|
2981
|
9.1 |
CRITICAL
Network
|
electerm_project
|
electerm
|
electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.9.5, deterministic AES-192-CBC with a fixed zero IV, constant KDF salt, and no MAC leads to confid…
|
CWE-326 CWE-329 CWE-353 CWE-759 CWE-916
Inadequate Encryption Strength Not Using a Random IV with CBC Mode Missing Support for Integrity Check Use of a One-Way Hash without a Salt Use of Password Hash With Insufficient Computational Effort
|
CVE-2026-45787
|
2026-06-4 02:56 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2982
|
7.8 |
HIGH
Local
|
electerm_project
|
electerm
|
electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. From 3.0.6 to 3.8.8, This vulnerability is fixed in 3.9.0.
|
CWE-94 CWE-732 CWE-940
Code Injection Incorrect Permission Assignment for Critical Resource Improper Verification of Source of a Communication Channel
|
CVE-2026-45353
|
2026-06-4 02:54 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2983
|
8.8 |
HIGH
Network
|
oracle
|
e-business_suite
|
Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability all…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2026-46826
|
2026-06-4 02:43 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2984
|
8.8 |
HIGH
Network
|
oracle
|
e-business_suite
|
Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Self Service Manager). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability al…
|
CWE-269 CWE-284 CWE-287 CWE-306
Improper Privilege Management Improper Access Control Improper Authentication Missing Authentication for Critical Function
|
CVE-2026-46827
|
2026-06-4 02:43 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2985
|
8.1 |
HIGH
Network
|
oracle
|
e-business_suite
|
Vulnerability in the Oracle Payroll product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability all…
|
CWE-284
Improper Access Control
|
CVE-2026-46828
|
2026-06-4 02:42 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2986
|
7.5 |
HIGH
Network
|
oracle
|
rest_data_services
|
Vulnerability in Oracle REST Data Services (component: Mongoapi). Supported versions that are affected are 24.2.0-26.1.0. Easily exploitable vulnerability allows unauthenticated attacker with networ…
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2026-46829
|
2026-06-4 02:41 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2987
|
6.5 |
MEDIUM
Network
|
nextcloud
|
approval
|
Nextcloud is an open source content collaboration platform. Prior to version 2.7.2, a privilege escalation vulnerability exists in the Approval app that allows a user without sharing permissions to f…
|
CWE-285
Improper Authorization
|
CVE-2026-45275
|
2026-06-4 02:39 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2988
|
9.1 |
CRITICAL
Network
|
oracle
|
e-business_suite
|
Vulnerability in the Oracle Internet Procurement Connector product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploi…
|
CWE-284
Improper Access Control
|
CVE-2026-46819
|
2026-06-4 02:37 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2989
|
3.3 |
LOW
Local
|
nextcloud
|
approval
|
Nextcloud is an open source content collaboration platform. Prior to version 2.7.2, authenticated users can check if arbitrary files are associated with specific approval workflows where they can req…
|
CWE-200 NVD-CWE-noinfo
Information Exposure
|
CVE-2026-45277
|
2026-06-4 02:36 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2990
|
6.1 |
MEDIUM
Network
|
nextcloud
|
user_oidc
|
Nextcloud is an open source content collaboration platform. From version 6.1.0 to before version 8.2.2, an attacker can craft links that would redirect users to another website, when the victim uses …
|
CWE-601
Open Redirect
|
CVE-2026-45278
|
2026-06-4 02:34 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|