CVE Feed

    Dashboard / CVE

    6.9
    Medium

    CVE-2026-27868

    Last Modified: 1 Jul 2026

    An attacker with access via network to the Regesta Smart HD-PLC of the provider Teldat (in this case, NO registration action is required) who has the vulnerable software could obtain privilege information by using the command Version via the path: /upgrade/query.php?cmd=p+3&3Bversion resulting in a information disclosure. This issue affects Regesta Smart HD-PLC - TLDPH16D2: 11.02.05.10.02.

    Published: 17 Jun 2026
    10
    Critical

    CVE-2026-0063

    Last Modified: 18 Jun 2026

    In setAllowedCarriers of PhoneInterfaceManager.java, there is a possible way to disable carrier restrictions due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 17 Jun 2026
    10
    Critical

    CVE-2026-28587

    Last Modified: 18 Jun 2026

    In MmsSmsProvider of MmsSmsProvider.java, there is a possible way to retrieve sensitive information due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 17 Jun 2026
    10
    Critical

    CVE-2026-28576

    Last Modified: 18 Jun 2026

    In Contacts Provider, there is a possible way to access the contacts database due to SQL injection. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 17 Jun 2026
    10
    Critical

    CVE-2026-28615

    Last Modified: 18 Jun 2026

    In Telecomm, there is a possible way to initiate an unauthorized phone call due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 17 Jun 2026
    10
    Critical

    CVE-2026-0083

    Last Modified: 18 Jun 2026

    In Nfc::eventCallback() of Nfc.h, there is a possible use after free due to a race condition. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 17 Jun 2026
    10
    Critical

    CVE-2026-0082

    Last Modified: 18 Jun 2026

    In tryStartActivity of NfcDispatcher.java, there is a possible automatic special app access permission assignment due to an insecure default value. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 17 Jun 2026
    7.5
    High

    CVE-2026-12199

    Last Modified: 17 Jun 2026

    A vulnerability in `nltk.app.wordnet_app` up to version 3.9.3 allows unauthenticated remote shutdown of the local WordNet Browser HTTP server when started in its default mode. The server listens on all interfaces and processes a specific unauthenticated GET request (`/SHUTDOWN%20THE%20SERVER`) to terminate the process immediately via `os._exit(0)`. This results in a denial of service, impacting service availability. The issue arises due to insufficient authentication and protection mechanisms for critical server functions.

    Published: 17 Jun 2026
    10
    Critical

    CVE-2026-0081

    Last Modified: 18 Jun 2026

    In NFC, there is a possible way to spoof an NFC event due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 17 Jun 2026
    10
    Critical

    CVE-2026-0071

    Last Modified: 18 Jun 2026

    In SettingsLib, there is a possible missing permission check due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 17 Jun 2026
    10
    Critical

    CVE-2026-28575

    Last Modified: 17 Jun 2026

    In PackageInstaller.Session#transfer of frameworks/base/services/core/java/com/android/server/pm/PackageInstallerSession.java, there is a possible memory exhaustion attack due to a logic error in the code. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 17 Jun 2026
    10
    Critical

    CVE-2026-0064

    Last Modified: 17 Jun 2026

    In multiple places, there is a possible persistent denial of service due to resource exhaustion. This could lead to local denial of service with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 17 Jun 2026
    10
    Critical

    CVE-2026-0092

    Last Modified: 18 Jun 2026

    In Package Manager, there is a possible device lock controller bypass due to a missing permission check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 17 Jun 2026
    6.4
    Medium

    CVE-2026-8494

    Last Modified: 26 Jun 2026

    The Permalink Manager Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via post titles in the admin URI Editor interface in all versions up to, and including, 2.5.3.3 due to insufficient output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject arbitrary web scripts in the admin Permalink Manager page that will execute whenever an administrator accesses the Permalink Manager page.

    Published: 17 Jun 2026
    6.4
    Medium

    CVE-2026-8607

    Last Modified: 26 Jun 2026

    The Points Management System For Gamification, Ranks, Badges, and Loyalty Rewards Program – myCred plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'wrap' Shortcode Attribute in all versions up to, and including, 3.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 17 Jun 2026
    10
    Critical

    CVE-2026-0068

    Last Modified: 18 Jun 2026

    In createSessionInternal of PackageInstallerService.java, there is a possible method to remove a DPC app from a managed device without DO consent due to desync from persistence. This could lead to local escalation of privilege if a user can install a malicious app with no additional execution privileges needed. User interaction is needed for exploitation.

    Published: 17 Jun 2026
    9.8
    Critical

    CVE-2026-10094

    Last Modified: 26 Jun 2026

    A Path Traversal vulnerability affecting SOLIDWORKS Visualize from SOLIDWORKS Desktop Release 2024 through SOLIDWORKS Desktop Release 2026 could allow an attacker to write arbitrary files on the server.

