|
91
|
6.1 |
MEDIUM
Network
|
ibm
|
devops_plan
|
IBM DevOps Plan 3.0.0 through 3.0.6 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against…
Update
|
CWE-644
Improper Neutralization of HTTP Headers for Scripting Syntax
|
CVE-2026-4096
|
2026-06-17 01:23 |
2026-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
92
|
8.8 |
HIGH
Network
|
kovidgoyal
|
kitty
|
Kitty is a cross-platform GPU based terminal. In versions prior to 0.47.0, it is possible to inject commands within the subshell through kitty error. A special escape code will make kitty return an e…
New
|
CWE-77
Command Injection
|
CVE-2026-42850
|
2026-06-17 01:11 |
2026-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
93
|
7.8 |
HIGH
Local
|
kovidgoyal
|
kitty
|
Kitty is a cross-platform GPU based terminal. In versions prior to 0.47.0, a program able to write bytes to a kitty terminal — a remote SSH peer, a downloaded file viewed with `cat`, a log line, an e…
New
|
CWE-94 CWE-862
Code Injection Missing Authorization
|
CVE-2026-42851
|
2026-06-17 01:07 |
2026-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
94
|
5.0 |
MEDIUM
Local
|
kovidgoyal
|
kitty
|
Kitty is a cross-platform GPU based terminal. In versions prior to 0.47.2, a local privilege escalation vulnerability exists in kitty's file transmission protocol where a child process running in the…
New
|
CWE-59 CWE-367 CWE-426
Link Following Time-of-check Time-of-use (TOCTOU) Race Condition Untrusted Search Path
|
CVE-2026-54055
|
2026-06-17 01:02 |
2026-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
95
|
7.1 |
HIGH
Network
|
kovidgoyal
|
kitty
|
Kitty is a cross-platform GPU based terminal. In versions 0.47.0 and 0.47.1, `kitten dnd` can allow a malicious remote drag-and-drop source to overwrite or truncate arbitrary files writable by the lo…
New
|
CWE-59
Link Following
|
CVE-2026-54056
|
2026-06-17 00:59 |
2026-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
96
|
- |
|
-
|
-
|
AgenticMail gives AI agents real email addresses and phone numbers. Prior to version 0.9.27, @agenticmail/mcp exposes a Streamable HTTP transport when started with --http or MCP_HTTP=1. In that mode,…
New
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2026-50287
|
2026-06-17 00:51 |
2026-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
97
|
8.8 |
HIGH
Network
|
-
|
-
|
A Time-Based Blind SQL Injection vulnerability in the alias_management module of OpenSIPS Control Panel (opensips-cp) prior to version 9.3.3 allows authenticated attackers to execute arbitrary SQL co…
New
|
CWE-89
SQL Injection
|
CVE-2026-36670
|
2026-06-17 00:51 |
2026-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
98
|
6.8 |
MEDIUM
Network
|
-
|
-
|
In OpenStack Ironic through 35.0.1, when applying a PATCH to update fields in volume properties the user is authorized for, Ironic can return unredacted sensitive information (such as iSCSI credentia…
New
|
CWE-212
Improper Removal of Sensitive Information Before Storage or Transfer
|
CVE-2026-54421
|
2026-06-17 00:51 |
2026-06-14 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
99
|
7.5 |
HIGH
Network
|
-
|
-
|
Mastodon is a free, open-source social network server based on ActivityPub. In versions there is a missing condition in the check if remote accounts consented to be featured in a remote Collection co…
New
|
CWE-345 CWE-863
Insufficient Verification of Data Authenticity Incorrect Authorization
|
CVE-2026-47777
|
2026-06-17 00:51 |
2026-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
100
|
6.1 |
MEDIUM
Network
|
-
|
-
|
Valhalla is an open source routing engine and accompanying libraries for use with OpenStreetMap data. Versions 3.6.3 and prior are vulnerable to reflected cross-site scripting (XSS) due to improper n…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-49294
|
2026-06-17 00:51 |
2026-06-16 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|