CVE zaktualizowane w ostatnich 24 godzinach — 200 wpisów. Mogą zawierać nowe CVSS, EPSS, informacje o patchu lub zmiany statusu KEV.

CVE-2026-48995 🟡 Monitoruj

pnpm is a package manager. Prior to 10.33.4 and 11.0.7, a malicious codeload.github.com server can serve whatever tarball it wants and pnpm will install it regardless of the lockfile. The lockfile does not store the hash…

7.5 CVSS
0.1% EPSS
pnpmexploit 2026-06-25
CVE-2026-50739 ⚪ Do wiadomości

A bypass for CVE‑2026‑34913 exists with proper ownership validation that had not been applied to the reverse operation of linking campaigns and trackers through the `tracker-campaigns.php` script in Revive Adserver 6.0.7…

4.3 CVSS
0.2% EPSS
revive-adserver 2026-06-26
CVE-2026-50740 ⚪ Do wiadomości

A missing sanitisation vulnerability of user input in the zone-include.php script exists in Revive Adserver 6.0.7 and earlier. A low‑privileged user could exploit the refresh parameter of the iFrame invocation tag to per…

5.4 CVSS
0.1% EPSS
revive-adserverxss 2026-06-26
CVE-2026-50741 🟡 Monitoruj

Bypass to the fix for CVE-2026-34916. Variants of such vectors have been also reported by phucrio and offsetmd. The fix can be bypassed either by sending a disallowed but otherwise valid plugin identifier as `type`, or u…

8.8 CVSS
0.3% EPSS
revive-adserver 2026-06-26
CVE-2026-50742 ⚪ Do wiadomości

A stored XSS vulnerabilities exists in the `maintenance-acl-check.php` and `maintenance-banners-check.php` tools of Revive Adserver 6.0.7. The issue was caused by entity names being displayed without proper escaping when…

5.4 CVSS
0.1% EPSS
revive-adserverxss 2026-06-26
CVE-2026-50744 ⚪ Do wiadomości

A bypass to the admin‑only restriction of the XML‑RPC API in Revive Adserver 6.0.7. The API response for the ox.login method returned a session ID cookie in the HTTP headers, and although the method correctly returned an…

4.3 CVSS
0.2% EPSS
revive-adserver 2026-06-26
CVE-2026-9643 🟡 Monitoruj

The WP Meta SEO plugin for WordPress is vulnerable to Unauthenticated Stored Cross-Site Scripting via the REQUEST_URI server variable in all versions up to, and including, 4.5.18. When the plugin's `wpmsTemplateRedirect(…

7.2 CVSS
0.2% EPSS
xss 2026-06-24
CVE-2026-9183 ⚪ Do wiadomości

The 24liveblog - live blog tool plugin for WordPress is vulnerable to Exposure of Sensitive Information in versions up to, and including, 2.2. This is due to the lb24_block_enqueue_scripts() function being hooked to enqu…

4.3 CVSS
0.2% EPSS
2026-06-24
CVE-2026-9233 ⚪ Do wiadomości

The Quiz and Survey Master (QSM) – Easy Quiz and Survey Maker plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 11.1.4. This is due to the plugin not properly verifying that…

4.3 CVSS
0.3% EPSS
2026-06-27
CVE-2026-58000 🟡 Monitoruj

luci-proto-openvpn through 0.11.1, fixed in commit e4ff45e, contains a command injection vulnerability in the generateKey ubus method where the cl_meta parameter is interpolated into a shell command without proper escapi…

8.8 CVSS
0.0% EPSS
rce 2026-06-29
CVE-2026-57959 ⚪ Do wiadomości

Hi.Events through 1.9.0 contains a promo code validation vulnerability where reservation validates usage count before asynchronous UpdateEventStatisticsJob increments it, allowing attackers to redeem limited promo codes …

5.9 CVSS
0.0% EPSS
2026-06-29
CVE-2026-57498 🟠 Łataj w tym tygodniu

Coolify is an open-source and self-hostable tool for managing servers, applications, and databases. Prior to 4.0.0-beta.474, Coolify's API controllers consistently validate server ownership with Server::whereTeamId($team…

9.6 CVSS
0.0% EPSS
2026-06-29
CVE-2026-57947 🟡 Monitoruj

Pinpoint through 3.1.0 contains a server-side request forgery vulnerability in the webhook registration endpoint that allows authenticated users to register internal URLs due to missing SSRF protection. Attackers can tri…

8.5 CVSS
0.0% EPSS
ssrf 2026-06-29
CVE-2026-57950 🟡 Monitoruj

ruoyi-vue-pro through 2026.05, fixed in commit 5d1fd70 contains a broken access control vulnerability in ErpSaleOrderController that allows attackers with erp:sale-out permissions to gain unauthorized access to sale orde…

8.1 CVSS
0.0% EPSS
2026-06-29
CVE-2026-57919 🟡 Monitoruj

PBackupVSS.exe in Matrix42 Empirum before 25.5 and 26.x before 26.2 creates a named pipe (\\.\pipe\PBackupVSS) with a DACL that grants GENERIC_READ and GENERIC_WRITE permissions to all authenticated users. A low-privileg…

7.8 CVSS
0.0% EPSS
CVE-2026-57956 ⚪ Do wiadomości

SigNoz through 0.130.1 contains a broken access control vulnerability that allows authenticated users to access other organizations' alert rules by supplying a target rule UUID, as the alert rule store predicates fail to…

6.4 CVSS
0.0% EPSS
2026-06-29
CVE-2026-57943 ⚪ Do wiadomości

LibrePhotos before 1.0.0 contains a broken object level authorization vulnerability in the SetPhotosShared endpoint that allows authenticated users to grant themselves access to other users' private photos by bypassing o…

5.9 CVSS
0.0% EPSS
2026-06-29
CVE-2026-57953 ⚪ Do wiadomości

Mythic before 3.4.0.60 contains an authorization bypass vulnerability that allows authenticated spectator-role users to perform unauthorized write operations by accessing the eventing_import_automatic_webhook endpoint re…

5.4 CVSS
0.0% EPSS
2026-06-29
CVE-2026-56782 🟠 Łataj w tym tygodniu

Gorse before 0.5.10 contains an authentication bypass vulnerability in the /api/dump and /api/restore endpoints that allows unauthenticated attackers to access protected functionality when admin_api_key is empty, which i…

9.8 CVSS
0.0% EPSS
auth-bypass 2026-06-29
CVE-2026-56285 🟡 Monitoruj

Nitter's /video media proxy endpoint fails to validate target URLs against Twitter/X domains and uses a hardcoded default HMAC key, allowing unauthenticated attackers to compute valid HMACs for arbitrary URLs. Attackers …

8.6 CVSS
0.0% EPSS
2026-06-29
CVE-2026-53429 ⚪ Do wiadomości

Missing Release of Memory after Effective Lifetime vulnerability in leandrocp mdex and mdex_native allows an attacker who controls a rendered document to cause a denial of service through unbounded native memory exhausti…

0.0 CVSS
0.0% EPSS
dos 2026-06-29
CVE-2026-54888 ⚪ Do wiadomości

Uncontrolled Recursion vulnerability in leandrocp mdex allows denial of service via deeply nested Markdown input. mdex converts between an Elixir %MDEx.Document{} struct and Comrak's internal AST using two mutually recu…

