Searching...
Please wait while we search the database
| CVE ID | Severity | Description | Published | Actions |
|---|---|---|---|---|
|
CVE-2026-12437
|
N/A |
Use after free in WebShare in Google Chrome on Windows prior to 149.0.7827.155 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
|
17 Jun 2026
|
|
|
CVE-2025-15641
|
MEDIUM |
Netskope was notified about a potential gap in its Netskope Client for Windows systems where a malicious insider with administrative privileges can potentially tamper with the customer IOCTL by sending crafted IOCTL requests to the driver. A successful exploit can result in the bypassing of all anti-tampering protections for the NSClient.Affected Product(s) and Version(s)
* Product Name: Netskope Client
* Affected Platform: Windows
* Affected Version: All version below R138
|
17 Jun 2026
|
|
|
CVE-2026-55706
|
MEDIUM |
sppp_pap_input in sys/net/if_spppsubr.c in OpenBSD before 076e2b1 allows authentication bypass via certain zero values for lengths.
|
17 Jun 2026
|
|
|
CVE-2026-39199
|
LOW |
snes9x 1.63 allows an out-of-bounds write and denial of service via a crafted .ups file.
|
17 Jun 2026
|
|
|
CVE-2026-36418
|
N/A |
JimuReport versions 2.3.4 and below are vulnerable to remote code execution due to improper handling of Aviator expressions. The /jmreport/executeSelectApi endpoint passes user-supplied input directly to the Aviator expression engine without adequate validation allowing attackers to execute arbitrary code.
|
17 Jun 2026
|
|
|
CVE-2025-66391
|
N/A |
In Citrix Cloud through 2025-11-10, an account with read-only access can trigger the beginning of a workflow for write operations, e.g., the system will send a one-time password to an attacker-controlled email address when the attacker attempts to reset the password of a user account.
|
17 Jun 2026
|
|
|
CVE-2025-26240
|
N/A |
In JazzCore python-pdfkit 1.0.0, the from_string method enables the execution of JavaScript code within the context of the server application and the exfiltration of local files.
|
17 Jun 2026
|
|
|
CVE-2026-48616
|
CRITICAL |
Rocket.Chat versions <8.5.1, 8.4.4, 8.3.6, 8.2.6, 8.1.6, 8.0.7, 7.13.9, 7.10.13 has an access control vulnerability in Livechat files. Protected file downloads at /file-upload/:fileId/:name authorize livechat access using rc_room_type=l with rc_rid+rc_token, but the authorization path does not verify that rc_rid matches the requested file's rid. Furthermore, :fileId is predictable via sequential MongoDB IDs, and :name can be anything, allowing unauthenticated discovery of all uploaded files.
|
16 Jun 2026
|
|
|
CVE-2026-48929
|
HIGH |
Rocket.Chat in versions <8.5.1, <8.4.4, <8.3.6, <8.2.6, <8.1.6, <8.0.7, <7.13.9, and <7.10.13 is vulnerable to unauthenticated file deletion. The deleteFileMessage Meteor method permanently deletes any uploaded file by ID without requiring authentication. When called via an unauthenticated DDP WebSocket connection, Meteor.userId() returns null, causing the authorization check to be skipped. Execution falls through to FileUpload.getStore('Uploads').deleteById(fileID), which removes the file from storage and database unconditionally. File IDs are discoverable from public channel message payloads and download URLs.
|
16 Jun 2026
|
|
|
CVE-2026-2604
|
MEDIUM |
A flaw was found in evolution-data-server. Inconsistent comparison logic in the addressbook file backend allows a Flatpak application with D-Bus access to craft a malicious URI containing directory traversal sequences. This URI is stored without proper validation during contact creation or modification. Later, during contact deletion, the URI is processed with a less strict check, leading to the deletion of arbitrary files on the host filesystem. This could potentially include critical Flatpak override files.
|
16 Jun 2026
|
|
|
CVE-2026-25470
|
CRITICAL |
Improper Control of Generation of Code ('Code Injection') vulnerability in ACPT ACPT (Pro) - Custom Post Types Plugin for WordPress allows Remote Code Inclusion.
This issue affects ACPT (Pro) - Custom Post Types Plugin for WordPress: from n/a through 2.0.47.
|
16 Jun 2026
|
|
|
CVE-2026-39598
|
HIGH |
Unrestricted Upload of File with Dangerous Type vulnerability in Kodezen LLC Academy LMS Pro allows Upload a Web Shell to a Web Server.
