|
601
|
5.3 |
MEDIUM
Network
|
-
|
-
|
Hermes WebUI before version 0.51.270 contains a resource exhaustion vulnerability that allows unauthenticated remote attackers to degrade service availability by repeatedly calling the passkey option…
New
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2026-49955
|
2026-06-10 02:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
602
|
6.5 |
MEDIUM
Network
|
-
|
-
|
The Apache Airflow Samba provider's `GCSToSambaOperator` joined GCS object names to the SMB destination path without a containment check, so an object named with `../` segments resolved a write path …
New
|
CWE-22
Path Traversal
|
CVE-2026-49818
|
2026-06-10 02:17 |
2026-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
603
|
7.8 |
HIGH
Local
|
-
|
-
|
Improper access control in Microsoft PC Manager allows an authorized attacker to bypass a security feature locally.
New
|
CWE-284
Improper Access Control
|
CVE-2026-49161
|
2026-06-10 02:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
604
|
7.1 |
HIGH
Local
|
-
|
-
|
Improper input validation in Visual Studio Code allows an unauthorized attacker to bypass a security feature locally.
New
|
CWE-20 CWE-23
Improper Input Validation Relative Path Traversal
|
CVE-2026-48569
|
2026-06-10 02:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
605
|
7.8 |
HIGH
Local
|
-
|
-
|
Untrusted search path in Windows Narrator Braille allows an authorized attacker to elevate privileges locally.
New
|
CWE-426
Untrusted Search Path
|
CVE-2026-48565
|
2026-06-10 02:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
606
|
4.6 |
MEDIUM
Network
|
-
|
-
|
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-48562
|
2026-06-10 02:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
607
|
5.4 |
MEDIUM
Network
|
-
|
-
|
Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Office SharePoint allows an authorized attacker to perform spoofing over a network.
New
|
CWE-502
Deserialization of Untrusted Data
|
CVE-2026-48560
|
2026-06-10 02:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
608
|
7.5 |
HIGH
Network
|
-
|
-
|
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
New
|
CWE-416
Use After Free
|
CVE-2026-47654
|
2026-06-10 02:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
609
|
8.8 |
HIGH
Network
|
-
|
-
|
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
New
|
CWE-416
Use After Free
|
CVE-2026-47653
|
2026-06-10 02:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
610
|
9.8 |
CRITICAL
Network
|
-
|
-
|
External control of file name or path in Azure Stack Edge allows an unauthorized attacker to execute code over a network.
New
|
CWE-73
External Control of File Name or Path
|
CVE-2026-47643
|
2026-06-10 02:17 |
2026-06-10 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|