0.0 CVSS
0.0% EPSS
buffer-overflowdos 2026-06-29
CVE-2026-54889 ⚪ Do wiadomości

Improper Neutralization of Input During Web Page Generation (XSS) vulnerability in leandrocp mdex allows cross-site scripting via unsanitized URL schemes in Quill Delta output. 'Elixir.MDEx':to_delta/2 converts Markdown…

0.0 CVSS
0.0% EPSS
xss 2026-06-29
CVE-2026-56017 ⚪ Do wiadomości

JavaScript::Minifier::XS versions before 0.16 for Perl crash with a NULL pointer dereference when the first meaningful token of the input is a slash. The regexp versus division disambiguator in JsTokenizeString (XS.xs) …

0.0 CVSS
0.0% EPSS
dos 2026-06-29
CVE-2026-56018 ⚪ Do wiadomości

JavaScript::Minifier::XS versions before 0.16 for Perl leak memory on every call to minify(), allowing unbounded memory growth. In JsMinify (XS.xs) the cleanup frees only the NodeSet structures and never the per-token c…

0.0 CVSS
0.0% EPSS
dos 2026-06-29
CVE-2026-48558 🔴 Łataj teraz KEV

SimpleHelp versions 5.5.15 and prior and 6.0 pre-release versions contain an authentication bypass vulnerability in the OIDC authentication flow. When OIDC authentication is configured, identity tokens submitted during l…

10.0 CVSS
0.7% EPSS
auth-bypass 2026-06-12
CVE-2026-49416 🟡 Monitoruj

The CONS_HISTORY ioctl handler did not adequately validate the requested history size. A large value caused an integer overflow in the buffer size calculation, resulting in a heap allocation smaller than expected. Subs…

7.8 CVSS
0.1% EPSS
2026-06-27
CVE-2026-4610 ⚪ Do wiadomości

The ProfileGrid – User Profiles, Groups and Communities plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'pm_author_message' parameter in the pm_send_message_to_author function in all versions up…

6.4 CVSS
0.2% EPSS
xss 2026-06-23
CVE-2026-53427 ⚪ Do wiadomości

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in leandrocp MDEx allows stored or reflected cross-site scripting via attacker-controlled Markdown. When syntax highligh…

0.0 CVSS
0.0% EPSS
xss 2026-06-29
CVE-2026-53428 ⚪ Do wiadomości

Memory Allocation with Excessive Size Value vulnerability in leandrocp mdex allows an unauthenticated attacker to cause a denial of service through unbounded memory allocation. comrak_nif::lumis_adapter::LumisAdapter::p…

0.0 CVSS
0.0% EPSS
dos 2026-06-29
CVE-2026-53426 ⚪ Do wiadomości

Allocation of Resources Without Limits or Throttling vulnerability in leandrocp MDEx allows Excessive Allocation. MDEx.parse_document/2 accepts a {:json, json} source. In lib/mdex.ex, the private json_to_node/1 function…

0.0 CVSS
0.0% EPSS
2026-06-29
CVE-2026-43726 ⚪ Do wiadomości

A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. Processing maliciously crafted web content may lead to an unex…

0.0 CVSS
0.0% EPSS
2026-06-29
CVE-2026-43727 ⚪ Do wiadomości

A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. Processing maliciously crafted web content may lead to an unex…

0.0 CVSS
0.0% EPSS
2026-06-29
CVE-2026-43731 ⚪ Do wiadomości

A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. Processing maliciously crafted web content may lead to memory …

0.0 CVSS
0.0% EPSS
2026-06-29
CVE-2026-43732 ⚪ Do wiadomości

A path handling issue was addressed with improved validation. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. Processing maliciously crafted web content may disclose sensitive user…

0.0 CVSS
0.0% EPSS
2026-06-29
CVE-2026-43734 ⚪ Do wiadomości

A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. Processing maliciously crafted web content may lead to an unex…

0.0 CVSS
0.0% EPSS
2026-06-29
CVE-2026-43735 ⚪ Do wiadomości

The issue was addressed with improved checks. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. A malicious website may exfiltrate data cross-origin.

0.0 CVSS
0.0% EPSS
2026-06-29
CVE-2026-43740 ⚪ Do wiadomości

The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. Processing maliciously crafted web content may result in the disclosure of pr…

0.0 CVSS
0.0% EPSS
2026-06-29
CVE-2026-43742 ⚪ Do wiadomości

A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. Processing maliciously crafted web content may lead to an unex…

0.0 CVSS
0.0% EPSS
2026-06-29
CVE-2026-43743 ⚪ Do wiadomości

A race condition was addressed with improved state handling. This issue is fixed in iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. An app may be able to cause unexpected system termination.

0.0 CVSS
0.0% EPSS
2026-06-29
CVE-2026-43745 ⚪ Do wiadomości

An out-of-bounds write issue was addressed with improved input validation. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. Processing maliciously crafted web content may lead to an…

0.0 CVSS
0.0% EPSS
2026-06-29
CVE-2026-43746 ⚪ Do wiadomości

A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. Processing maliciously crafted web content may lead to an unex…

0.0 CVSS
0.0% EPSS
2026-06-29
CVE-2026-43713 ⚪ Do wiadomości

A permissions issue was addressed with additional restrictions. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. Visiting a website may leak sensitive data.

0.0 CVSS
0.0% EPSS
2026-06-29
CVE-2026-43715 ⚪ Do wiadomości

A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. Processing maliciously crafted web content may lead to memory …

0.0 CVSS
0.0% EPSS
2026-06-29
CVE-2026-43716 ⚪ Do wiadomości

The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. Processing maliciously crafted web content may lead to an unexpected Safari c…

0.0 CVSS
0.0% EPSS
2026-06-29
CVE-2026-43717 ⚪ Do wiadomości

A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. Processing maliciously crafted web content may lead to an unex…

0.0 CVSS
0.0% EPSS
2026-06-29
CVE-2026-43718 ⚪ Do wiadomości

A stack overflow was addressed with improved input validation. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. Processing maliciously crafted web content may lead to an unexpected …

0.0 CVSS
0.0% EPSS
buffer-overflow 2026-06-29
CVE-2026-43720 ⚪ Do wiadomości

A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. Processing maliciously crafted web content may lead to an unex…

0.0 CVSS
0.0% EPSS
2026-06-29
CVE-2026-43721 ⚪ Do wiadomości

This issue was addressed through improved state management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. A malicious website may be able to silently hijack clipboard data.

0.0 CVSS
0.0% EPSS
2026-06-29
CVE-2026-43722 ⚪ Do wiadomości

The issue was addressed with improved input sanitization. This issue is fixed in iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. An app may be able to leak sensitive kernel state.

0.0 CVSS
0.0% EPSS
2026-06-29
CVE-2026-43724 ⚪ Do wiadomości

The issue was addressed with improved input sanitization. This issue is fixed in iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. An app may be able to cause unexpected system termination or write kernel memory.

0.0 CVSS
0.0% EPSS
2026-06-29
CVE-2026-43725 ⚪ Do wiadomości

The issue was addressed with improved input validation. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. A malicious website may be able to process restricted web content outside th…

0.0 CVSS
0.0% EPSS
2026-06-29
CVE-2026-43700 ⚪ Do wiadomości

A cross-origin issue was addressed with improved tracking of security origins. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. Processing maliciously crafted web content may disclo…

0.0 CVSS
0.0% EPSS
2026-06-29
CVE-2026-43701 ⚪ Do wiadomości

The issue was addressed with improved checks. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. A malicious website may be able to process restricted web content outside the sandbox.