    Published: 17 Jun 2026
    7.1
    High

    CVE-2026-9570

    Last Modified: 17 Jun 2026

    The Taskbuilder WordPress plugin before 5.0.8 does not properly sanitise a URL parameter before echoing it into inline JavaScript on a frontend page containing one of its shortcodes, leading to a Reflected Cross-Site Scripting vulnerability that can be triggered against any logged-in user.

    Published: 17 Jun 2026
    5.3
    Medium

    CVE-2026-8383

    Last Modified: 26 Jun 2026

    The LearnPress WordPress plugin before 4.3.7 does not gate the `edit` context on one of its REST endpoint behind the `edit_users` capability, allowing unauthenticated visitors to retrieve each returned user's roles, full capabilities map, extra capabilities, locale, and registration date via a crafted request

    Published: 17 Jun 2026
    7.1
    High

    CVE-2026-8089

    Last Modified: 26 Jun 2026

    The weMail: Email Marketing, Email Automation, Newsletters, Subscribers & Email Optins for WooCommerce WordPress plugin before 2.1.3 does not properly escape a user-supplied parameter before reflecting it into an HTML attribute on a non-nonce-protected AJAX response, allowing unauthenticated attackers to deliver Reflected Cross-Site Scripting against any authenticated user (including administrators) via a crafted URL.

    Published: 17 Jun 2026
    5.9
    Medium

    CVE-2026-7850

    Last Modified: 26 Jun 2026

    The WP Magnific Popup WordPress plugin through 1.0 does not properly escape user-controlled link URLs before injecting them into the DOM when displaying image load error messages, allowing authenticated attackers with Author-level access or above to perform Stored Cross-Site Scripting attacks against any visiting user.

    Published: 17 Jun 2026
    3.3
    Low

    CVE-2026-0057

    Last Modified: 18 Jun 2026

    In Contacts Provider, there is a possible way to access an incoming call's phone number and associated metadata due to a missing permission check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 17 Jun 2026
    7.8
    High

    CVE-2026-0019

    Last Modified: 18 Jun 2026

    In SettingsLib, there is a possible way to disable system components due to a logic error in the code. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 17 Jun 2026
    7.8
    High

    CVE-2025-48643

    Last Modified: 18 Jun 2026

    In multiple locations there is a possible provisioning bypass due to improper input validation. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 17 Jun 2026
    8
    High

    CVE-2025-48640

    Last Modified: 18 Jun 2026

    In multiple locations, there is a possible 3rd party passkey entry pairing approval due to a missing permission check. This could lead to remote (proximal/adjacent) escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 17 Jun 2026
    7.8
    High

    CVE-2025-48617

    Last Modified: 18 Jun 2026

    In overrideConfig of CarrierConfigLoader.java, there is a possible way to bypass UID check due to a permissions bypass. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation.

    Published: 17 Jun 2026
    4.3
    Medium

    CVE-2025-48571

    Last Modified: 17 Jun 2026

    In multiple functions of btm_sec.cc, there is a possible way for an attacker to intercept SMS messages due to a logic error in the code. This could lead to remote information disclosure with no additional execution privileges needed. User interaction is needed for exploitation.

    Published: 17 Jun 2026
    8.6
    High

    CVE-2026-53876

    Last Modified: 20 Jun 2026

    RadiX AX6600 WiFi 6 Tri-Band Gaming Router contains an OS command injection vulnerability, which may lead to arbitrary command execution with the root privilege by a user who logs in to the web console as an administrator.

    Published: 17 Jun 2026
    7.5
    High

    CVE-2026-12360

    Last Modified: 17 Jun 2026

    The JetEngine plugin for WordPress is vulnerable to SQL injection in all versions up to and including 3.8.10.1. The listing_load_more AJAX handler accepts a filtered_query parameter that is intentionally excluded from the HMAC query signature check to support front-end filter integration. However, meta_query row values within filtered_query are not sanitized before being merged into SQL construction. This makes it possible for unauthenticated attackers to perform time-based or boolean blind SQL injection by appending a malicious meta_query value to a Load More AJAX request captured from any public Listing Grid page.

    Published: 17 Jun 2026
    6.8
    Medium

    CVE-2025-15642

    Last Modified: 26 Jun 2026

    Netskope is notified about a potential gap in its Netskoped Client for Windows systems where a malicious insider with admin privileges can lead to bypassing the NSClient Tamper Protections due to weak Discretionary Access Control List (DACLs) on the service object and related registry keys,. * Product Name: Netskope Client * Affected Platform: Windows * Affected Version: All version below R138

    Published: 17 Jun 2026
    9.1
    Critical

    CVE-2026-50203

    Last Modified: 26 Jun 2026

    A path traversal in the SFTP provider (`SFTPHook.retrieve_directory` / `SFTPOperator(operation=get)`) let a malicious or compromised remote SFTP server write files outside the configured local destination directory via crafted directory-entry names. No Airflow account is required — the attack surface is any deployment downloading directories from an untrusted SFTP server. Upgrade `apache-airflow-providers-sftp` to 5.8.1 or later.

