject scri…
Update
|
CWE-79
Cross-site Scripting
|
CVE-2026-41724
|
2026-06-16 03:50 |
2026-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
669
|
6.5 |
MEDIUM
Network
|
redhat
|
directory_server 389_directory_server enterprise_linux
|
A flaw was found in 389 Directory Server. The Content Synchronization persistent search plugin allows unbounded memory growth when an authenticated client stops reading sync responses, enabling denia…
Update
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2026-11611
|
2026-06-16 03:41 |
2026-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
670
|
4.9 |
MEDIUM
Network
|
redhat
|
389_directory_server
|
A stack buffer overflow flaw was found in 389 Directory Server. The checkPrefix() function in pw.c copies an attacker-controlled algorithm ID into a 256-byte stack buffer without bounds checking when…
Update
|
CWE-121
Stack-based Buffer Overflow
|
CVE-2026-11793
|
2026-06-16 03:34 |
2026-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|