|
1511
|
4.3 |
MEDIUM
Adjacent
|
-
|
-
|
Dräger Infinity Delta, Delta XL, and Kappa patient monitors contain an information disclosure vulnerability that allows unauthenticated network attackers to access log files over a network connection…
|
CWE-538
File and Directory Information Exposure
|
CVE-2019-25717
|
2026-06-2 23:40 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1512
|
8.8 |
HIGH
Network
|
openstack
|
keystone
|
An issue was discovered in OpenStack Keystone before 29.0.2. When combined with an application credential impersonation vulnerability, an attacker with the member role on a project can escalate to ad…
|
CWE-863
Incorrect Authorization
|
CVE-2026-43000
|
2026-06-2 23:38 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1513
|
4.9 |
MEDIUM
Network
|
mattermost
|
legal_hold
|
Mattermost Plugins versions <=1.1.5 fail to sanitize filenames received from federated peers before using them to construct export destination paths, which allows an administrator of a remote federat…
|
CWE-22
Path Traversal
|
CVE-2026-6957
|
2026-06-2 23:29 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1514
|
8.1 |
HIGH
Network
|
erlang
|
erlang\/otp
|
Improper Certificate Validation vulnerability in Erlang OTP public_key (pubkey_cert and public_key modules) allows a DNS nameConstraints bypass via subject CommonName fallback in TLS hostname verific…
|
CWE-295 CWE-297
Improper Certificate Validation Improper Validation of Certificate with Host Mismatch
|
CVE-2026-42790
|
2026-06-2 23:24 |
2026-05-28 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1515
|
8.1 |
HIGH
Network
|
openstack
|
keystone
|
An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone federated token rescoping mechanism does not propagate the original token's expiry to the newly issued token. When a federate…
|
CWE-863
Incorrect Authorization
|
CVE-2026-44394
|
2026-06-2 23:21 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1516
|
9.8 |
CRITICAL
Network
|
joomla
|
joomla\!
|
The password and username reset features created plain http links for https connections if the "Force SSL" flag wasn't explicitly set.
|
NVD-CWE-noinfo CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2026-48902
|
2026-06-2 23:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1517
|
- |
|
-
|
-
|
RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, RustFS suffers from sensitive information leakage in log outputs. When the server is run with RUST_LOG=debug sensit…
|
CWE-312 CWE-532
Cleartext Storage of Sensitive Information Inclusion of Sensitive Information in Log Files
|
CVE-2026-45040
|
2026-06-2 23:16 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1518
|
7.5 |
HIGH
Network
|
portainer
|
portainer
|
Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. From 2.33.0 to before …
|
CWE-598
Information Exposure Through Query Strings in GET Request
|
CVE-2026-44883
|
2026-06-2 23:16 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1519
|
- |
|
-
|
-
|
launch-editor allows users to open files with line numbers in editor from Node.js. Prior to version 2.9.0, due to the insufficient sanitization of the `file` argument in the `launchEditor`, an attack…
|
CWE-77
Command Injection
|
CVE-2024-52011
|
2026-06-2 23:04 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1520
|
- |
|
-
|
-
|
CloakBrowser is a tool to bypass bot detection tests. Prior to version 0.3.28, the cloakserve CDP multiplexer uses the user-supplied fingerprint query parameter directly as a filesystem path componen…
|
CWE-22
Path Traversal
|
CVE-2026-45727
|
2026-06-2 23:04 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|