|
1591
|
5.3 |
MEDIUM
Adjacent
|
-
|
-
|
dhcpcd through 10.3.2, fixed in commit 5733d3c, contains a heap use-after-free vulnerability that allows unauthenticated same-link attackers to crash the daemon by sending a crafted DHCPv6 RENEW repl…
|
CWE-416
Use After Free
|
CVE-2026-56113
|
2026-06-24 03:18 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1592
|
5.8 |
MEDIUM
Network
|
-
|
-
|
Guzzle is an extensible PHP HTTP client. Prior to 7.12.1, CookieJar incorrectly accepts cookies with a dot-only Domain attribute and whitespace-padded variants. SetCookie::matchesDomain() removes lea…
|
CWE-346 CWE-1286
Origin Validation Error Improper Validation of Syntactic Correctness of Input
|
CVE-2026-55767
|
2026-06-24 03:18 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1593
|
6.1 |
MEDIUM
Network
|
-
|
-
|
yt-dlp is a command-line audio/video downloader. From 2023.09.24 until 2026.06.09, if curl is used as an external downloader for yt-dlp, cookies may be leaked to an unintended host upon HTTP redirect…
|
CWE-200
Information Exposure
|
CVE-2026-50019
|
2026-06-24 03:18 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1594
|
8.8 |
HIGH
Network
|
-
|
-
|
A missing validation of user input exists when saving delivery limitations in Revive Adserver 6.0.6 and earlier. A low‑privileged user could add an unexpected component parameter and inject malicious…
|
CWE-94
Code Injection
|
CVE-2026-44959
|
2026-06-24 03:17 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1595
|
5.4 |
MEDIUM
Network
|
-
|
-
|
An access control bypass allows an advertiser‑level user to activate or deactivate a banner in Revive Adserver 6.0.6 and earlier, even when such permissions were not granted. The banner-edit.php scri…
|
CWE-284
Improper Access Control
|
CVE-2026-44958
|
2026-06-24 03:17 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1596
|
4.3 |
MEDIUM
Network
|
-
|
-
|
A missing access control check when invoking various modify methods in the XML‑RPC API of Revive Adserver 6.0.6 and earlier. The API allowed entities to be reassigned to different parent entities, le…
|
CWE-284
Improper Access Control
|
CVE-2026-44957
|
2026-06-24 03:17 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1597
|
8.8 |
HIGH
Network
|
-
|
-
|
A missing validation of user input when saving delivery limitations in Revive Adserver 6.0.6 and earlier could allow a low‑privileged user to use the logical parameter to inject malicious PHP code in…
|
CWE-94
Code Injection
|
CVE-2026-34916
|
2026-06-24 03:17 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1598
|
6.1 |
MEDIUM
Network
|
-
|
-
|
A missing sanitisation of user input in the zone-include.php script of Revive Adserver 6.0.6 and earlier could allow a low‑privileged user to exploit the clientid parameter to perform blind SQL injec…
|
CWE-79
Cross-site Scripting
|
CVE-2026-34915
|
2026-06-24 03:17 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1599
|
8.3 |
HIGH
Network
|
-
|
-
|
A missing sanitisation of user input in the zone-include.php script of Revive Adserver 6.0.6 and earlier. A low‑privileged user could exploit the clientid parameter to perform blind SQL injection att…
|
CWE-89
SQL Injection
|
CVE-2026-34914
|
2026-06-24 03:17 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1600
|
4.3 |
MEDIUM
Network
|
-
|
-
|
A missing access control check when linking trackers to campaigns through the campaign-trackers.php script of Revive Adserver 6.0.6 and earlier could allow a low‑privileged user to link their tracker…
|
CWE-284
Improper Access Control
|
CVE-2026-34913
|
2026-06-24 03:17 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|