This issue affects Academy LMS Pro: from n/a before 3.5.2.
|
16 Jun 2026
|
|
|
CVE-2026-49073
|
HIGH |
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in wpWax Directorist Booking allows Blind SQL Injection.
This issue affects Directorist Booking: from n/a through 3.0.3.
|
16 Jun 2026
|
|
|
CVE-2026-11409
|
HIGH |
An authenticated OS command injection vulnerability exists in the IPv6 PPPoE configuration handler in TL-WR940N v6 due to improper sanitization of user input. An attacker with administrative access may exploit this issue to execute arbitrary system commands with elevated privileges.
|
16 Jun 2026
|
|
|
CVE-2026-11410
|
HIGH |
An authenticated OS command injection vulnerability exists in the BigPond Cable (BPA) WAN configuration module in TL-WR940N v6 due to improper sanitization of user input. An attacker with administrative access may exploit this issue to execute arbitrary system commands with elevated privileges.
|
16 Jun 2026
|
|
|
CVE-2026-49113
|
HIGH |
Subscriber Arbitrary Code Execution in Cornerstone < 7.8.8 versions.
|
16 Jun 2026
|
|
|
CVE-2026-49080
|
CRITICAL |
Unauthenticated SQL Injection in wpDataTables <= 7.3.6 versions.
|
16 Jun 2026
|
|
|
CVE-2026-49057
|
HIGH |
Unauthenticated Broken Access Control in JobSearch <= 3.2.7 versions.
|
16 Jun 2026
|
|
|
CVE-2026-48869
|
HIGH |
Unauthenticated Cross Site Scripting (XSS) in Enfold <= 7.1.4 versions.
|
16 Jun 2026
|
|
|
CVE-2026-40761
|
HIGH |
Unauthenticated PHP Object Injection in Valeska <= 1.2.2 versions.
|
16 Jun 2026
|
|
|
CVE-2026-40760
|
HIGH |
Unauthenticated PHP Object Injection in Behold <= 1.5 versions.
|
16 Jun 2026
|
|
|
CVE-2026-40759
|
HIGH |
Unauthenticated PHP Object Injection in Esmée <= 1.4 versions.
|
16 Jun 2026
|
|
|
CVE-2026-40758
|
HIGH |
Unauthenticated PHP Object Injection in Léonie <= 1.2.1 versions.
|
16 Jun 2026
|
|
|
CVE-2026-40755
|
HIGH |
Unauthenticated PHP Object Injection in TechLink <= 1.3 versions.
|
16 Jun 2026
|
|
|
CVE-2026-40754
|
HIGH |
Unauthenticated PHP Object Injection in Roisin <= 1.4 versions.
|
16 Jun 2026
|
CVE-2026-12437
N/A
17 Jun 2026
Use after free in WebShare in Google Chrome on Windows prior to 149.0.7827.155 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Critical)
CVE-2025-15641
MEDIUM
17 Jun 2026
Netskope was notified about a potential gap in its Netskope Client for Windows systems where a malicious insider with administrative privileges can potentially tamper with the customer IOCTL by sending crafted IOCTL requests to the driver. A successful exploit can result in the bypassing of all anti-tampering protections for the NSClient.Affected Product(s) and Version(s)
* Product Name: Netskope Client
* Affected Platform: Windows
* Affected Version: All version below R138
CVE-2026-55706
MEDIUM
17 Jun 2026
sppp_pap_input in sys/net/if_spppsubr.c in OpenBSD before 076e2b1 allows authentication bypass via certain zero values for lengths.
CVE-2026-39199
LOW
17 Jun 2026
snes9x 1.63 allows an out-of-bounds write and denial of service via a crafted .ups file.
CVE-2026-36418
N/A
17 Jun 2026
JimuReport versions 2.3.4 and below are vulnerable to remote code execution due to improper handling of Aviator expressions. The /jmreport/executeSelectApi endpoint passes user-supplied input directly to the Aviator expression engine without adequate validation allowing attackers to execute arbitrary code.
CVE-2025-66391
N/A
17 Jun 2026
In Citrix Cloud through 2025-11-10, an account with read-only access can trigger the beginning of a workflow for write operations, e.g., the system will send a one-time password to an attacker-controlled email address when the attacker attempts to reset the password of a user account.
CVE-2025-26240
N/A
17 Jun 2026
In JazzCore python-pdfkit 1.0.0, the from_string method enables the execution of JavaScript code within the context of the server application and the exfiltration of local files.
