|
1011
|
8.8 |
HIGH
Network
|
microsoft
|
windows_app windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2012 windows_s…
|
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
|
CWE-122
Heap-based Buffer Overflow
|
CVE-2026-47289
|
2026-06-13 02:39 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1012
|
8.8 |
HIGH
Network
|
microsoft
|
windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows_server_2012 windows_server_2016 w…
|
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
|
CWE-416 CWE-787
Use After Free Out-of-bounds Write
|
CVE-2026-47653
|
2026-06-13 02:32 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1013
|
7.5 |
HIGH
Network
|
microsoft
|
windows_server_2016 windows_server_2019 windows_server_2022 windows_server_2025
|
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
|
CWE-416 CWE-787
Use After Free Out-of-bounds Write
|
CVE-2026-47654
|
2026-06-13 02:27 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1014
|
8.3 |
HIGH
Network
|
google
|
chrome
|
Use after free in WebMIDI in Google Chrome on Windows prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted …
|
CWE-416
Use After Free
|
CVE-2026-12011
|
2026-06-13 02:20 |
2026-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1015
|
7.5 |
HIGH
Network
|
microsoft
|
remote_desktop_client windows_app windows_10_1607 windows_10_1809 windows_10_21h2 windows_10_22h2 windows_11_23h2 windows_11_24h2 windows_11_25h2 windows_11_26h1 windows…
|
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
|
CWE-416 CWE-787
Use After Free Out-of-bounds Write
|
CVE-2026-44801
|
2026-06-13 02:20 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1016
|
8.3 |
HIGH
Network
|
google
|
chrome
|
Heap buffer overflow in GPU in Google Chrome on Android prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafte…
|
CWE-122
Heap-based Buffer Overflow
|
CVE-2026-12010
|
2026-06-13 02:19 |
2026-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1017
|
8.3 |
HIGH
Network
|
google
|
chrome
|
Insufficient validation of untrusted input in Accessibility in Google Chrome on Mac prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to potentially perform a…
|
CWE-20 NVD-CWE-noinfo
Improper Input Validation
|
CVE-2026-12009
|
2026-06-13 02:18 |
2026-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1018
|
9.1 |
CRITICAL
Network
|
-
|
-
|
Aqara Home Android (com.lumiunited.aqarahome) 6.0.0 (and white-label clients embedding the same liblumidevsdk.so) uses hard-coded cryptographic keys, which is an instance of "CWE-321: Use of Hard-cod…
|
CWE-321
Use of Hard-coded Cryptographic Key
|
CVE-2026-50091
|
2026-06-13 02:16 |
2026-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1019
|
9.3 |
CRITICAL
Network
|
-
|
-
|
The Aqara Cloud OAuth Authorization Endpoint (open-cn.aqara.com/oauth/authorize) is vulnerable to a redirect bypass due to lax controls on domain matching, which is an instance of "CWE-1289: Improper…
|
CWE-1289
Improper Validation of Unsafe Equivalence in Input
|
CVE-2026-50090
|
2026-06-13 02:16 |
2026-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1020
|
6.1 |
MEDIUM
Network
|
-
|
-
|
The Aqara IAM/SSO Gateway (gw-builder.aqara.com) provides an open redirect, which is an instance of "CWE-601: URL Redirection to Untrusted Site," with an estimated CVSS of CVSS:3.1/AV:N/AC:L/PR:N/UI:…
|
CWE-601
Open Redirect
|
CVE-2026-50089
|
2026-06-13 02:16 |
2026-06-13 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|