    Published: 17 Jun 2026
    4.3
    Medium

    CVE-2026-12469

    Last Modified: 18 Jun 2026

    Uninitialized Use in GPU in Google Chrome on Android prior to 149.0.7827.155 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)

    Published: 17 Jun 2026
    8.3
    High

    CVE-2026-12468

    Last Modified: 19 Jun 2026

    Race in Updater in Google Chrome on Mac prior to 149.0.7827.155 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

    Published: 17 Jun 2026
    8.3
    High

    CVE-2026-12467

    Last Modified: 18 Jun 2026

    Use after free in Extensions in Google Chrome prior to 149.0.7827.155 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

    Published: 17 Jun 2026
    8.8
    High

    CVE-2026-12466

    Last Modified: 18 Jun 2026

    Heap buffer overflow in WebRTC in Google Chrome on Windows prior to 149.0.7827.155 allowed a remote attacker to execute arbitrary code via a crafted HTML page. (Chromium security severity: High)

    Published: 17 Jun 2026
    8.3
    High

    CVE-2026-12465

    Last Modified: 18 Jun 2026

    Object lifecycle issue in Metrics in Google Chrome prior to 149.0.7827.155 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

    Published: 17 Jun 2026
    8.3
    High

    CVE-2026-12464

    Last Modified: 18 Jun 2026

    Use after free in Browser in Google Chrome prior to 149.0.7827.155 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

    Published: 17 Jun 2026
    4.7
    Medium

    CVE-2026-12463

    Last Modified: 17 Jun 2026

    Inappropriate implementation in Views in Google Chrome on Linux prior to 149.0.7827.155 allowed a remote attacker who had compromised the renderer process to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: High)

    Published: 17 Jun 2026
    7.5
    High

    CVE-2026-12462

    Last Modified: 18 Jun 2026

    Use after free in Media in Google Chrome prior to 149.0.7827.155 allowed a remote attacker who had compromised the renderer process to execute arbitrary code inside a sandbox via a crafted HTML page. (Chromium security severity: High)

    Published: 17 Jun 2026
    4.2
    Medium

    CVE-2026-12460

    Last Modified: 18 Jun 2026

    Insufficient policy enforcement in File System Access in Google Chrome prior to 149.0.7827.155 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted PDF file. (Chromium security severity: High)

    Published: 17 Jun 2026
    6.5
    Medium

    CVE-2026-12461

    Last Modified: 18 Jun 2026

    Out of bounds read in WebRTC in Google Chrome on Windows prior to 149.0.7827.155 allowed a remote attacker to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)

    Published: 17 Jun 2026
    3.1
    Low

    CVE-2026-12458

    Last Modified: 18 Jun 2026

    Inappropriate implementation in Passwords in Google Chrome prior to 149.0.7827.155 allowed a remote attacker who convinced a user to engage in specific UI gestures to leak cross-origin data via a crafted HTML page. (Chromium security severity: High)

    Published: 17 Jun 2026
    6.1
    Medium

    CVE-2026-12459

    Last Modified: 18 Jun 2026

    Inappropriate implementation in Serial in Google Chrome prior to 149.0.7827.155 allowed a remote attacker to inject arbitrary scripts or HTML (UXSS) via a crafted HTML page. (Chromium security severity: High)

    Published: 17 Jun 2026
    4.2
    Medium

    CVE-2026-12457

    Last Modified: 18 Jun 2026

    Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.155 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: High)

    Published: 17 Jun 2026
    7.5
    High

    CVE-2026-12455

    Last Modified: 18 Jun 2026

    Use after free in Tab Strip in Google Chrome prior to 149.0.7827.155 allowed a remote attacker who convinced a user to engage in specific UI gestures to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

    Published: 17 Jun 2026
    4.2
    Medium

    CVE-2026-12456

    Last Modified: 18 Jun 2026

    Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.155 allowed an attacker who convinced a user to install a malicious extension to bypass same origin policy via a crafted Chrome Extension. (Chromium security severity: High)

    Published: 17 Jun 2026
    4.2
    Medium

    CVE-2026-12453

    Last Modified: 18 Jun 2026

    Insufficient validation of untrusted input in Input in Google Chrome prior to 149.0.7827.155 allowed a remote attacker who had compromised the renderer process to bypass same origin policy via a crafted HTML page. (Chromium security severity: High)

    Published: 17 Jun 2026
    8.3
    High

    CVE-2026-12454

    Last Modified: 18 Jun 2026

    Race in Safe Browsing in Google Chrome on Mac prior to 149.0.7827.155 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

    Published: 17 Jun 2026
    8.8
    High

    CVE-2026-12452

    Last Modified: 18 Jun 2026

    Use after free in Downloads in Google Chrome on Android prior to 149.0.7827.155 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

    Published: 17 Jun 2026
    8.3
    High

    CVE-2026-12451

    Last Modified: 18 Jun 2026

    Use after free in DigitalCredentials in Google Chrome prior to 149.0.7827.155 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High)

    Published: 17 Jun 2026