0.0 CVSS
0.0% EPSS
2026-06-29
CVE-2026-43703 ⚪ Do wiadomości

The issue was addressed with improved memory handling. This issue is fixed in iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. Processing maliciously crafted web content may lead to an unexpected process crash.

0.0 CVSS
0.0% EPSS
2026-06-29
CVE-2026-43704 ⚪ Do wiadomości

A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. A malicious web extension may be able to cause an unexpected p…

0.0 CVSS
0.0% EPSS
2026-06-29
CVE-2026-43705 ⚪ Do wiadomości

A type confusion issue was addressed with improved checks. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. Processing maliciously crafted web content may lead to memory corruption.

0.0 CVSS
0.0% EPSS
2026-06-29
CVE-2026-43706 ⚪ Do wiadomości

A double free issue was addressed with improved memory management. This issue is fixed in iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. Processing maliciously crafted web content may lead to an unexpected process cra…

0.0 CVSS
0.0% EPSS
2026-06-29
CVE-2026-43707 ⚪ Do wiadomości

A memory corruption issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. Processing maliciously crafted web content may lead to an une…

0.0 CVSS
0.0% EPSS
2026-06-29
CVE-2026-43708 ⚪ Do wiadomości

The issue was addressed with improved input validation. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. A malicious website may exfiltrate data cross-origin.

0.0 CVSS
0.0% EPSS
2026-06-29
CVE-2026-43709 ⚪ Do wiadomości

A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. Processing maliciously crafted web content may lead to an unex…

0.0 CVSS
0.0% EPSS
2026-06-29
CVE-2026-43712 ⚪ Do wiadomości

The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. Processing maliciously crafted web content may lead to an unexpected process …

0.0 CVSS
0.0% EPSS
2026-06-29
CVE-2026-40682 🟠 Łataj w tym tygodniu
apps

XML External Entity (XXE) via Unsanitized Dictionary Parsing in Apache OpenNLP DictionaryEntryPersistor Versions Affected: before 2.5.9, before 3.0.0-M3 Description: The DictionaryEntryPersistor class initializes a s…

9.1 CVSS
0.4% EPSS
apachessrfxxe 2026-05-04
CVE-2026-42027 🟠 Łataj w tym tygodniu
apps

Arbitrary Class Instantiation via Model Manifest in Apache OpenNLP ExtensionLoader Versions Affected: before 1.9.5, before 2.5.9, before 3.0.0-M3 Description:  The ExtensionLoader.instantiateExtension(Class, S…

9.8 CVSS
0.7% EPSS
apacherce 2026-05-04
CVE-2026-42440 🟡 Monitoruj
apps

OOM Denial of Service via Unbounded Array Allocation in Apache OpenNLP AbstractModelReader  Versions Affected:  before 1.9.5 before 2.5.9 before 3.0.0-M3  Description: The AbstractModelReader methods getOutcomes(),…

7.5 CVSS
0.5% EPSS
CVE-2026-39872 ⚪ Do wiadomości

The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. Processing maliciously crafted web content may lead to an unexpected process …

0.0 CVSS
0.0% EPSS
2026-06-29
CVE-2026-43663 ⚪ Do wiadomości

The issue was addressed with improved memory handling. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. Processing maliciously crafted web content may lead to an unexpected process …

0.0 CVSS
0.0% EPSS
2026-06-29
CVE-2026-43676 ⚪ Do wiadomości

An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. Processing maliciously crafted web content may lead to an…

0.0 CVSS
0.0% EPSS
2026-06-29
CVE-2026-43699 ⚪ Do wiadomości

A use-after-free issue was addressed with improved memory management. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. Processing maliciously crafted web content may lead to an unex…

0.0 CVSS
0.0% EPSS
2026-06-29
CVE-2026-13762 🟠 Łataj w tym tygodniu

Inconsistent interpretation of HTTP/2 requests in Amazon CloudFront with AWS WAF enabled might allow remote actors to bypass AWS WAF managed rule body inspection via crafted HTTP/2 requests that fragment the request body…

9.8 CVSS
0.0% EPSS
2026-06-29
CVE-2026-13763 🟠 Łataj w tym tygodniu

Inconsistent interpretation of HTTP/2 requests in AWS Application Load Balancer with AWS WAF enabled might allow remote actors to bypass AWS WAF managed rule body inspection via crafted HTTP/2 requests that fragment the …

9.8 CVSS
0.0% EPSS
2026-06-29
CVE-2026-36848 🟡 Monitoruj

Gigamon GVOS v5.16.1 and below is vulnerable to Directory Traversal in the GVOS H-VUE subsystem.

7.5 CVSS
0.0% EPSS
path-traversal 2026-06-29
CVE-2026-13757 ⚪ Do wiadomości

A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_message_get_attribute_array_value() form a mutually-recursive call chain with no recursion depth limit …

6.2 CVSS
0.0% EPSS
2026-06-29
CVE-2026-28979 ⚪ Do wiadomości

An out-of-bounds access issue was addressed with improved bounds checking. This issue is fixed in Safari 26.5.2, iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. Processing maliciously crafted web content may lead to an…

0.0 CVSS
0.0% EPSS
2026-06-29
CVE-2026-31016 ⚪ Do wiadomości

Cross Site Request Forgery vulnerability in Squidex.io Squidex CMS v.7.21.0 and before allows a remote attacker to escalate privileges via the IdentityServer account profile endpoint

0.0 CVSS
0.0% EPSS
2026-06-29
CVE-2026-37637 ⚪ Do wiadomości

An issue in Alexantr filemanager v.1.0 allows a remote attacker to execute arbitrary code via the filemanager.php component

0.0 CVSS
0.0% EPSS
2026-06-29
CVE-2026-39868 ⚪ Do wiadomości

This issue was addressed with improved input validation. This issue is fixed in iOS 26.5.2 and iPadOS 26.5.2, macOS Tahoe 26.5.2. An app may be able to cause unexpected system termination or corrupt kernel memory.

0.0 CVSS
0.0% EPSS
2026-06-29
CVE-2025-70101 ⚪ Do wiadomości

An out-of-bounds read in the ext4_ext_binsearch_idx function in src/ext4_extent.c of the lwext4 1.0.0 library allows attackers to cause a denial of service by supplying a specially crafted ext4 filesystem image. The vuln…

6.5 CVSS
0.3% EPSS
gkostkadosexploit 2026-06-03
CVE-2026-12417 🟠 Łataj w tym tygodniu

The SignUp & SignIn plugin for WordPress is vulnerable to Authentication Bypass via Weak Password Reset Validation leading to Account Takeover in versions up to, and including, 1.0.0. This is due to the `pravel_change_pa…

9.8 CVSS
0.4% EPSS
CVE-2026-11370 ⚪ Do wiadomości

The WP Meta SEO plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 4.5.18 via the 'new_link' parameter. This makes it possible for authenticated attackers, with contri…

6.4 CVSS
0.2% EPSS
ssrf 2026-06-24
CVE-2026-11356 ⚪ Do wiadomości

The Ivory Search – WordPress Search Plugin plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'menu_title' and 'menu_magnifier_color' Settings in all versions up to, and including, 5.5.15 due to insuff…

4.4 CVSS
0.3% EPSS
xss 2026-06-27
CVE-2026-11987 ⚪ Do wiadomości

The Dokan: AI Powered WooCommerce Multivendor Marketplace Solution – Build Your Own Amazon, eBay, Etsy plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.0.4 vi…

