|
121
|
7.8 |
HIGH
Local
|
google
|
android
|
In approvalLevelForDomainInternal of DomainVerificationService.java, there is a possible way to hijack an arbitrary app link due to a logic error in the code. This could lead to local escalation of p…
New
|
CWE-693
Protection Mechanism Failure
|
CVE-2026-0087
|
2026-06-4 01:59 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
122
|
6.8 |
MEDIUM
Local
|
google
|
android
|
In onCreate of DisableSupervisionActivity.kt, there is a possible way to delete supervision data due to a missing null check. This could lead to local escalation of privilege with no additional execu…
New
|
CWE-269
Improper Privilege Management
|
CVE-2026-0086
|
2026-06-4 01:58 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
123
|
6.5 |
MEDIUM
Network
|
google
|
android
|
In multiple functions of ubsan_throwing_runtime.cpp, there is a possible way to cause a crash due to an integer overflow. This could lead to remote denial of service with no additional execution priv…
New
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2026-0080
|
2026-06-4 01:58 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
124
|
5.5 |
MEDIUM
Local
|
google
|
android
|
In multiple functions of ubsan_throwing_runtime.cpp, there is a possible persistent denial of service due to an integer overflow. This could lead to local denial of service with no additional executi…
New
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2026-0079
|
2026-06-4 01:57 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
125
|
7.8 |
HIGH
Local
|
google
|
android
|
In setGlobalProxy of DevicePolicyManagerService.java, there is a possible desync in persistence due to improper input validation. This could lead to local escalation of privilege with no additional e…
New
|
CWE-20
Improper Input Validation
|
CVE-2026-0078
|
2026-06-4 01:57 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
126
|
9.8 |
CRITICAL
Network
|
gitlawb
|
openclaude
|
OpenClaude is an open-source coding-agent command line interface for cloud and local model providers. Prior to version 0.5.1, the dangerouslyDisableSandbox parameter is exposed as part of the BashToo…
New
|
CWE-284 CWE-306
Improper Access Control Missing Authentication for Critical Function
|
CVE-2026-42074
|
2026-06-4 01:54 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
127
|
6.5 |
MEDIUM
Network
|
gitlawb
|
openclaude
|
OpenClaude is an open-source coding-agent command line interface for cloud and local model providers. Prior to version 0.5.1, the OpenClaude MCP authentication flow starts a temporary local HTTP serv…
New
|
CWE-352 CWE-400
Origin Validation Error Uncontrolled Resource Consumption
|
CVE-2026-42073
|
2026-06-4 01:54 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
128
|
5.4 |
MEDIUM
Network
|
shopify
|
react-router
|
React Router is a router for React. In versions 7.5.1 through 7.13.1, when using Framework Mode with pre-rendering enabled, improper neutralization of the HTTP `Location` header value can permit Cros…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-33244
|
2026-06-4 01:54 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
129
|
5.3 |
MEDIUM
Network
|
oracle
|
rest_data_services
|
Vulnerability in Oracle REST Data Services (component: Core). Supported versions that are affected are 24.2.0-26.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network ac…
Update
|
CWE-284
Improper Access Control
|
CVE-2026-46842
|
2026-06-4 01:53 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
130
|
7.5 |
HIGH
Network
|
opentelemetry
|
ebpf_instrumentation
|
OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. From version 0.7.0 to before version 0.9.0, a remotely reachable integer overflow in OBI's memcac…
New
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2026-45686
|
2026-06-4 01:52 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|