|
1331
|
- |
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
io-wq: check that the predecessor is hashed in io_wq_remove_pending()
io_wq_remove_pending() needs to fix up wq->hash_tail[] if t…
New
|
-
|
CVE-2026-46274
|
2026-06-9 01:16 |
2026-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1332
|
5.4 |
MEDIUM
Network
|
-
|
-
|
IRIS is a web collaborative platform that helps incident responders share technical details during investigations. In versions prior to 2.4.28, users can create alerts for customers that are not assi…
Update
|
CWE-863
Incorrect Authorization
|
CVE-2026-42547
|
2026-06-9 01:16 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1333
|
4.7 |
MEDIUM
Network
|
-
|
-
|
Iris is a web collaborative platform that helps incident responders share technical details during investigations. Versions prior to 2.4.28 contain a weakness where an attacker can misuse it to redir…
Update
|
CWE-602
Client-Side Enforcement of Server-Side Security
|
CVE-2026-42329
|
2026-06-9 01:16 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1334
|
8.8 |
HIGH
Network
|
-
|
-
|
Froxlor is open source server administration software. Version 2.3.6 contains a symlink-following flaw in the root-owned SSH key synchronization path used for customer FTP users. The provisioning cod…
Update
|
CWE-59
Link Following
|
CVE-2026-41236
|
2026-06-9 01:16 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1335
|
7.3 |
HIGH
Network
|
-
|
-
|
A vulnerability was detected in GL.iNet GL-MT3000 4.4.5. This affects the function dlopen in the library /usr/lib/oui-httpd/rpc/ of the component Path Normalization Handler. Performing a manipulation…
Update
|
CWE-74 CWE-77
Injection Command Injection
|
CVE-2026-11450
|
2026-06-9 01:16 |
2026-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1336
|
4.7 |
MEDIUM
Network
|
-
|
-
|
A weakness has been identified in GL.iNet GL-MT3000 up to 4.4.5. The affected element is the function realpath of the file /rpc of the component Minidlna Service. This manipulation of the argument ku…
Update
|
CWE-74 CWE-77
Injection Command Injection
|
CVE-2026-11448
|
2026-06-9 01:16 |
2026-06-7 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1337
|
9.6 |
CRITICAL
Network
|
google
|
chrome
|
Insufficient validation of untrusted input in Enterprise Reporting in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a …
Update
|
CWE-20
Improper Input Validation
|
CVE-2026-11120
|
2026-06-9 01:16 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1338
|
7.2 |
HIGH
Network
|
-
|
-
|
A flaw has been found in Shibby Tomato 1.28.0000. This affects the function start_dhcpc of the file /sbin/rc of the component Web UI. This manipulation causes os command injection. It is possible to …
Update
|
CWE-77 CWE-78
Command Injection OS Command
|
CVE-2026-10870
|
2026-06-9 01:16 |
2026-06-5 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1339
|
- |
|
-
|
-
|
In the Linux kernel, the following vulnerability has been resolved:
drm/vkms: Convert to DRM's vblank timer
Replace vkms' vblank timer with the DRM implementation. The DRM
code is identical in conc…
New
|
-
|
CVE-2025-71315
|
2026-06-9 01:16 |
2026-06-9 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1340
|
4.8 |
MEDIUM
Network
|
checkmk
|
checkmk
|
Stored cross-site scripting in the global settings change log in Checkmk <2.5.0p5, <2.4.0p31, <2.3.0p48, and all 2.2.0 versions allows an administrator who can change global settings to store malicio…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-8078
|
2026-06-9 00:53 |
2026-06-8 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|