|
2051
|
5.4 |
MEDIUM
Network
|
-
|
-
|
IBM TRIRIGA Application Platform 5.0.2 through 5.0.3 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus alter…
|
CWE-79
Cross-site Scripting
|
CVE-2026-11372
|
2026-06-23 03:16 |
2026-06-23 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2052
|
4.3 |
MEDIUM
Network
|
-
|
-
|
The Classified Listing – Classified ads & Business Directory plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 5.4.2. This is due to a missing capabili…
|
CWE-862
Missing Authorization
|
CVE-2026-10779
|
2026-06-23 03:16 |
2026-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2053
|
6.5 |
MEDIUM
Network
|
-
|
-
|
IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data versions 4.8,5.0,5.1,5.2,5.3 could allow an authenticated user to cause a denial of service when creating new databases due to im…
|
CWE-770
Allocation of Resources Without Limits or Throttling
|
CVE-2024-54178
|
2026-06-23 03:16 |
2026-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2054
|
8.1 |
HIGH
Network
|
-
|
-
|
A stored cross-site scripting vulnerability in the Runtime component of Pilz PASvisu before 1.14.1 and PMI v8xx up to and including 2.0.33992 allows a low-privileged remote unauthenticated attacker t…
|
CWE-79
Cross-site Scripting
|
CVE-2023-45796
|
2026-06-23 03:16 |
2026-06-22 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2055
|
6.3 |
MEDIUM
Local
|
-
|
-
|
pam_usb provides hardware authentication for Linux using removable media. In versions prior to 0.9.2, getenv() environment variables XRDP_SESSION, DISPLAY and TMUX allow environment variable injecti…
|
CWE-454 CWE-807
External Initialization of Trusted Variables or Data Stores Reliance on Untrusted Inputs in a Security Decision
|
CVE-2026-48980
|
2026-06-23 02:56 |
2026-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2056
|
6.7 |
MEDIUM
Local
|
-
|
-
|
pam_usb provides hardware authentication for Linux using ordinary removable media. In versions prior to 0.9.2, pam_usb calls xmlReadFile() with flags=0 when loading the configuration file, allowing l…
|
CWE-611
XXE
|
CVE-2026-48981
|
2026-06-23 02:56 |
2026-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2057
|
5.8 |
MEDIUM
Local
|
-
|
-
|
pam_usb provides hardware authentication for Linux using ordinary removable media. In versions prior to 0.9.2, a symlink race condition exists in per-device and per-user pad directory creation. pam_u…
|
CWE-367
Time-of-check Time-of-use (TOCTOU) Race Condition
|
CVE-2026-48983
|
2026-06-23 02:56 |
2026-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2058
|
- |
|
-
|
-
|
A security vulnerability has been identified in FlexNet Manager Suite 2025 R1 that could allow an authenticated user with read-only access to account settings to escalate their privileges to Administ…
|
CWE-284
Improper Access Control
|
CVE-2026-4026
|
2026-06-23 02:54 |
2026-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2059
|
7.5 |
HIGH
Network
|
-
|
-
|
The security fix for CVE-2025-0728 in eclipse-threadx NetX Duo refactors error handling in the HTTP server PUT process to use a shared cleanup label, but this unified cleanup path unconditionally cal…
|
CWE-415 CWE-459 CWE-908
Double Free Incomplete Cleanup Use of Uninitialized Resource
|
CVE-2026-11576
|
2026-06-23 02:53 |
2026-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
2060
|
5.6 |
MEDIUM
Network
|
-
|
-
|
Cloudflare Quiche was affected by 2 use-after-free vulnerabilities in the connection ID iterator FFI functions.
The “quiche_connection_id_iter_next” and “quiche_conn_retired_scid_next” functions w…
|
CWE-416
Use After Free
|
CVE-2026-11941
|
2026-06-23 02:51 |
2026-06-19 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|