|
4381
|
7.5 |
HIGH
Network
|
-
|
-
|
CORS misconfiguration in the REST API of Network Optix Nx Witness VMS before version 6.1.2, when running in the default Standard security mode, on Linux and Windows allows an unauthenticated remote a…
|
CWE-942
Permissive Cross-domain Policy with Untrusted Domains
|
CVE-2026-10056
|
2026-06-2 02:06 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4382
|
9.1 |
CRITICAL
Network
|
-
|
-
|
There is an authentication bypass vulnerability in the NI SystemLink Enterprise Dashboard application that may allow an unauthenticated remote attacker to bypass authentication controls leading to pr…
|
CWE-306
Missing Authentication for Critical Function
|
CVE-2026-9051
|
2026-06-2 02:06 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4383
|
3.1 |
LOW
Network
|
apache
|
airflow
|
The structure_data endpoint in the Airflow UI returned external dependency graph nodes for linked Dags without checking whether the caller had read permission on those linked Dags. An authenticated U…
|
CWE-285
Improper Authorization
|
CVE-2026-40963
|
2026-06-2 02:06 |
2026-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4384
|
6.1 |
MEDIUM
Network
|
apache
|
activemq activemq_web
|
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache ActiveMQ, Apache ActiveMQ Web.
The MessageServlet in the ActiveMQ web console API copies …
|
CWE-79
Cross-site Scripting
|
CVE-2026-42253
|
2026-06-2 02:06 |
2026-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4385
|
6.5 |
MEDIUM
Network
|
apache
|
airflow
|
A bug in Apache Airflow's rendered-template field handling caused nested sensitive-key masking (e.g. nested `password` / `token` / `secret` / `api_key` keys inside a JSON template structure) to be by…
|
CWE-200
Information Exposure
|
CVE-2026-42360
|
2026-06-2 02:06 |
2026-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4386
|
8.1 |
HIGH
Network
|
apache
|
activemq activemq_broker
|
Improper Input Validation, Improper Control of Generation of Code ('Code Injection') vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ All, Apache ActiveMQ.
Apache ActiveMQ Classic exposes th…
|
CWE-20 CWE-94
Improper Input Validation Code Injection
|
CVE-2026-42588
|
2026-06-2 02:06 |
2026-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4387
|
5.8 |
MEDIUM
Network
|
-
|
-
|
A flaw was found in Clair. The fetcher component makes outbound HTTP requests to attacker-supplied URIs from manifest layer descriptors without IP or scheme filtering. When PSK authentication is not …
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-10517
|
2026-06-2 01:57 |
2026-06-1 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4388
|
9.8 |
CRITICAL
Network
|
-
|
-
|
SDMC NE6037 cable modem routers running firmware 7.1.6.0.25 and 7.1.6.1.9_B9 contain a hardcoded password vulnerability in the web management interface recovery endpoints (mgmt.php, npcmd.php) that a…
|
CWE-798
Use of Hard-coded Credentials
|
CVE-2026-24444
|
2026-06-2 01:55 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4389
|
7.5 |
HIGH
Network
|
-
|
-
|
Usagi-org ai-goofish-monitor contains an unauthenticated arbitrary file read vulnerability in the GET /api/prompts/{filename} endpoint on Windows deployments that allows unauthenticated remote attack…
|
CWE-36
Absolute Path Traversal
|
CVE-2026-10044
|
2026-06-2 01:55 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
4390
|
7.5 |
HIGH
Network
|
-
|
-
|
Heatmiser Wifi Thermostat 1.7 contains a credential disclosure vulnerability that allows unauthenticated attackers to retrieve administrative credentials by accessing the networkSetup.htm page. Attac…
|
CWE-256
Plaintext Storage of a Password
|
CVE-2018-25396
|
2026-06-2 01:55 |
2026-05-30 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|