4.3 CVSS
0.3% EPSS
2026-06-27
CVE-2026-12077 🟡 Monitoruj

The Dokan Pro plugin for WordPress is vulnerable to time-based SQL Injection via the via 'latitude' and 'longitude' parameters in all versions up to, and including, 5.0.4 due to insufficient escaping on the user supplied…

7.5 CVSS
0.3% EPSS
sql-injection 2026-06-25
CVE-2026-13008 ⚪ Do wiadomości

Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-57700. Reason: This candidate is a reservation duplicate of CVE-2026-57700. Notes: All CVE users should reference CVE-2026-57700 instea…

0.0 CVSS
0.0% EPSS
2026-06-29
CVE-2026-13593 ⚪ Do wiadomości

CSS::Minifier::XS versions before 0.14 for Perl have a memory leak when the entire document is minified away. The minify function has a memory leak when processing a document containing only characters to be removed, su…

0.0 CVSS
0.0% EPSS
2026-06-29
CVE-2025-70099 🟡 Monitoruj

A NULL pointer dereference in the ext4_dir_en_get_name_len function in include/ext4_dir.h of lwext4 1.0.0 allows attackers to cause a denial of service by supplying a specially crafted EXT4 filesystem image with malforme…

7.5 CVSS
0.3% EPSS
dos 2026-06-01
CVE-2025-70100 ⚪ Do wiadomości

A divide-by-zero vulnerability in the ext4_block_set_lb_size function in src/ext4_blockdev.c of the lwext4 1.0.0 library allows attackers to cause a denial of service by providing a malformed ext4 filesystem image that r…

5.5 CVSS
0.1% EPSS
gkostkadosexploit 2026-06-03
CVE-2026-50745 ⚪ Do wiadomości

A missing sanitisation vulnerability exists with user input in the stats-video.php script. The way URLs to this script were constructed did not follow best practices, and the output of the Smarty custom helper function u…

6.1 CVSS
0.1% EPSS
revive-adserver 2026-06-26
CVE-2025-63391 ⚪ Do wiadomości

Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

0.0 CVSS
0.5% EPSS
2025-12-18
CVE-2025-29446 ⚪ Do wiadomości

Rejected reason: DO NOT USE THIS CVE RECORD. ConsultIDs: none. Reason: This record was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: none.

0.0 CVSS
0.2% EPSS
2025-04-21
CVE-2023-0645 ⚪ Do wiadomości

An out of bounds read exists in libjxl. An attacker using a specifically crafted file could cause an out of bounds read in the exif handler. We recommend upgrading to version 0.8.1 or past commit  https://github.com/libj…

5.3 CVSS
0.6% EPSS
libjxl_project 2023-04-11
CVE-2026-1288 ⚪ Do wiadomości

A maliciously crafted RFA file, when converted to FormIt via “Convert RFA to FormIt” in Autodesk Revit, can force a NULL Pointer Dereference vulnerability. Successful exploitation may cause the application to crash, lead…

5.5 CVSS
0.1% EPSS
autodesk 2026-06-17
CVE-2026-27878 ⚪ Do wiadomości

A TraceQL query in Grafana Tempo with a large exemplars hint value can cause the Tempo instance to allocate an excessive amount of memory, resulting in an out-of-memory crash. This could allow an authenticated user to tr…

6.5 CVSS
0.2% EPSS
grafanados 2026-06-19
CVE-2026-21728 🟡 Monitoruj

Tempo queries with large limits can cause large memory allocations which can impact the availability of the service, depending on its deployment strategy. Mitigation can be done by setting max_result_limit in the search…

7.5 CVSS
0.4% EPSS
grafana 2026-04-24
CVE-2026-57053 ⚪ Do wiadomości

GNU libidn before 1.44 is prone to out-of-bounds reads of uninitialized memory in the ToUnicode APIs because of mishandling in idna_to_unicode_internal. The affected code is not present in libidn2.

4.0 CVSS
0.1% EPSS
gnuexploit 2026-06-23
CVE-2026-11877 🟡 Monitoruj

An unauthorized user can modify configuration through API calls that affects the OpenText Access Manager. This issue affects Access Manager before 5.1.3.

7.5 CVSS
0.2% EPSS
microfocus 2026-06-24
CVE-2026-11878 ⚪ Do wiadomości

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in OpenText Access Manager allows Cross-Site Scripting (XSS). This issue affects Access Manager: from 5.1 through 5.1.2.

6.1 CVSS
0.2% EPSS
microfocusxss 2026-06-24
CVE-2026-8659 ⚪ Do wiadomości
os

OS Command Injection vulnerability in Rapid7 InsightConnect SQLmap Plugin on Linux allows authenticated attackers to execute arbitrary OS commands via the api_host or api_port parameters during connection configuration d…

6.0 CVSS
0.7% EPSS
linuxrce 2026-06-25
CVE-2026-58055 ⚪ Do wiadomości

nghttp2's nghttpx proxy through 1.69.0 forwards an HTTP/1.1 Upgrade request that also carries a Content-Length header and body onto reusable keep-alive backend connections, re-adding the Upgrade and Connection headers wh…

5.4 CVSS
0.2% EPSS
2026-06-28
CVE-2026-58057 ⚪ Do wiadomości

Flowise before 3.1.3 validates Custom MCP stdio environment variables against a denylist using a case-sensitive comparison, so on Windows, where environment names are case-insensitive, supplying 'node_options' bypasses t…

5.0 CVSS
0.2% EPSS
2026-06-28
CVE-2026-58052 ⚪ Do wiadomości

7-Zip for Windows through 26.02 fails to preserve the Mark-of-the-Web when extracting a crafted RAR5 archive, because its guard that suppresses an archive-supplied Zone.Identifier stream matches the exact name 'Zone.Iden…

3.3 CVSS
0.1% EPSS
2026-06-28
CVE-2026-38571 ⚪ Do wiadomości

Cleartext storage and exposure of WPA2 credentials, and missing authentication on the rr/wr memory read/write commands, in the unauthenticated UART debug console of the Tenda N300 F3 (V603) allow a physically proximate a…

4.6 CVSS
0.2% EPSS
2026-06-26
CVE-2026-3472 ⚪ Do wiadomości

Mattermost versions 10.11.x <= 10.11.18, 11.6.x <= 11.6.3, 11.5.x <= 11.5.6 fail to properly apply markdown image rendering restrictions to AI bot tool result posts, which allows an authenticated attacker to exfiltrate d…

3.5 CVSS
0.2% EPSS
mattermost 2026-06-26
CVE-2026-36478 🟡 Monitoruj

An issue in Technitium DNS Server v.14.3 and before allows a remote attacker to cause a denial of service via the DnsServerApp.exe, DnsServerApp.dll, TechnitiumLibrary.Net/Dns/DnsClient.cs components

7.5 CVSS
0.2% EPSS
dos 2026-06-26
CVE-2026-38639 🟡 Monitoruj

An issue in the parse_month function (/time/strptime.rs) of relibc commit ab6a2e allows attackers to cause a Denial of Service (DoS) via parsing a crafted input.

7.5 CVSS
0.2% EPSS
dos 2026-06-26
CVE-2026-38641 🟡 Monitoruj

An issue in the DSO::mmap_and_copy function of relibc commit 61f42d allows attackers to cause a Denial of Service (DoS) via loading a crafted shared library.

