|
2121
|
6.5 |
MEDIUM
Network
|
-
|
-
|
wire-ios is an iOS client for the Wire secure messaging application. Prior to version 4.16.0, upon receiving a crafted malicious Proteus external message with an encrypted payload that is shorter tha…
|
CWE-20 CWE-191
Improper Input Validation Integer Underflow (Wrap or Wraparound)
|
CVE-2026-35049
|
2026-06-5 01:12 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2122
|
8.5 |
HIGH
Network
|
-
|
-
|
Medplum before 5.1.14 contains a server-side request forgery vulnerability in the subscription worker that allows authenticated users to perform unauthorized internal network requests by creating FHI…
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-49120
|
2026-06-5 01:10 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2123
|
8.8 |
HIGH
Adjacent
|
-
|
-
|
BrowserStack Runner through 0.9.5 contains a remote code execution vulnerability in the /_log HTTP handler that allows unauthenticated network-adjacent attackers to execute arbitrary code by submitti…
|
CWE-94
Code Injection
|
CVE-2026-49143
|
2026-06-5 01:10 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2124
|
6.5 |
MEDIUM
Adjacent
|
-
|
-
|
BrowserStack Runner through 0.9.5 contains a path traversal vulnerability in the _default HTTP handler in lib/server.js that allows unauthenticated network-adjacent attackers to read arbitrary files.…
|
CWE-22
Path Traversal
|
CVE-2026-49144
|
2026-06-5 01:10 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2125
|
5.9 |
MEDIUM
Network
|
-
|
-
|
QloApps through 1.7.0, fixed in commit 64e9722, contains a weak cryptographic algorithm vulnerability that allows attackers to compromise user credentials by exploiting the use of MD5 for password ha…
|
CWE-916
Use of Password Hash With Insufficient Computational Effort
|
CVE-2026-25861
|
2026-06-5 01:10 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2126
|
3.6 |
LOW
Local
|
-
|
-
|
A vulnerability has been found in mlrun up to 1.12.0-rc3. This impacts the function mlrun.utils.helpers.calculate_dataframe_hash of the file mlrun/utils/helpers.py of the component DataFrame Hash Han…
|
CWE-327 CWE-328
Use of a Broken or Risky Cryptographic Algorithm Use of Weak Hash
|
CVE-2026-10766
|
2026-06-5 01:10 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2127
|
5.3 |
MEDIUM
Network
|
-
|
-
|
OMICARD EDM developed by ITPison has a Insecure Direct Object Reference vulnerability, allowing unauthenticated remote attackers to modify a specific parameter to obtain user's email address.
|
CWE-639
Authorization Bypass Through User-Controlled Key
|
CVE-2026-10597
|
2026-06-5 01:10 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2128
|
4.3 |
MEDIUM
Network
|
-
|
-
|
A vulnerability was detected in keystonejs keystone up to 20260319. This vulnerability affects unknown code in the library packages/core/src/lib/core/queries/output-field.ts of the component GraphQL …
|
CWE-400 CWE-404
Uncontrolled Resource Consumption Improper Resource Shutdown or Release
|
CVE-2026-10802
|
2026-06-5 01:10 |
2026-06-4 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2129
|
- |
|
-
|
-
|
authentik is an open-source identity provider. Prior to versions 2025.12.5 and 2026.2.3, the SAML source response processor (ResponseProcessor.parse()) does not validate the Conditions element on ass…
|
CWE-345
Insufficient Verification of Data Authenticity
|
CVE-2026-41577
|
2026-06-5 00:49 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2130
|
- |
|
-
|
-
|
authentik is an open-source identity provider. Prior to version 2026.2.3, the WS-Federation provider validates the user-supplied wreply parameter using a raw string prefix check rather than proper UR…
|
CWE-601
Open Redirect
|
CVE-2026-41569
|
2026-06-5 00:49 |
2026-06-3 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|