|
1081
|
7.3 |
HIGH
Network
|
-
|
-
|
It is possible to bypass the Kerberos pre-authentication check in Apache Kerby by sending a PA-DATA with an unrecognized or unsupported type. Users are recommended to upgrade to version 2.1.2, which …
|
CWE-304
Missing Critical Step in Authentication
|
CVE-2026-57915
|
2026-06-27 00:16 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1082
|
7.5 |
HIGH
Network
|
-
|
-
|
An issue in the pthread_rwlockattr_setpshared() function of relibc commit 61f42d allows attackers to cause a Denial of Service (DoS) via a crafted input.
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2026-38637
|
2026-06-27 00:16 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1083
|
7.5 |
HIGH
Network
|
-
|
-
|
Insecure Permissions vulnerability in MSI NBFoundation Service v.2.0.2506.1201 allows a remote attacker to obtain sensitive information via the 3DES-ECB encryption
|
CWE-200
Information Exposure
|
CVE-2026-37454
|
2026-06-27 00:16 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1084
|
7.5 |
HIGH
Network
|
-
|
-
|
Insecure Permissions vulnerability in MSI NBFoundation Service v.2.0.2506.1201 allows a remote attacker to obtain sensitive information via the MSI_SERVICE_2 pipe
|
CWE-200
Information Exposure
|
CVE-2026-37453
|
2026-06-27 00:16 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1085
|
7.5 |
HIGH
Network
|
-
|
-
|
Insecure Permissions vulnerability in MSI NBFoundation Service v.2.0.2506.1201 allows a remote attacker to obtain sensitive information via the MSIAPService.exe component
|
CWE-200
Information Exposure
|
CVE-2026-37452
|
2026-06-27 00:16 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1086
|
7.7 |
HIGH
Local
|
-
|
-
|
GROCERY-STORE-MANAGEMENT-SYSTEM-USING-PHP-AND-MYSQL-PHPMYADMIN v1.0 was discovered to contain a SQL injection vulnerability in the scost parameter in /grocery/search_products.php. This vulnerability …
|
CWE-89
SQL Injection
|
CVE-2026-37149
|
2026-06-27 00:16 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1087
|
- |
|
-
|
-
|
FOSSBilling is a free, open-source billing and client management system. In versions 0.7.2 and prior, a query-construction flaw in client list endpoints allowed authenticated clients to bypass tenant…
|
CWE-863
Incorrect Authorization
|
CVE-2026-23513
|
2026-06-27 00:16 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1088
|
6.5 |
MEDIUM
Network
|
-
|
-
|
By sending a deeply nested ASN1 structure to a Apache Kerby client or service, it's possible to trigger a StackOverFlow Exception which can lead to denial of service issues. Users are recommended to …
|
CWE-400
Uncontrolled Resource Consumption
|
CVE-2026-57914
|
2026-06-26 23:51 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1089
|
- |
|
-
|
-
|
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache IoTDB.
This issue affects Apache IoTDB: from 2.0.0 before 2.0.6, from 1.0.0 before 1.3.6.
User…
|
CWE-22
Path Traversal
|
CVE-2025-55017
|
2026-06-26 23:51 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
1090
|
- |
|
-
|
-
|
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache IoTDB.
This issue affects Apache IoTDB: from 1.0.0 before 1.3.6, from 2.0.0 before 2.0.7.
User…
|
CWE-22
Path Traversal
|
CVE-2025-64152
|
2026-06-26 23:51 |
2026-06-26 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|