7.5 CVSS
0.2% EPSS
dos 2026-06-26
CVE-2026-36907 ⚪ Do wiadomości

A stack overflow in the AP4_StsdAtom::AP4_StsdAtom component of axiomatic-systems Bento4 before v1.8.9allows attackers to cause a Denial of Service (DoS) via a crafted MP4 file.

5.5 CVSS
0.2% EPSS
buffer-overflowdos 2026-06-26
CVE-2026-36908 ⚪ Do wiadomości

A stack overflow in the AP4_Array<AP4_TrunAtom::Entry>::EnsureCapacity component of axiomatic-systems Bento4 before v1.8.9allows attackers to cause a Denial of Service (DoS) via a crafted MP4 file.

5.5 CVSS
0.2% EPSS
buffer-overflowdos 2026-06-26
CVE-2026-39031 ⚪ Do wiadomości

Lansweeper lsrunase 2.0 and lsencrypt 2.0 use RC4 encryption with a hardcoded 142-byte static key array to encrypt credentials. An 8-character prefix is stored in cleartext alongside the ciphertext. This allows an attack…

5.5 CVSS
0.1% EPSS
2026-06-26
CVE-2026-8663 ⚪ Do wiadomości
os

OS Command Injection vulnerability in Rapid7 InsightConnect RPM Plugin on Linux allows authenticated attackers to execute arbitrary OS commands via the repo, key, or name parameters due to insufficient input sanitization…

6.0 CVSS
0.7% EPSS
linuxrce 2026-06-25
CVE-2026-8592 🟡 Monitoruj
os

OS Command Injection vulnerability in the process_string action of Rapid7 InsightConnect AWK Plugin on Linux allows remote attackers to execute arbitrary OS commands via the text or expression parameters due to unsafe sh…

7.7 CVSS
0.5% EPSS
linuxrce 2026-06-25
CVE-2026-4339 ⚪ Do wiadomości

Mattermost versions 10.11.x <= 10.11.18, 11.6.x <= 11.6.3, 11.5.x <= 11.5.6 fail to validate attachment URLs against internal or private IP ranges in the Mattermost Agents plugin MCP server which allows an attacker with …

6.5 CVSS
0.1% EPSS
mattermostssrf 2026-06-26
CVE-2026-8660 🟡 Monitoruj
os

OS Command Injection vulnerability in the ping action of Rapid7 InsightConnect Ping Plugin on Linux allows remote attackers to execute arbitrary OS commands via the host parameter due to insufficient input validation whe…

7.7 CVSS
0.5% EPSS
linuxrce 2026-06-25
CVE-2026-8664 ⚪ Do wiadomości

OS Command Injection vulnerability in Rapid7 InsightConnect Finger Plugin on Linux allows authenticated attackers to execute arbitrary OS commands via the user or host parameters due to insufficient input validation in s…

6.0 CVSS
0.7% EPSS
rapid7rce 2026-06-25
CVE-2026-8665 🟡 Monitoruj
os

OS Command Injection vulnerability in the TR action of Rapid7 InsightConnect Translate Plugin on Linux allows remote attackers to execute arbitrary OS commands via the text or expression parameters due to insufficient in…

7.7 CVSS
0.5% EPSS
linuxrce 2026-06-25
CVE-2026-55975 🟡 Monitoruj

A vulnerability exists in H.View IP cameras that could allow an authenticated user to supply unsanitized XML fields to the device's certificate generation interface, which are incorporated into a backend certificate crea…

7.2 CVSS
0.7% EPSS
2026-06-26
CVE-2026-56414 🟡 Monitoruj

A vulnerability exists in H.View IP cameras certificate-related upload interfaces allow authenticated users to store arbitrary file content to fixed, persistent filesystem locations without validating file type, structur…

7.2 CVSS
0.4% EPSS
2026-06-26
CVE-2026-31928 🟡 Monitoruj

The DMP-5000 devices are shipped with a default administrative web account with weak authentication controls, which are not required to be changed during initial configuration or operation. Using these accounts provides …

8.1 CVSS
0.4% EPSS
2026-06-26
CVE-2026-33560 🟡 Monitoruj

The DMP-5000 file service exposes authenticated arbitrary file upload functionality. There are exposed endpoints which allows authenticated users to upload files of any type without validation. No file extension filterin…

7.1 CVSS
0.3% EPSS
2026-06-26
CVE-2026-8666 🟡 Monitoruj
os

OS Command Injection vulnerability in the traceroute action of Rapid7 InsightConnect Traceroute Plugin on Linux allows remote attackers to execute arbitrary OS commands via the host, port, max_ttl, count, or time_out req…

7.7 CVSS
0.5% EPSS
linuxrce 2026-06-25
CVE-2026-8658 ⚪ Do wiadomości
os

OS Command Injection vulnerability in Rapid7 InsightConnect Tcpdump Plugin on Linux allows authenticated attackers to execute arbitrary OS commands via the options or filter parameters due to insufficient input sanitizat…

6.0 CVSS
0.7% EPSS
linuxrce 2026-06-25
CVE-2026-58054 🟡 Monitoruj

MyBB 1.8.40 does not restrict which usergroup a limited Admin Control Panel user may assign when creating or editing users; the user module offers the Administrators group (gid 4) and its datahandler's verify_usergroup()…

7.2 CVSS
0.3% EPSS
2026-06-28
CVE-2026-57999 🟡 Monitoruj

luci-app-tailscale-community contains a command injection vulnerability in the tailscale.do_login RPC method that allows authenticated users to execute arbitrary commands as root. The vulnerability exists because user-co…

8.8 CVSS
0.0% EPSS
rce 2026-06-29
CVE-2026-56124 🟡 Monitoruj

phpUploader before 2.0.2 contains an unauthenticated information disclosure vulnerability that allows remote attackers to access the full contents of the uploaded-files database table by visiting any page of the applicat…

7.5 CVSS
0.0% EPSS
2026-06-29
CVE-2026-54369 🟡 Monitoruj

acl before version 2.4.0 contains a symlink traversal vulnerability in the libacl pathname-based functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() that allows local attackers to esc…

7.1 CVSS
0.0% EPSS
CVE-2026-54371 🟡 Monitoruj

attr before version 2.6.0 contains a symlink traversal vulnerability in the getfattr and setfattr utilities that allows local attackers to escalate privileges by replacing a pathname component with a symbolic link during…

7.1 CVSS
0.0% EPSS
CVE-2026-54370 ⚪ Do wiadomości

acl before version 2.4.0 contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability that allows local attackers to escalate privileges by replacing a pathname component with a symbolic link between an …

6.3 CVSS
0.0% EPSS
CVE-2026-57946 ⚪ Do wiadomości

Invidious before version 2.20260626.0 contains a broken access control vulnerability that allows unauthenticated attackers to retrieve private playlist contents by accessing the RSS feed playlist endpoint without authent…

3.7 CVSS
0.0% EPSS
2026-06-29
CVE-2026-8662 ⚪ Do wiadomości
os

Path Traversal vulnerability in the create_archive function of Rapid7 InsightConnect Compression Plugin on Linux allows authenticated attackers to write to unintended file paths via crafted filename input. The impact is …

3.3 CVSS
0.2% EPSS
linuxpath-traversal 2026-06-25
CVE-2026-8622 ⚪ Do wiadomości

The Image Sizes on Demand plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via PHP_SELF Server Variable in all versions up to, and including, 1.3 due to insufficient input sanitization and output esca…

