|
651
|
6.5 |
MEDIUM
Adjacent
|
-
|
-
|
aiograpi is an asynchronous Instagram API for Python. aiograpi versions before 0.9.10 accepted server-supplied signup challenge paths and used them to build request URLs before validating that the pa…
New
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-47157
|
2026-06-12 03:16 |
2026-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
652
|
5.3 |
MEDIUM
Network
|
-
|
-
|
Fediverse Embeds embeds fediverse posts on WordPress sites. Prior to version 1.5.9, Fediverse Embeds registered the unauthenticated AJAX action wp_ajax_nopriv_ftf_get_site_info (includes/Site_Info.ph…
New
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-46698
|
2026-06-12 03:16 |
2026-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
653
|
7.5 |
HIGH
Network
|
-
|
-
|
Fediverse Embeds embeds fediverse posts on WordPress sites. Prior to version 1.5.8, Fediverse Embeds registered an unauthenticated REST route ftf/media-proxy (includes/Media_Proxy.php) with permissio…
New
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-46697
|
2026-06-12 03:16 |
2026-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
654
|
4.8 |
MEDIUM
Network
|
-
|
-
|
Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, axios exposes two read-side prototype-pollution gadgets. When Object.prototype is polluted by an upstream…
New
|
CWE-1321
Improperly Controlled Modification of Object Prototype Attributes ('Prototype Pollution')
|
CVE-2026-44490
|
2026-06-12 03:16 |
2026-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
655
|
- |
|
-
|
-
|
A remote unauthenticated attacker may be able to conduct credential-guessing attacks against user accounts in Sonatype Nexus Repository via authentication endpoints.
New
|
CWE-307
mproper Restriction of Excessive Authentication Attempts
|
CVE-2026-3329
|
2026-06-12 03:16 |
2026-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
656
|
4.9 |
MEDIUM
Network
|
-
|
-
|
A flaw was found in the admin-ui-ext component of Keycloak, which provides extended administrative user interface capabilities. The issue occurs because certain bulk role-removal endpoints fail to pe…
New
|
CWE-425
Direct Request ('Forced Browsing')
|
CVE-2026-11986
|
2026-06-12 03:16 |
2026-06-12 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
657
|
8.8 |
HIGH
Local
|
espressif
|
esp-idf
|
ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.4 and 6.0, the esp_tee component exposes secure-service wrappers in esp_secure_services.c and esp_secure_servi…
New
|
CWE-20 CWE-787
Improper Input Validation Out-of-bounds Write
|
CVE-2026-45328
|
2026-06-12 03:15 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
658
|
7.5 |
HIGH
Network
|
espressif
|
esp-idf
|
ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.2.6, 5.3.5, 5.4.4, 5.5.4, and 6.0, a NULL-pointer dereference exists in the WebSocket subprotocol-negotiation pa…
New
|
CWE-476
NULL Pointer Dereference
|
CVE-2026-45541
|
2026-06-12 03:05 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
659
|
6.5 |
MEDIUM
Local
|
espressif
|
esp-idf
|
ESF-IDF is the Espressif Internet of Things (IOT) Development Framework. In versions 5.5.4 and 6.0, several ESP-TEE secure-service wrappers in esp_secure_services.c and esp_secure_services_iram.c val…
New
|
CWE-20 CWE-125 CWE-200
Improper Input Validation Out-of-bounds Read Information Exposure
|
CVE-2026-45329
|
2026-06-12 03:04 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
660
|
6.5 |
MEDIUM
Network
|
7-zip
|
7-zip
|
7-Zip is a file archiver with a high compression ratio. Versions 9.21 through 26.00 contain an An uninitialized memory disclosure vulnerability in the UEFI capsule (.scap) parser in 7-Zip. The OpenCa…
Update
|
CWE-908
Use of Uninitialized Resource
|
CVE-2026-48101
|
2026-06-12 03:02 |
2026-06-6 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|