|
1801
|
4.3 |
MEDIUM
Network
|
-
|
-
|
A weakness has been identified in kortix-ai suna up to 0.8.38. Affected by this issue is the function router.replace/router.push of the file apps/frontend/src/app/auth/page.tsx of the component Auth …
|
CWE-79 CWE-94
Cross-site Scripting Code Injection
|
CVE-2026-12811
|
2026-06-23 23:17 |
2026-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1802
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A flaw has been found in OFFIS DCMTK up to 3.7.0. The affected element is the function XMLNode::parseFile in the library ofstd/libsrc/ofxml.cc. Executing a manipulation can lead to heap-based buffer …
|
CWE-119 CWE-122
Incorrect Access of Indexable Resource ('Range Error') Heap-based Buffer Overflow
|
CVE-2026-12805
|
2026-06-23 23:17 |
2026-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1803
|
7.2 |
HIGH
Network
|
misp-project
|
misp
|
MISP allowed an authenticated site administrator to set the Kafka_rdkafka_config setting to an arbitrary filesystem path. MISP subsequently parsed the referenced INI file and passed its options to rd…
|
CWE-829
Inclusion of Functionality from Untrusted Control Sphere
|
CVE-2026-56447
|
2026-06-23 23:16 |
2026-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1804
|
6.5 |
MEDIUM
Network
|
-
|
-
|
A TraceQL query in Grafana Tempo with a large exemplars hint value can cause the Tempo instance to allocate an excessive amount of memory, resulting in an out-of-memory crash. This could allow an aut…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2026-27878
|
2026-06-23 22:16 |
2026-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1805
|
- |
|
-
|
-
|
An insecure process execution vulnerability exists in the pc-printer-updater.exe component of the PaperCut Print Deploy Client for Windows. The application, which typically operates with high-level s…
|
CWE-427
Uncontrolled Search Path Element
|
CVE-2026-6645
|
2026-06-23 14:17 |
2026-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1806
|
8.3 |
HIGH
Adjacent
|
-
|
-
|
A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. WMCO establishes SSH connections to Windows worker nodes without verifying the remote server h…
|
CWE-295
Improper Certificate Validation
|
CVE-2026-54100
|
2026-06-23 14:17 |
2026-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1807
|
8.8 |
HIGH
Local
|
-
|
-
|
A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. The WICD CSR auto-approver validates that a Certificate Signing Request contains the organizat…
|
CWE-269
Improper Privilege Management
|
CVE-2026-54099
|
2026-06-23 14:17 |
2026-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1808
|
9.0 |
CRITICAL
Network
|
-
|
-
|
Two state-mutating endpoints in pgAdmin 4's SQL Editor blueprint -- DELETE /sqleditor/close/<trans_id> and POST /sqleditor/initialize/sqleditor/update_connection/<sgid>/<sid>/<did> -- were the only r…
|
CWE-306 CWE-502
Missing Authentication for Critical Function Deserialization of Untrusted Data
|
CVE-2026-12046
|
2026-06-23 14:17 |
2026-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1809
|
9.0 |
CRITICAL
Network
|
-
|
-
|
Read-only transaction bypass in the pgAdmin 4 AI Assistant allows an attacker who can influence database content that the assistant reads to execute arbitrary SQL with the privileges of the pgAdmin u…
|
CWE-77 CWE-89
Command Injection SQL Injection
|
CVE-2026-12045
|
2026-06-23 14:17 |
2026-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1810
|
- |
|
-
|
-
|
A command
injection vulnerability has been identified in the DHCP option processing logic
in multiple TP-Link router models, due to insufficient validation of externally
supplied DHCP option data. An…
|
CWE-78
OS Command
|
CVE-2026-11834
|
2026-06-23 14:17 |
2026-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|