6.1 CVSS
0.2% EPSS
xss 2026-06-24
CVE-2026-9705 ⚪ Do wiadomości

A flaw was found in Keycloak's client registration service. A remote attacker, possessing a previously issued Registration Access Token (RAT), could exploit this vulnerability to re-enable a client that an administrator …

6.5 CVSS
0.3% EPSS
2026-06-25
CVE-2026-57955 🟡 Monitoruj

SigNoz through 0.130.1 contains a SQL injection vulnerability that allows authenticated attackers to execute arbitrary ClickHouse queries by injecting URL-encoded quotes into the rule ID path parameter of the alert-histo…

8.5 CVSS
0.0% EPSS
sql-injectionssrf 2026-06-29
CVE-2026-57949 ⚪ Do wiadomości

ruoyi-vue-pro through 2026.05, fixed in commit c779a47, contains a missing authorization vulnerability in the CRM module's GET /admin-api/crm/follow-up-record/get endpoint that allows authenticated users to read any foll…

6.5 CVSS
0.0% EPSS
2026-06-29
CVE-2026-57958 ⚪ Do wiadomości

Mixpost through 2.6.0 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to execute arbitrary JavaScript in authenticated users' browsers by crafting malicious OAuth callback UR…

6.1 CVSS
0.0% EPSS
xss 2026-06-29
CVE-2026-56781 ⚪ Do wiadomości

Teable before 2026-06-15T04-43-24Z.1912 contains an improper access control vulnerability that allows anonymous attackers to access hidden field data by supplying arbitrary field IDs in the projection parameter of the sh…

5.3 CVSS
0.0% EPSS
2026-06-29
CVE-2026-57942 ⚪ Do wiadomości

LibreTranslate through 1.9.7, fixed in commit 397fd22, contains an IP spoofing vulnerability in the get_remote_address() function that allows unauthenticated attackers to spoof client IP addresses by injecting arbitrary …

5.3 CVSS
0.0% EPSS
2026-06-29
CVE-2026-57952 ⚪ Do wiadomości

Mythic before 3.4.0.60 contains an authorization bypass vulnerability in four REST endpoints (c2profile_config_check_webhook, c2profile_redirect_rules_webhook, c2profile_get_ioc_webhook, c2profile_sample_message_webhook)…

5.3 CVSS
0.0% EPSS
2026-06-29
CVE-2026-12993 ⚪ Do wiadomości

A flaw was found in Apicurio Registry. The DocumentBuilderAccessor correctly blocks external DTD and schema access but does not disable DOCTYPE declarations or enable FEATURE_SECURE_PROCESSING. An attacker with artifact-…

6.5 CVSS
0.3% EPSS
2026-06-26
CVE-2026-12912 🟡 Monitoruj

A flaw was found in libtiff. A remote attacker could exploit this vulnerability by providing a specially crafted PixarLog-compressed TIFF image. This issue occurs when decoding Pixarlog codec images with the PIXARLOGDATA…

7.3 CVSS
0.0% EPSS
CVE-2026-12404 ⚪ Do wiadomości

The NEX-Forms – Ultimate Forms Plugin for WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 9.2.2. This is due to the plugin not properly verifying that a user is …

5.3 CVSS
0.3% EPSS
2026-06-27
CVE-2026-11720 ⚪ Do wiadomości

A path traversal vulnerability exists in the HTTP tool URL builder of googleapis/mcp-toolbox. When constructing downstream API requests, the URL builder substitutes user-controlled pathParams into the configured tool pa…

0.0 CVSS
0.0% EPSS
path-traversal 2026-06-29
CVE-2026-46604 🟡 Monitoruj

The TIFF decoder can panic when decoding an invalid image with an out-of-bounds strip offset.

7.5 CVSS
0.2% EPSS
2026-06-26
CVE-2026-58053 🟠 Łataj w tym tygodniu

Gitea act_runner with the Docker backend (through act 0.262.0) passes a workflow's container.options string to the Docker job container's HostConfig and, when configured with privileged: false, forces only the Privileged…

9.9 CVSS
0.3% EPSS
2026-06-28
CVE-2026-10820 🟡 Monitoruj

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress plugin before 4.16.17 does not verify that the user performing a subscription action owns the targeted…

8.1 CVSS
0.1% EPSS
2026-06-27
CVE-2026-58056 🟡 Monitoruj

RustDesk gates incoming control messages on per-capability flags rather than on the session's authorized connection type, and a file-transfer session does not clear those flags. A peer holding only a valid FileTransfer a…

7.6 CVSS
0.2% EPSS
2026-06-28
CVE-2026-9677 ⚪ Do wiadomości

The Shariff for WordPress Shariff for WordPress plugin through 1.0.11 does not sanitize or escape the shariff_infourl setting before outputting it in the frontend HTML via the generateshariff() function, which could allo…

4.8 CVSS
0.1% EPSS
xss 2026-06-27
CVE-2026-40521 🟡 Monitoruj

FrontAccounting before 2.4.20 contains a path traversal vulnerability in the attachment upload handler that allows authenticated attackers to execute arbitrary code by uploading files with traversal sequences in the uniq…

8.8 CVSS
0.0% EPSS
path-traversalrce 2026-06-29
CVE-2026-40523 🟡 Monitoruj

FrontAccounting before 2.4.20 contains a SQL injection vulnerability in the Audit Trail report handler that allows authenticated attackers with SA_GLANALYTIC permission to execute arbitrary SQL queries by injecting malic…

8.1 CVSS
0.0% EPSS
dossql-injection 2026-06-29
CVE-2026-40524 🟡 Monitoruj

FrontAccounting before 2.4.20 contains a SQL injection vulnerability in the get_gl_transactions() function where the filter_type parameter is concatenated directly into a SQL IN() clause without parameterization. Attacke…

8.1 CVSS
0.0% EPSS
sql-injection 2026-06-29
CVE-2026-10083 🟡 Monitoruj

The APCu Manager WordPress plugin before 4.5.0 does not escape APCu object-cache keys before rendering them in an admin-area page, leading to a Stored Cross-Site Scripting vulnerability. When a persistent object cache is…

7.5 CVSS
0.2% EPSS
xss 2026-06-29
CVE-2026-40522 🟡 Monitoruj

FrontAccounting before 2.4.20 contains a SQL injection vulnerability in the Bank Statement report handler that allows authenticated attackers to extract arbitrary database data by injecting UNION SELECT payloads into the…

7.1 CVSS
0.0% EPSS
sql-injection 2026-06-29
CVE-2026-57948 ⚪ Do wiadomości

Pinpoint through version 3.1.0 contains an insecure session management vulnerability that allows attackers to access the pinpointJwt session cookie due to missing HttpOnly and Secure attributes, enabling JavaScript acces…

6.8 CVSS
0.0% EPSS
xss 2026-06-29
CVE-2026-57960 ⚪ Do wiadomości

Hi.Events through 1.9.0 public check-in list endpoints use short_id as sole access control, allowing unauthenticated access to retrieve full attendee lists including emails and personal information. Attackers with knowle…

6.5 CVSS
0.0% EPSS
2026-06-29
CVE-2026-57957 ⚪ Do wiadomości

Papermark through 0.22.0 contains a cross-origin resource sharing (CORS) misconfiguration vulnerability that allows unauthenticated remote attackers to perform credentialed cross-origin requests by exploiting the TUS-bas…

