|
101
|
5.9 |
MEDIUM
Network
|
-
|
-
|
FastNetMon Community Edition through 1.2.9 contains an out-of-bounds read in the IPv4 packet parser. In src/simple_packet_parser_ng.cpp, after validating that the packet contains at least sizeof(ipv4…
New
|
CWE-125
Out-of-bounds Read
|
CVE-2026-48682
|
2026-06-5 01:28 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
102
|
7.5 |
HIGH
Network
|
-
|
-
|
An integer underflow in the BGPUpdate.DecodeFromBytes function (/bgp/bgp.go) of gobgp v4.3.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted BGP UPDATE message.
New
|
CWE-190
Integer Overflow or Wraparound
|
CVE-2026-37462
|
2026-06-5 01:28 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
103
|
6.3 |
MEDIUM
Network
|
-
|
-
|
A Cross Site Scripting vulnerability exists in the Kimi AI v1.0 web interface's 'Preview' feature. The application fails to properly sanitize or encode HTML/JavaScript payloads generated by the AI mo…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-39107
|
2026-06-5 01:28 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
104
|
- |
|
-
|
-
|
GNCC GP5 v7.1.76 was discovered to utilize a weak hashing algorithm to protect the root password, possibly allowing attackers to obtain root credentials and privileges via a bruteforce attack.
New
|
-
|
CVE-2026-36182
|
2026-06-5 01:28 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
105
|
- |
|
-
|
-
|
bacnet_stack 1.3.1 contains an Out-of-bounds Read in bacnet_tag_number_decode which allows attackers to cause a denial of service.
New
|
-
|
CVE-2026-38570
|
2026-06-5 01:28 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
106
|
9.8 |
CRITICAL
Network
|
-
|
-
|
CrowCpp Crow through v1.3.1 HTTP is vulnerable to response header injection via unvalidated response header values.
New
|
CWE-113
HTTP Response Splitting
|
CVE-2026-38967
|
2026-06-5 01:26 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
107
|
9.8 |
CRITICAL
Network
|
-
|
-
|
An OS command injection vulnerability in the app.py component of openlabs docker-wkhtmltopdf-aas up to commit 9f50579 allows attackers to execute arbitrary commands via a crafted POST request.
New
|
CWE-78
OS Command
|
CVE-2026-36576
|
2026-06-5 01:26 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
108
|
- |
|
-
|
-
|
Dovestones Softwares ADPhonebook before v4.0.1.1 is vulnerable to a Cross Site Scripting vulnerability. The /Admin/Save API allows an authenticated admin user to store malicious JavaScript payloads i…
New
|
-
|
CVE-2026-36460
|
2026-06-5 01:26 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
109
|
6.1 |
MEDIUM
Network
|
-
|
-
|
Northern.tech CFEngine Enterprise 3.24.3 before 3.24.4 and 3.27.0 before 3.27.1 allows XSS.
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-33553
|
2026-06-5 01:25 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
110
|
5.4 |
MEDIUM
Network
|
-
|
-
|
LIBPNG is a reference library for use in applications that process PNG (Portable Network Graphics) raster image files. In version 1.8.0, three inter-frame chunk discard paths in the push-mode APNG pa…
New
|
CWE-436
Interpretation Conflict
|
CVE-2026-40930
|
2026-06-5 01:23 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|