|
51
|
9.1 |
CRITICAL
Network
|
apache
|
cxf
|
The JwtAccessTokenValidator class in Apache CXF fails to validate the 'aud' (Audience) claims of incoming JWT access tokens. This allows a JWT issued for one Resource Server to be successfully replay…
Update
|
CWE-289
Authentication Bypass by Alternate Name
|
CVE-2026-50627
|
2026-06-16 03:07 |
2026-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
52
|
5.4 |
MEDIUM
Network
|
jenkins
|
jenkins
|
Jenkins 2.483 through 2.567 (both inclusive), LTS 2.492.1 through 2.555.2 (both inclusive) does not escape the user-provided description of a generic offline cause that could be set through the `POST…
Update
|
CWE-79
Cross-site Scripting
|
CVE-2026-53441
|
2026-06-16 03:05 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
53
|
7.2 |
HIGH
Network
|
qnap
|
quts_hero
|
A NULL pointer dereference vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerabili…
Update
|
CWE-476
NULL Pointer Dereference
|
CVE-2025-62850
|
2026-06-16 02:59 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
54
|
7.5 |
HIGH
Network
|
image-size
|
image-size
|
image-size through 2.0.2 contains a denial of service vulnerability that allows remote attackers to permanently block the Node.js event loop by supplying a specially crafted image buffer with a zero-…
Update
|
CWE-835
Loop with Unreachable Exit Condition ('Infinite Loop')
|
CVE-2025-71319
|
2026-06-16 02:52 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
55
|
7.5 |
HIGH
Network
|
adobe
|
c2pa c2pa-web
|
CAI Content Credentials versions c2pa-web@0.7.1, c2pa-v0.80.1 and earlier are affected by an Improper Input Validation vulnerability. An attacker could exploit this vulnerability to crash the applica…
Update
|
CWE-20
Improper Input Validation
|
CVE-2026-34712
|
2026-06-16 02:42 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
56
|
7.5 |
HIGH
Network
|
adobe
|
c2pa c2pa-web
|
CAI Content Credentials versions c2pa-web@0.7.1, c2pa-v0.80.1 and earlier are affected by an Uncontrolled Resource Consumption vulnerability. An attacker could exploit this vulnerability to exhaust s…
Update
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2026-34713
|
2026-06-16 02:42 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
57
|
6.2 |
MEDIUM
Local
|
adobe
|
c2pa c2pa-web
|
CAI Content Credentials versions c2pa-web@0.7.1, c2pa-v0.80.1 and earlier are affected by an Uncontrolled Resource Consumption vulnerability. An attacker could exploit this vulnerability to exhaust s…
Update
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2026-47902
|
2026-06-16 02:42 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
58
|
6.2 |
MEDIUM
Local
|
adobe
|
c2pa c2pa-web
|
CAI Content Credentials versions c2pa-web@0.7.1, c2pa-v0.80.1 and earlier are affected by an Improper Input Validation vulnerability. An attacker could exploit this vulnerability to crash the applica…
Update
|
CWE-20
Improper Input Validation
|
CVE-2026-47903
|
2026-06-16 02:42 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
59
|
6.2 |
MEDIUM
Local
|
adobe
|
c2pa c2pa-web
|
CAI Content Credentials versions c2pa-web@0.7.1, c2pa-v0.80.1 and earlier are affected by an Uncontrolled Resource Consumption vulnerability. An attacker could exploit this vulnerability to exhaust s…
Update
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2026-47905
|
2026-06-16 02:42 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
60
|
6.2 |
MEDIUM
Local
|
adobe
|
c2pa c2pa-web
|
CAI Content Credentials versions c2pa-web@0.7.1, c2pa-v0.80.1 and earlier are affected by an Uncontrolled Resource Consumption vulnerability. An attacker could exploit this vulnerability to exhaust s…
Update
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2026-47904
|
2026-06-16 02:42 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|