|
1181
|
7.5 |
HIGH
Network
|
redhat
|
build_of_keycloak
|
A flaw was found in Keycloak. When a JSON Web Encryption (JWE) encrypted request object is submitted, Keycloak may incorrectly process unsigned claims if the decrypted content is raw JSON, bypassing …
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2026-9793
|
2026-06-4 03:26 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1182
|
7.5 |
HIGH
Adjacent
|
tp-link
|
tapo_l535e_firmware tapo_p300_firmware tapo_d100c_firmware
|
TP-Link has identified a vulnerability in Tapo L535E v1.0 and v3.0, Tapo P300 v1.0, and Tapo D100C v1.0, where Bluetooth communication during the initial setup phase is transmitted in cleartext witho…
|
CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2026-34126
|
2026-06-4 03:18 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1183
|
7.3 |
HIGH
Network
|
-
|
-
|
A vulnerability was identified in NousResearch hermes-agent up to 0.12.0. Affected by this vulnerability is the function _compress_context of the file run_agent.py. The manipulation leads to injectio…
|
CWE-74 CWE-707
Injection Improper Enforcement of Message or Data Structure
|
CVE-2026-10221
|
2026-06-4 03:16 |
2026-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1184
|
8.8 |
HIGH
Adjacent
|
tp-link
|
archer_c64_firmware
|
Due to improper enforcement of authentication rate-limiting on a debug SSH service in Archer C64 v1, the SSH service allows unlimited authentication attempts and uses the same credentials as the web …
|
CWE-288 CWE-306
Authentication Bypass Using an Alternate Path or Channel Missing Authentication for Critical Function
|
CVE-2026-8697
|
2026-06-4 03:14 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1185
|
5.3 |
MEDIUM
Network
|
oracle
|
rest_data_services
|
Vulnerability in Oracle REST Data Services (component: Mongoapi). Supported versions that are affected are 24.2.0-26.1.0. Easily exploitable vulnerability allows unauthenticated attacker with networ…
|
CWE-200
Information Exposure
|
CVE-2026-46830
|
2026-06-4 03:12 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1186
|
9.0 |
CRITICAL
Network
|
oracle
|
database_server
|
Vulnerability in the Net Service component of Oracle Database Server. Supported versions that are affected are 23.4.0-23.26.2. Difficult to exploit vulnerability allows unauthenticated attacker with…
|
NVD-CWE-noinfo
|
CVE-2026-46833
|
2026-06-4 03:12 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1187
|
8.1 |
HIGH
Network
|
oracle
|
rest_data_services
|
Vulnerability in Oracle REST Data Services (component: Core). Supported versions that are affected are 24.2.0-26.1.0. Easily exploitable vulnerability allows low privileged attacker with network acc…
|
CWE-400 CWE-284
Uncontrolled Resource Consumption Improper Access Control
|
CVE-2026-35277
|
2026-06-4 03:03 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1188
|
7.9 |
HIGH
Network
|
oracle
|
rest_data_services
|
Vulnerability in Oracle REST Data Services (component: Core). Supported versions that are affected are 24.2.0-26.1.0. Difficult to exploit vulnerability allows low privileged attacker with network a…
|
CWE-400 CWE-352
Uncontrolled Resource Consumption Origin Validation Error
|
CVE-2026-35266
|
2026-06-4 03:03 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1189
|
7.5 |
HIGH
Network
|
hkuds
|
deepcode
|
DeepCode through commit c991dc2 contains a path traversal vulnerability in the SPA catch-all route in new_ui/backend/main.py that allows unauthenticated attackers to read arbitrary files by supplying…
|
CWE-22
Path Traversal
|
CVE-2026-32847
|
2026-06-4 03:02 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1190
|
9.1 |
CRITICAL
Network
|
electerm_project
|
electerm
|
electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.9.5, deterministic AES-192-CBC with a fixed zero IV, constant KDF salt, and no MAC leads to confid…
|
CWE-326 CWE-329 CWE-353 CWE-759 CWE-916
Inadequate Encryption Strength Not Using a Random IV with CBC Mode Missing Support for Integrity Check Use of a One-Way Hash without a Salt Use of Password Hash With Insufficient Computational Effort
|
CVE-2026-45787
|
2026-06-4 02:56 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|