4.7 CVSS
0.0% EPSS
2026-06-29
CVE-2026-9676 ⚪ Do wiadomości

The F4 Post Tree WordPress plugin before 2.0.5 does not perform capability checks or CSRF/nonce verification on one of its AJAX actions, allowing authenticated users with Subscriber-level access and above to modify the p…

4.3 CVSS
0.1% EPSS
2026-06-29
CVE-2026-57954 ⚪ Do wiadomości

Elide through 7.1.17 fails to enforce @ReadPermission on client-supplied sort expressions in SortingImpl.getValidSortingRules, allowing attackers to sort collections by forbidden fields. Attackers can infer hidden field …

4.3 CVSS
0.0% EPSS
2026-06-29
CVE-2026-55844 🟡 Monitoruj

Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2025.5.0, The iOS companion app ignores the SSID allowlist for internal networks. The app uses SSID to detect whe…

7.5 CVSS
0.0% EPSS
2026-06-29
CVE-2026-56780 🟡 Monitoruj

Modoboa before 2.9.0 contains an insecure direct object reference vulnerability in the PUT /api/v1/accounts/{pk}/password/ endpoint that allows domain administrators to change any user's password. Attackers with domain a…

7.5 CVSS
0.0% EPSS
2026-06-29
CVE-2026-56783 ⚪ Do wiadomości

Parseable before 2.9.2 contains an information disclosure vulnerability in the notification-target API endpoints that returns webhook tokens and basic-auth credentials in cleartext due to commented-out secret-masking fun…

6.5 CVSS
0.0% EPSS
2026-06-29
CVE-2026-57945 ⚪ Do wiadomości

PhotoPrism before 260601-a7d098548 contains a broken access control vulnerability that allows authenticated non-admin users to modify other users' profile information by sending requests to arbitrary user endpoints. Atta…

4.3 CVSS
0.0% EPSS
2026-06-29
CVE-2026-9267 ⚪ Do wiadomości

Eclipse tinydtls before commit b3efd41ad111a4920f599f51ffa4f5e9f1e72221 contains an out-of-bounds read vulnerability in the check_server_certificate() function that allows unauthenticated attackers to trigger reads beyon…

0.0 CVSS
0.2% EPSS
dos 2026-06-29
CVE-2026-12616 ⚪ Do wiadomości

The /v1/upload/sbom endpoint extracts the iss claim from the attacker-supplied JWT with signature verification disabled, then interpolates that string into three log statements before any validation gate. Because the con…

0.0 CVSS
0.0% EPSS
2026-06-29
CVE-2026-13165 ⚪ Do wiadomości 🇵🇱 CERT.pl

SzafirHost verifies the downloaded native library archive with one JarFile parser (reading the Central Directory) but extracts native libraries with JarInputStream parser (reading sequentially from local file headers). A…

0.0 CVSS
0.0% EPSS
rce 2026-06-29
CVE-2026-28701 🟠 Łataj w tym tygodniu

Various versions of Daktronics Controller Firmware could allow authenticated and unauthenticated remote users to escape the intended directory and enumerate arbitrary file system paths.

9.8 CVSS
0.8% EPSS
2026-06-26
CVE-2026-41991 ⚪ Do wiadomości 🇵🇱 CERT.pl

GNU gzip contains a vulnerability in the gzexe utility related to insecure temporary file handling. When the mktemp utility is not available in the user’s PATH, gzexe falls back to constructing a temporary file path base…

0.0 CVSS
0.0% EPSS
2026-06-29
CVE-2026-41992 ⚪ Do wiadomości 🇵🇱 CERT.pl

GNU gzip contains a global buffer overflow vulnerability in the LZH decompression logic caused by improper reuse of shared global state between different decompression formats within a single execution. GNU gzip maintain…

0.0 CVSS
0.0% EPSS
buffer-overflow 2026-06-29
CVE-2026-11979 ⚪ Do wiadomości 🇵🇱 CERT.pl

libxml2 is vulnerable to multiple stack-based buffer overflows in the xmlcatalog utility when running in --shell mode. The usershell() function processes user input using fixed-size stack buffers without proper bounds ch…

0.0 CVSS
0.0% EPSS
buffer-overflowrce 2026-06-29
CVE-2026-54316 🟠 Łataj w tym tygodniu

Claude Code is an agentic coding tool. From 0.2.54 until 2.1.163, because the hostname huggingface.co was pre-approved as a bare hostname for the WebFetch tool, any path on that domain—including attacker-controlled mode…

9.1 CVSS
0.4% EPSS
anthropic 2026-06-23
CVE-2026-10643 🟡 Monitoruj

Zephyr's IP socket recvmsg() implementation (subsys/net/lib/sockets/sockets_inet.c, insert_pktinfo()) validated the user-supplied ancillary (msg_control) buffer using only the payload length (msg-msg_controllen < pktinfo…

8.7 CVSS
0.1% EPSS
2026-06-28
CVE-2026-58049 🟡 Monitoruj

FFmpeg's RASC video decoder (decode_dlta in libavcodec/rasc.c) performs 32-bit reads and writes at the row cursor before the NEXT_LINE row-boundary check and validates the DLTA region in pixel rather than byte units, so …

8.6 CVSS
0.3% EPSS
2026-06-28
CVE-2026-58050 🟡 Monitoruj

libssh2 through 1.11.1 reads an attacker-controlled 32-bit attribute count from a publickey-subsystem response and uses it in the allocation num_attrs * sizeof(libssh2_publickey_attribute) without bounds checking, so on …

7.0 CVSS
0.3% EPSS
buffer-overflow 2026-06-28
CVE-2026-58051 ⚪ Do wiadomości

libssh2 through 1.11.1 grows its publickey list with SSH2_REALLOC but does not zero-initialize new entries before parsing populates them, so a parse failure reaching the cleanup path leaves libssh2_publickey_list_free op…

6.5 CVSS
0.3% EPSS
2026-06-28
CVE-2026-58058 ⚪ Do wiadomości

Nmap through 7.99 does not keep the IPv6 extension-header walk within the captured packet in ipv6_get_data_primitive (libnetutil/netutil.cc), so the pointer advances past the buffer and the remaining-length computation u…

6.5 CVSS
0.3% EPSS
2026-06-28
CVE-2026-10593 ⚪ Do wiadomości

The Zephyr Bluetooth LE Audio Basic Audio Profile (BAP) unicast client mishandles peer-supplied ASE state notifications. In unicast_client_ep_qos_state() (subsys/bluetooth/audio/bap_unicast_client.c), the handler writes …

6.5 CVSS
0.2% EPSS
dos 2026-06-28
CVE-2026-50765 ⚪ Do wiadomości

A stored cross-site scripting (XSS) vulnerability in the patron restriction type administration page of Koha Library Management System 0 through 25.11 versions allow an authenticated remote attacker with administrator pr…

6.1 CVSS
0.2% EPSS
xss 2026-06-26
CVE-2026-50766 ⚪ Do wiadomości

A stored cross-site scripting (XSS) vulnerability in the OPAC item detail page of Koha Library Management System 0 through 25.11 versions allow an authenticated remote attacker with edit_items permission to inject arbitr…

5.4 CVSS
0.2% EPSS
xss 2026-06-26
CVE-2026-50767 ⚪ Do wiadomości

A stored cross-site scripting (XSS) vulnerability in the item type administration page of Koha Library Management System 0 through 25.11 versions allow an authenticated remote attacker with administrator privileges to in…

