|
41
|
9.1 |
CRITICAL
Network
|
openssl
|
openssl
|
Issue Summary: Cryptographic Message Services (CMS) processing fails to perform
sufficient input validation on the cipher and tag length fields of
AuthEnvelopedData containers, leading to various pot…
Update
|
CWE-354
Improper Validation of Integrity Check Value
|
CVE-2026-34182
|
2026-06-16 03:13 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
42
|
7.5 |
HIGH
Network
|
openssl
|
openssl
|
Issue summary: Remote peer may exhaust heap memory of the QUIC
server or client by flooding it with packets containing PATH_CHALLENGE
frames.
Impact summary: A malicious remote peer can cause an unb…
Update
|
CWE-1325
Improperly Controlled Sequential Memory Allocation
|
CVE-2026-34183
|
2026-06-16 03:12 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
43
|
5.0 |
MEDIUM
Network
|
openssl
|
openssl
|
Issue summary: A malicious server can exploit TLS OCSP stapling by delivering
a crafted response through the status_request extension, triggering a
double-free in the client's certificate verificatio…
Update
|
CWE-415
Double Free
|
CVE-2026-35188
|
2026-06-16 03:12 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
44
|
5.7 |
MEDIUM
Adjacent
|
nuxt
|
nuxt\/rspack-builder nuxt\/webpack-builder
|
Nuxt is an open-source web development framework for Vue.js. In @nuxt/rspack-builder and @nuxt/webpack-builder from versions 3.15.4 to before 3.21.7 and 4.0.0 to before 4.4.7, there is an incomplete …
New
|
CWE-749
Exposed Dangerous Method or Function
|
CVE-2026-49993
|
2026-06-16 03:10 |
2026-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
45
|
9.8 |
CRITICAL
Network
|
jmespath
|
jmespath
|
jmespath.php allows users to use JMESPath, software for declaratively specifying how to extract elements from a JSON document, in PHP applications with PHP data structures. Versions prior to 2.9.1 ca…
New
|
CWE-20 CWE-94 CWE-116
Improper Input Validation Code Injection Improper Encoding or Escaping of Output
|
CVE-2026-54133
|
2026-06-16 03:09 |
2026-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
46
|
5.4 |
MEDIUM
Network
|
nuxt
|
nuxt
|
Nuxt is an open-source web development framework for Vue.js. From versions 3.4.3 to before 3.21.6 and 4.0.0-alpha.1 to before 4.4.6, navigateTo() with external: true generates a server-side HTML redi…
New
|
CWE-83
Improper Neutralization of Script in Attributes in a Web Page
|
CVE-2026-45669
|
2026-06-16 03:09 |
2026-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
47
|
5.3 |
MEDIUM
Network
|
nuxt
|
nuxt nuxt\/nitro-server
|
Nuxt is an open-source web development framework for Vue.js. In Nuxt versions 3.11.0 to before 3.21.6 and 4.0.0-alpha.1 to before 4.4.6 and @nuxt/nitro-server versions 3.20.0 to before 3.21.6 and 4.0…
New
|
CWE-284 CWE-288
Improper Access Control Authentication Bypass Using an Alternate Path or Channel
|
CVE-2026-47200
|
2026-06-16 03:09 |
2026-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
48
|
5.4 |
MEDIUM
Network
|
nuxt
|
nuxt nuxt\/nitro-server
|
Nuxt is an open-source web development framework for Vue.js. In Nuxt versions 3.1.0 to before 3.21.6 and 4.0.0-alpha.1 to before 4.4.6 and @nuxt/nitro-server versions 3.20.0 to before 3.21.6 and 4.0.…
New
|
CWE-79 CWE-349 CWE-444
Cross-site Scripting Acceptance of Extraneous Untrusted Data With Trusted Data HTTP Request Smuggling
|
CVE-2026-46342
|
2026-06-16 03:09 |
2026-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
49
|
5.4 |
MEDIUM
Network
|
nuxt
|
nuxt\/rspack-builder nuxt\/webpack-builder
|
Nuxt is an open-source web development framework for Vue.js. In @nuxt/rspack-builder and @nuxt/webpack-builder versions 3.15.4 to before 3.21.6, and 4.0.0-alpha.1 to before 4.4.6, there is an incompl…
New
|
CWE-749
Exposed Dangerous Method or Function
|
CVE-2026-45670
|
2026-06-16 03:08 |
2026-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
50
|
9.8 |
CRITICAL
Network
|
apache
|
cxf
|
A logic error in OAuthRequestFilter rejects legitimate requests originating from the bound IP address, while blindly allowing requests from any other IP address. Enabling this
security feature inadv…
New
|
CWE-20
Improper Input Validation
|
CVE-2026-50628
|
2026-06-16 03:07 |
2026-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|