|
1531
|
9.8 |
CRITICAL
Network
|
joomla
|
joomla\!
|
The password and username reset features created plain http links for https connections if the "Force SSL" flag wasn't explicitly set.
|
NVD-CWE-noinfo CWE-319
Cleartext Transmission of Sensitive Information
|
CVE-2026-48902
|
2026-06-2 23:16 |
2026-05-27 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1532
|
- |
|
-
|
-
|
RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, RustFS suffers from sensitive information leakage in log outputs. When the server is run with RUST_LOG=debug sensit…
|
CWE-312 CWE-532
Cleartext Storage of Sensitive Information Inclusion of Sensitive Information in Log Files
|
CVE-2026-45040
|
2026-06-2 23:16 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1533
|
7.5 |
HIGH
Network
|
portainer
|
portainer
|
Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. From 2.33.0 to before …
|
CWE-598
Information Exposure Through Query Strings in GET Request
|
CVE-2026-44883
|
2026-06-2 23:16 |
2026-05-29 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1534
|
- |
|
-
|
-
|
launch-editor allows users to open files with line numbers in editor from Node.js. Prior to version 2.9.0, due to the insufficient sanitization of the `file` argument in the `launchEditor`, an attack…
|
CWE-77
Command Injection
|
CVE-2024-52011
|
2026-06-2 23:04 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1535
|
- |
|
-
|
-
|
CloakBrowser is a tool to bypass bot detection tests. Prior to version 0.3.28, the cloakserve CDP multiplexer uses the user-supplied fingerprint query parameter directly as a filesystem path componen…
|
CWE-22
Path Traversal
|
CVE-2026-45727
|
2026-06-2 23:04 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1536
|
8.1 |
HIGH
Network
|
-
|
-
|
Input validation bypass in SMB volume mount handling in CloudFoundry Foundation diego-release allows low-privileged CF space developer to inject arbitrary kernel CIFS mount options via bypassing the …
|
CWE-88
Argument Injection
|
CVE-2026-41013
|
2026-06-2 23:01 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1537
|
7.8 |
HIGH
Local
|
-
|
-
|
A flaw was found in rrdcached, a component of rrdtool. A local attacker with access to a rrdcached socket can exploit a stack-based buffer overflow by sending an oversized CREATE request. This vulner…
|
CWE-121
Stack-based Buffer Overflow
|
CVE-2026-43958
|
2026-06-2 23:01 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1538
|
7.5 |
HIGH
Network
|
-
|
-
|
Authentication Bypass in cf-auth-proxy in Cloud Foundry Foundation all installations allows an unauthenticated remote attacker to gain read access to every log and metric for every application and pl…
|
CWE-287
Improper Authentication
|
CVE-2026-40964
|
2026-06-2 23:01 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1539
|
10.0 |
CRITICAL
Network
|
-
|
-
|
Cloud Foundry UAA versions v76.12.0 through v78.12.0 are vulnerable to a private key exposure. The server contains a vulnerability where EC (Elliptic Curve) private keys are inadvertently exposed thr…
|
CWE-200
Information Exposure
|
CVE-2026-40965
|
2026-06-2 23:01 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1540
|
8.8 |
HIGH
Local
|
-
|
-
|
The Route OpenShift resource allows to define routes to make pods reachable at a subdomain through HAProxy. It was found that the checks performed on the spec.path YAML stanza in a Route document was…
|
CWE-15
External Control of System or Configuration Setting
|
CVE-2026-1784
|
2026-06-2 23:01 |
2026-06-2 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|