|
801
|
6.2 |
MEDIUM
Local
|
-
|
-
|
A flaw was found in foreman-mcp-server. This component utilizes two distinct logging mechanisms that can expose sensitive session and authentication data. One mechanism logs session identifiers, whic…
New
|
CWE-532
Inclusion of Sensitive Information in Log Files
|
CVE-2026-9073
|
2026-06-26 01:14 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
802
|
6.5 |
MEDIUM
Network
|
-
|
-
|
jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.21.0 until 2.21.4 and 3.1.4, UnwrappedPropertyHandler.processUnwrappedCreato…
New
|
CWE-863
Incorrect Authorization
|
CVE-2026-54518
|
2026-06-26 01:14 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
803
|
- |
|
-
|
-
|
Incorrect check of function return value in Caliptra Core Runtime Firmware (ActivateFirmwareCmd::activate_fw modules) allows bypass of Caliptra Core's verification of the MCU FW during a hitless upda…
New
|
CWE-253
Incorrect Check of Function Return Value
|
CVE-2026-5818
|
2026-06-26 01:14 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
804
|
- |
|
-
|
-
|
Missing cryptographic step in Caliptra Core Firmware (aes_256_gcm_update module) results in an incorrect GCM authentication tag. When the streaming AES-256-GCM API is used with empty AAD, the hardwar…
New
|
CWE-325
Missing Required Cryptographic Step
|
CVE-2026-6458
|
2026-06-26 01:14 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
805
|
- |
|
-
|
-
|
Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 1.99, the POST /api/v1/admin/send-test-email endpoint accepts attacker-controlled smtpHost and smtpPort values a…
New
|
CWE-209 CWE-918
Information Exposure Through an Error Message Server-Side Request Forgery (SSRF)
|
CVE-2026-49979
|
2026-06-26 01:11 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
806
|
7.5 |
HIGH
Network
|
-
|
-
|
Sentry is an error tracking and performance monitoring tool. From 24.4.0 until 26.5.2, a Regular Expression Denial of Service (ReDoS) vulnerability exists in Sentry's event ingestion pipeline, where …
New
|
CWE-1333
Inefficient Regular Expression Complexity
|
CVE-2026-52794
|
2026-06-26 01:11 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
807
|
- |
|
-
|
-
|
Appsmith is a platform to build admin panels, internal tools, and dashboards. Prior to 2.1, the outbound HTTP host filter applied by WebClientUtils (used by the REST API and GraphQL datasource plugin…
New
|
CWE-918
Server-Side Request Forgery (SSRF)
|
CVE-2026-55455
|
2026-06-26 01:11 |
2026-06-25 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
808
|
3.7 |
LOW
Network
|
-
|
-
|
ImageMagick before 7.1.2-15 contains a memory leak vulnerability in multiple coders that write raw pixel data where allocated objects are not properly freed. Attackers can trigger this leak by proces…
New
|
CWE-401
Missing Release of Memory after Effective Lifetime
|
CVE-2026-56368
|
2026-06-26 01:10 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
809
|
3.3 |
LOW
Local
|
-
|
-
|
ImageMagick before 7.1.2-19 contains an out-of-bounds access vulnerability in ConnectedComponentsImage() when processing connected-components artifacts with invalid indices. Attackers can trigger acc…
New
|
CWE-125
Out-of-bounds Read
|
CVE-2026-56370
|
2026-06-26 01:10 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|
|
810
|
4.3 |
MEDIUM
Network
|
-
|
-
|
hono before 4.12.14 contains an html injection vulnerability in jsx server-side rendering that allows attackers to inject unintended html by using malformed attribute names. Attackers can craft speci…
New
|
CWE-79
Cross-site Scripting
|
CVE-2026-56761
|
2026-06-26 01:10 |
2026-06-24 |
Show
|
GitHub
Exploit DB
Packet Storm
|
|
|