5.4 CVSS
0.2% EPSS
xss 2026-06-26
CVE-2026-13676 🟡 Monitoruj

fast-uri versions 2.3.1 through 3.1.2 and 4.0.0 fail to canonicalize Unicode (IDN) hostnames for HTTP-family URLs. The IDN conversion path calls a helper that does not exist on the global URL constructor, silently leavin…

7.5 CVSS
0.0% EPSS
2026-06-29
CVE-2026-10646 🟡 Monitoruj

Zephyr's BSD-sockets getaddrinfo() implementation (subsys/net/lib/sockets/getaddrinfo.c) passes a pointer to a stack-allocated state object (struct getaddrinfo_state ai_state) as the user_data of an asynchronous DNS reso…

7.4 CVSS
0.3% EPSS
dos 2026-06-28
CVE-2026-57951 ⚪ Do wiadomości

Mythic before 3.4.0.60 contains a broken hasura permission filter on the payload_build_step table with an always-satisfied _or condition that bypasses operation-scoped access controls. Authenticated operators and spectat…

6.5 CVSS
0.0% EPSS
2026-06-29
CVE-2026-10644 ⚪ Do wiadomości

The Microchip SERCOM-G1 UART driver (drivers/serial/uart_mchp_sercom_g1.c), used by the PIC32CM-JH SoC family, contains an out-of-bounds write in its asynchronous (DMA) receive path. When uart_rx_enable() is invoked with…

4.2 CVSS
0.1% EPSS
dos 2026-06-28
CVE-2026-52846 ⚪ Do wiadomości

Caddy is an extensible server platform that uses TLS by default. Prior to 2.11.4, Caddy’s stripHTML template function cannot reliably remove all HTML tags from input strings. Certain malformed HTML, such as <<>img src=x …

4.2 CVSS
0.1% EPSS
CVE-2026-52844 🟡 Monitoruj

Caddy is an extensible server platform that uses TLS by default. Prior to 2.11.4, on Windows, Caddy path matchers treat /private\secret.txt as outside /private/*, but file_server later resolves the same request path as p…

7.5 CVSS
0.4% EPSS
caddyserverexploit 2026-06-23
CVE-2026-22078 🟡 Monitoruj

Because O+ Connect's IPC service does not authenticate clients, external applications can escalate privileges and perform sensitive actions through the IPC channel.

7.3 CVSS
0.1% EPSS
2026-06-29
CVE-2025-8732 ⚪ Do wiadomości

A vulnerability was found in libxml2 up to 2.14.5. It has been declared as problematic. This vulnerability affects the function xmlParseSGMLCatalog of the component xmlcatalog. The manipulation leads to uncontrolled recu…

3.3 CVSS
0.1% EPSS
2025-08-08
CVE-2026-0989 ⚪ Do wiadomości

A flaw was identified in the RelaxNG parser of libxml2 related to how external schema inclusions are handled. The parser does not enforce a limit on inclusion depth when resolving nested <include> directives. Specially c…

3.7 CVSS
0.4% EPSS
2026-01-15
CVE-2026-0990 ⚪ Do wiadomości

A flaw was found in libxml2, an XML parsing library. This uncontrolled recursion vulnerability occurs in the xmlCatalogXMLResolveURI function when an XML catalog contains a delegate URI entry that references itself. A re…

5.9 CVSS
0.7% EPSS
dos 2026-01-15
CVE-2026-25707 🟡 Monitoruj

A relative path traversal bug problem when processing repository metadata in libzypp before 17.38.10 could be used by remote attackers supplying repositories to overwrite files on the system, leading to denial of service…

8.8 CVSS
0.0% EPSS
CVE-2026-13749 🟡 Monitoruj

Improper neutralization in the Snowpark annotation processor callback template in Snowflake CLI versions prior to 3.19 allowed arbitrary code execution during application bundling or deployment. An attacker could exploit…

8.8 CVSS
0.0% EPSS
rce 2026-06-29
CVE-2026-13744 🟡 Monitoruj

Improper neutralization of attacker-controlled content in Snowflake CLI versions prior to 3.19 allowed unintended SQL execution. By supplying crafted repository content, project configuration, manifest data, or specifica…

8.3 CVSS
0.0% EPSS
2026-06-29
CVE-2026-13748 ⚪ Do wiadomości

Improper restriction of file path resolution in Snowflake CLI versions prior to 3.19 allowed arbitrary local file content to be read and transmitted to Snowflake services. An attacker could exploit this by supplying craf…

6.3 CVSS
0.0% EPSS
2026-06-29
CVE-2026-13752 ⚪ Do wiadomości

Improper neutralization of parameters in Snowflake CLI versions prior to 3.19 allowed unintended SQL execution. An attacker could exploit this by supplying crafted values to vulnerable command paths, causing Snowflake CL…

6.0 CVSS
0.0% EPSS
2026-06-29
CVE-2026-13750 ⚪ Do wiadomości

Insertion of sensitive information into log files in Snowflake CLI versions prior to 3.19 allowed plaintext credentials to be written to persistent local debug logs. An attacker could exploit this by obtaining read acces…

5.5 CVSS
0.0% EPSS
2026-06-29
CVE-2026-13751 ⚪ Do wiadomości

Improper handling of untrusted remote references in Snowflake CLI versions prior to 3.19 allowed server-side request forgery. The SQL statement reader's !source/!load directives could reference remote URLs that were retr…

4.1 CVSS
0.0% EPSS
ssrf 2026-06-29
CVE-2026-13746 ⚪ Do wiadomości

Improper neutralization of local CLI parameters in Snowflake CLI versions prior to 3.19 allowed unintended SQL execution. A user could trigger this issue by supplying crafted values to vulnerable Cortex SQL or object lis…

3.6 CVSS
0.0% EPSS
2026-06-29
CVE-2026-41052 ⚪ Do wiadomości

Improper privilege handling could be used by users with Project Owner role to escalate privileges, in Rancher versions 2.14 before 2.14.2, 2.13 before 2.13.6, and 2.12 before 2.12.10.

0.0 CVSS
0.0% EPSS
2026-06-29
CVE-2026-9105 ⚪ Do wiadomości

An authenticated stack-based buffer overflow vulnerability exists in the web management interface of TP-Link TL-WR841N v14. A remote authenticated attacker can send crafted HTTP requests to cause the embedded web server…

0.0 CVSS
0.0% EPSS
buffer-overflow 2026-06-29
CVE-2026-13437 ⚪ Do wiadomości

Insertion of sensitive information into sent data in the AI Agent job API in Devolutions PowerShell Universal 2026.2.0 allows an authenticated user with AI Agent read access to obtain reusable, potentially higher-privile…

6.5 CVSS
0.0% EPSS
2026-06-29
CVE-2026-0992 ⚪ Do wiadomości

A flaw was found in the libxml2 library. This uncontrolled resource consumption vulnerability occurs when processing XML catalogs that contain repeated <nextCatalog> elements pointing to the same downstream catalog. A re…

2.9 CVSS
0.3% EPSS
2026-01-15
CVE-2025-62231 🟡 Monitoruj

A flaw was identified in the X.Org X server’s X Keyboard (Xkb) extension where improper bounds checking in the XkbSetCompatMap() function can cause an unsigned short overflow. If an attacker sends specially crafted input…

7.3 CVSS
0.3% EPSS
2025-10-30