|
1881
|
6.5 |
MEDIUM
Network
|
rust-lang
|
cargo
|
Cargo between 1.68 and 1.96 incorrectly normalized the URLs of third-party registries using the sparse index protocol. If a hosting provider allowed multiple registries to be hosted with arbitrary na…
|
CWE-647
Use of Non-Canonical URL Paths for Authorization Decisions
|
CVE-2026-5222
|
2026-06-2 02:56 |
2026-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1882
|
7.8 |
HIGH
Local
|
mediatek
|
mt6739_firmware mt6761_firmware mt6765_firmware mt6768_firmware mt6781_firmware mt6789_firmware mt6835_firmware mt6853_firmware mt6855_firmware mt6877_firmware mt6878_fi…
|
In geniezone, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. U…
|
CWE-787
Out-of-bounds Write
|
CVE-2026-20455
|
2026-06-2 02:56 |
2026-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1883
|
5.5 |
MEDIUM
Local
|
mediatek
|
mt7902_firmware mt7920_firmware mt7921_firmware mt7922_firmware mt7925_firmware mt7927_firmware
|
In wlan STA driver, there is a possible system crash due to a missing bounds check. This could lead to local denial of service with User execution privileges needed. User interaction is not needed fo…
|
CWE-787
Out-of-bounds Write
|
CVE-2026-20456
|
2026-06-2 02:54 |
2026-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1884
|
9.8 |
CRITICAL
Network
|
redhat samba
|
openshift_container_platform samba enterprise_linux
|
A flaw was found in the Samba printing subsystem. Samba passes the client-controlled job description string to the command configured with the "print command" setting via the "%J"
substitution charac…
|
CWE-78
OS Command
|
CVE-2026-4480
|
2026-06-2 02:53 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1885
|
5.3 |
MEDIUM
Network
|
rust-lang
|
cargo
|
Cargo incorrectly handled symlinks inside of crate tarballs downloaded from third-party registries, allowing a malicious crate to override the source code of another crate from the same registry. The…
|
CWE-61
UNIX Symbolic Link (Symlink) Following
|
CVE-2026-5223
|
2026-06-2 02:52 |
2026-05-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1886
|
7.4 |
HIGH
Network
|
pyjwt_project
|
pyjwt
|
PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, when the verifier is decoding JSON Web Tokens, while supporting both asymmetric and HMAC algorithms, the library does not validate…
|
CWE-287 CWE-347
Improper Authentication Improper Verification of Cryptographic Signature
|
CVE-2026-48526
|
2026-06-2 02:45 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1887
|
5.3 |
MEDIUM
Network
|
pyjwt_project
|
pyjwt
|
PyJWT is a JSON Web Token implementation in Python. From 2.8.0 to 2.12.1, when verifying detached JWS tokens using the unencoded-payload option ("b64": false, RFC 7797), PyJWT performs Base64URL deco…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2026-48525
|
2026-06-2 02:45 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1888
|
3.7 |
LOW
Network
|
pyjwt_project
|
pyjwt
|
PyJWT is a JSON Web Token implementation in Python. Prior to 2.13.0, PyJWKClient.get_signing_key() forces a fresh HTTP request to the JWKS endpoint for every JWT with an unknown kid value, with no ra…
|
CWE-460 CWE-755
Improper Cleanup on Thrown Exception Improper Handling of Exceptional Conditions
|
CVE-2026-48524
|
2026-06-2 02:44 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1889
|
5.4 |
MEDIUM
Network
|
pyjwt_project
|
pyjwt
|
PyJWT is a JSON Web Token implementation in Python. From 2.9.0 to 2.12.1, there is a verifier-side algorithm allow-list bypass when jwt.decode() or jwt.decode_complete() are called with a PyJWK key. …
|
CWE-347
Improper Verification of Cryptographic Signature
|
CVE-2026-48523
|
2026-06-2 02:44 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1890
|
8.8 |
HIGH
Network
|
freerdp
|
freerdp
|
FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, a malicious RDP server can trigger a heap-buffer-overflow write in the FreeRDP client by sending crafted RDPGFX PDUs.…
|
CWE-122
Heap-based Buffer Overflow
|
CVE-2026-44421
|
2026-06-2 02:35 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|