|
1221
|
- |
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
vsock/virtio: fix potential unbounded skb queue
virtio_transport_inc_rx_pkt() checks vvs->rx_bytes + len > vvs->buf_alloc.
virti…
New
|
-
|
CVE-2026-53132
|
2026-06-25 18:16 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1222
|
- |
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
netfilter: require Ethernet MAC header before using eth_hdr()
`ip6t_eui64`, `xt_mac`, the `bitmap:ip,mac`, `hash:ip,mac`, and
`ha…
New
|
-
|
CVE-2026-53131
|
2026-06-25 18:16 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1223
|
8.3 |
HIGH
Network
|
-
|
-
|
yt-dlp is a command-line audio/video downloader. Prior to 2026.06.09, if aria2c is used as an external downloader for a fragmented manifest format (such as an HLS/DASH stream), yt-dlp passes insuffic…
New
|
CWE-74
Injection
|
CVE-2026-50574
|
2026-06-25 14:16 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1224
|
- |
|
-
|
-
|
A vulnerability in the iCagenda extension for Joomla allows the upload of arbitrary files in the file attachment feature, ultimately resulting in PHP code upload and execution.
New
|
CWE-284
Improper Access Control
|
CVE-2026-48939
|
2026-06-25 14:16 |
2026-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1225
|
9.9 |
CRITICAL
Network
|
-
|
-
|
Execution with unnecessary privileges in Azure Synapse allows an authorized attacker to elevate privileges over a network.
New
|
CWE-250
Execution with Unnecessary Privileges
|
CVE-2026-48584
|
2026-06-25 14:16 |
2026-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1226
|
7.8 |
HIGH
Local
|
-
|
-
|
Dell Server Hardware Manager, versions prior to 3.2.2, contains an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, lea…
New
|
CWE-284
Improper Access Control
|
CVE-2026-46461
|
2026-06-25 14:16 |
2026-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1227
|
- |
|
-
|
-
|
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
New
|
-
|
CVE-2025-8106
|
2026-06-25 08:16 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1228
|
- |
|
-
|
-
|
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
New
|
-
|
CVE-2026-47093
|
2026-06-25 07:16 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1229
|
5.3 |
MEDIUM
Network
|
-
|
-
|
The WP Go Maps – Most Popular Map Plugin plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 10.1.01. This is due to the plugin not properly verifying tha…
New
|
CWE-862
Missing Authorization
|
CVE-2026-12238
|
2026-06-25 06:16 |
2026-06-20 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1230
|
7.5 |
HIGH
Network
|
vitejs voidzero
|
vite vite\+
|
Vite is a frontend tooling framework for JavaScript. Prior to 8.0.16, 7.3.5, and 6.4.3, the contents of files that are specified by server.fs.deny can be returned to the browser on Windows. Vite’s de…
New
|
CWE-22 CWE-200
Path Traversal Information Exposure
|
CVE-2026-53571
|
2026-06-25 05:44 |
2026-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|