CVE-2026-48616
CRITICAL
16 Jun 2026
Rocket.Chat versions <8.5.1, 8.4.4, 8.3.6, 8.2.6, 8.1.6, 8.0.7, 7.13.9, 7.10.13 has an access control vulnerability in Livechat files. Protected file downloads at /file-upload/:fileId/:name authorize livechat access using rc_room_type=l with rc_rid+rc_token, but the authorization path does not verify that rc_rid matches the requested file's rid. Furthermore, :fileId is predictable via sequential MongoDB IDs, and :name can be anything, allowing unauthenticated discovery of all uploaded files.
CVE-2026-48929
HIGH
16 Jun 2026
Rocket.Chat in versions <8.5.1, <8.4.4, <8.3.6, <8.2.6, <8.1.6, <8.0.7, <7.13.9, and <7.10.13 is vulnerable to unauthenticated file deletion. The deleteFileMessage Meteor method permanently deletes any uploaded file by ID without requiring authentication. When called via an unauthenticated DDP WebSocket connection, Meteor.userId() returns null, causing the authorization check to be skipped. Execution falls through to FileUpload.getStore('Uploads').deleteById(fileID), which removes the file from storage and database unconditionally. File IDs are discoverable from public channel message payloads and download URLs.
CVE-2026-2604
MEDIUM
16 Jun 2026
A flaw was found in evolution-data-server. Inconsistent comparison logic in the addressbook file backend allows a Flatpak application with D-Bus access to craft a malicious URI containing directory traversal sequences. This URI is stored without proper validation during contact creation or modification. Later, during contact deletion, the URI is processed with a less strict check, leading to the deletion of arbitrary files on the host filesystem. This could potentially include critical Flatpak override files.
CVE-2026-25470
CRITICAL
16 Jun 2026
Improper Control of Generation of Code ('Code Injection') vulnerability in ACPT ACPT (Pro) - Custom Post Types Plugin for WordPress allows Remote Code Inclusion.
This issue affects ACPT (Pro) - Custom Post Types Plugin for WordPress: from n/a through 2.0.47.
CVE-2026-39598
HIGH
16 Jun 2026
Unrestricted Upload of File with Dangerous Type vulnerability in Kodezen LLC Academy LMS Pro allows Upload a Web Shell to a Web Server.
This issue affects Academy LMS Pro: from n/a before 3.5.2.
CVE-2026-49073
HIGH
16 Jun 2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in wpWax Directorist Booking allows Blind SQL Injection.
This issue affects Directorist Booking: from n/a through 3.0.3.
CVE-2026-11409
HIGH
16 Jun 2026
An authenticated OS command injection vulnerability exists in the IPv6 PPPoE configuration handler in TL-WR940N v6 due to improper sanitization of user input. An attacker with administrative access may exploit this issue to execute arbitrary system commands with elevated privileges.
CVE-2026-11410
HIGH
16 Jun 2026
An authenticated OS command injection vulnerability exists in the BigPond Cable (BPA) WAN configuration module in TL-WR940N v6 due to improper sanitization of user input. An attacker with administrative access may exploit this issue to execute arbitrary system commands with elevated privileges.
CVE-2026-49113
HIGH
16 Jun 2026
Subscriber Arbitrary Code Execution in Cornerstone < 7.8.8 versions.
CVE-2026-49080
CRITICAL
16 Jun 2026
Unauthenticated SQL Injection in wpDataTables <= 7.3.6 versions.
CVE-2026-49057
HIGH
16 Jun 2026
Unauthenticated Broken Access Control in JobSearch <= 3.2.7 versions.
CVE-2026-48869
HIGH
16 Jun 2026
Unauthenticated Cross Site Scripting (XSS) in Enfold <= 7.1.4 versions.
CVE-2026-40761
HIGH
16 Jun 2026
Unauthenticated PHP Object Injection in Valeska <= 1.2.2 versions.
CVE-2026-40760
HIGH
16 Jun 2026
Unauthenticated PHP Object Injection in Behold <= 1.5 versions.
CVE-2026-40759
HIGH
16 Jun 2026
Unauthenticated PHP Object Injection in Esmée <= 1.4 versions.
CVE-2026-40758
HIGH
16 Jun 2026
Unauthenticated PHP Object Injection in Léonie <= 1.2.1 versions.
CVE-2026-40755
HIGH
16 Jun 2026
Unauthenticated PHP Object Injection in TechLink <= 1.3 versions.
CVE-2026-40754
HIGH
16 Jun 2026
Unauthenticated PHP Object Injection in Roisin <= 1.4 versions.
Page 379 of 400
Page 379 of 400