|
561
|
- |
|
-
|
-
|
Jellyfin is an open source self hosted media server. Prior to 10.11.10, a specifically crafted MKV file containing forged filename tags can be leveraged to exploit missing path sanitization during pl…
New
|
CWE-22
Path Traversal
|
CVE-2026-49246
|
2026-06-26 05:17 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
562
|
8.8 |
HIGH
Network
|
-
|
-
|
Warp is an agentic development environment. From 0.2025.03.05.08.02.stable_00 until 0.2026.05.06.15.42.stable_01, Warp accepts non-inline `OSC 1337;File` payloads from terminal output and materialize…
New
|
CWE-20 CWE-73
Improper Input Validation External Control of File Name or Path
|
CVE-2026-48720
|
2026-06-26 05:17 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
563
|
7.5 |
HIGH
Network
|
-
|
-
|
Docling simplifies document processing by parsing diverse formats and providing integrations with the generative AI ecosystem. Prior to 2.91.0, the EasyOCR model download functionality extracted ZIP …
New
|
CWE-22
Path Traversal
|
CVE-2026-44017
|
2026-06-26 05:17 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
564
|
5.3 |
MEDIUM
Network
|
-
|
-
|
swift-nio-http2's HTTP/2-to-HTTP/1.1 codec did not validate pseudo-header values for control characters before placing them into the translated HTTP/1.1 message. swift-nio-http2 1.44.1 adds validatio…
New
|
CWE-116
Improper Encoding or Escaping of Output
|
CVE-2026-28898
|
2026-06-26 05:17 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
565
|
- |
|
-
|
-
|
FOSSBilling is a free, open-source billing and client management system. In versions 0.7.2 and prior, the Servicecustom Client API's __call method accepts an order_id parameter and fetches the associ…
New
|
CWE-284 CWE-639 CWE-862
Improper Access Control Authorization Bypass Through User-Controlled Key Missing Authorization
|
CVE-2026-27708
|
2026-06-26 05:17 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
566
|
7.5 |
HIGH
Network
|
-
|
-
|
List::SomeUtils::XS versions before 0.59 for Perl have a heap buffer overflow in the pairwise function.
pairwise() collects the values returned by the block into a heap buffer sized to the longer in…
New
|
CWE-122 CWE-787
Heap-based Buffer Overflow Out-of-bounds Write
|
CVE-2026-12844
|
2026-06-26 05:17 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
567
|
7.5 |
HIGH
Network
|
-
|
-
|
An issue in the sqlo_natural_join_cond component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.
New
|
CWE-89
SQL Injection
|
CVE-2025-61021
|
2026-06-26 05:17 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
568
|
7.5 |
HIGH
Network
|
-
|
-
|
An issue in the sqlo_key_part_best component of openlink virtuoso-opensource v7.2.11 allows attackers to cause a Denial of Service (DoS) via crafted SQL statements.
New
|
CWE-89
SQL Injection
|
CVE-2025-61019
|
2026-06-26 05:17 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
569
|
7.5 |
HIGH
Network
|
-
|
-
|
The Aclara Metrum Cellular Web Interface is vulnerable to unauthorized access due to the absence of authentication controls on critical system functions. This weakness exposes essential configuration…
New
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2026-1840
|
2026-06-26 05:16 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
570
|
- |
|
-
|
-
|
Horner Automation Cscape versions prior to 10.2 SP3 are vulnerable to an Out-of-Bounds Read vulnerability through parsing CSP files. Successful exploitation of this vulnerability could allow an attac…
New
|
CWE-125
Out-of-bounds Read
|
CVE-2026-12897
|
2026-06-26 05:16 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|