|
1531
|
- |
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
netfilter: nf_queue: hold bridge skb->dev while queued
br_pass_frame_up() rewrites skb->dev from the ingress port to the bridge
m…
|
-
|
CVE-2026-52912
|
2026-06-24 17:16 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1532
|
9.1 |
CRITICAL
Network
|
ibm
|
websphere_application_server
|
IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to server-side request forgery (SSRF) with the Ajax Proxy configured. This may allow an attacker to send unauthorized requests from the sys…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-9006
|
2026-06-24 14:17 |
2026-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1533
|
- |
|
-
|
-
|
A permissive list of allowed inputs in ASUS Armoury Crate allows a local administrator to perform arbitrary memory read/write operations or cause a system crash (BSOD) by bypassing the validation mec…
|
CWE-183
Permissive List of Allowed Inputs
|
CVE-2026-8918
|
2026-06-24 14:17 |
2026-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1534
|
9.1 |
CRITICAL
Network
|
ibm
|
websphere_application_server
|
IBM WebSphere Application Server 9.0 and 8.5 and IBM WebSphere Application Server - Liberty 17.0.0.3 through 26.0.0.6 are vulnerable to HTTP request smuggling. A remote attacker could smuggle a speci…
|
CWE-444
HTTP Request Smuggling
|
CVE-2026-8646
|
2026-06-24 14:17 |
2026-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1535
|
- |
|
-
|
-
|
Nest is a framework for building scalable Node.js server-side applications. Prior to 11.1.24, an authentication bypass vulnerability exists in @nestjs/platform-fastify. When middleware is registered …
|
CWE-863
Incorrect Authorization
|
CVE-2026-54281
|
2026-06-24 14:17 |
2026-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1536
|
8.8 |
HIGH
Network
|
-
|
-
|
Url redirection to untrusted site ('open redirect') in Microsoft 365 Copilot's Business Chat allows an unauthorized attacker to elevate privileges over a network.
|
CWE-601
Open Redirect
|
CVE-2026-47645
|
2026-06-24 14:17 |
2026-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1537
|
- |
|
-
|
-
|
A command injection vulnerability in the Rancher Manager cluster before 2.14.2 import endpoint /v3/import/{token}_{clusterId}.yaml through unsanitized YAML parameters could allow remote attackers to…
|
CWE-95
Eval Injection
|
CVE-2026-44939
|
2026-06-24 14:17 |
2026-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1538
|
7.2 |
HIGH
Network
|
apache
|
nifi
|
Apache NiFi 1.12.0 through 2.9.0 are missing authorization when replacing Process Groups that include extension components with specific Required Permissions based on the Restricted annotation. The R…
|
CWE-862
Missing Authorization
|
CVE-2026-44914
|
2026-06-24 14:17 |
2026-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1539
|
6.0 |
MEDIUM
Local
|
-
|
-
|
Dell Wyse Management Suite (WMS), versions prior to WMS 2605, contain a Use of Default Credentials vulnerability. A high privileged attacker with local access could potentially exploit this vulnerabi…
|
CWE-1392
Use of Default Credentials
|
CVE-2026-44273
|
2026-06-24 14:17 |
2026-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1540
|
6.5 |
MEDIUM
Network
|
-
|
-
|
Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an unauthorized attacker to perform tampering over a network.
|
CWE-77
Command Injection
|
CVE-2026-42895
|
2026-06-24 14:17 |
2026-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|