CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2026-50630

    Last Modified: 7 Aug 2026

    A CRLF injection vulnerability exists in the OAuth2 AuthorizationUtils class. When constructing the WWW-Authenticate response header, the 'realm' parameter is concatenated without sanitizing Carriage Return (CR) and Line Feed (LF) characters. If an attacker can control the realm value, they can inject arbitrary HTTP headers or split the HTTP response entirely. Users are recommended to upgrade to versions 4.2.2 or 4.1.7 or 3.6.12, which fixes this issue.

    Published: 12 Jun 2026
    5.3
    Medium

    CVE-2026-50629

    Last Modified: 7 Aug 2026

    The 'clientId' parameter from incoming HTTP requests is directly concatenated into OAuth2 server log warning messages without sanitizing control characters. This allows an attacker to inject arbitrary content, including fake log entries, into the server's log files. Users are recommended to upgrade to versions 4.2.2 or 4.1.7 or 3.6.12, which fixes this issue.

    Published: 12 Jun 2026
    9.8
    Critical

    CVE-2026-50628

    Last Modified: 7 Aug 2026

    A logic error in OAuthRequestFilter rejects legitimate requests originating from the bound IP address, while blindly allowing requests from any other IP address. Enabling this security feature inadvertently creates an inverse security check. Users are recommended to upgrade to versions 4.2.2 or 4.1.7 or 3.6.12, which fixes this issue.

    Published: 12 Jun 2026
    9.1
    Critical

    CVE-2026-50627

    Last Modified: 7 Aug 2026

    The JwtAccessTokenValidator class in Apache CXF fails to validate the 'aud' (Audience) claims of incoming JWT access tokens. This allows a JWT issued for one Resource Server to be successfully replayed against a completely different Resource Server, leading to Token Confusion/Routing attacks. Users are recommended to upgrade to versions 4.2.2 or 4.1.7 or 3.6.12, which fixes this issue.

    Published: 12 Jun 2026
    9.8
    Critical

    CVE-2026-49875

    Last Modified: 7 Aug 2026

    Apache CXF's EndpointReferenceUtils and W3CMultiSchemaFactory classes construct a SAXParserFactory without the necessary JAXP hardening configurations, enabling out-of-band (OOB) external entity resolution. Users are recommended to upgrade to versions 4.2.2 or 4.1.7 or 3.6.12, which fix this issue.

    Published: 12 Jun 2026
    4.8
    Medium

    CVE-2026-50623

    Last Modified: 7 Aug 2026

    An authentication bypass vulnerability exists in the OAuth2 TokenIntrospectionService in Apache CXF. Due to a missing 'throw' keyword in the security context check, the introspection endpoint (/services/oauth2/introspect) can be accessed by any unauthenticated network attacker. However note that this is a safeguard only in the case that someone forgot to enable authentication on the service. Users are recommended to upgrade to version 4.2.2 or 4.1.7 or 3.6.12, which fixes this issue.

    Published: 12 Jun 2026
    5.3
    Medium

    CVE-2026-12058

    Last Modified: 12 Jun 2026

    The connection confirmation pop-up of a specific feature in the PcSuite can be bypassed.

    Published: 12 Jun 2026
    9.4
    Critical

    CVE-2026-11535

    Last Modified: 12 Jun 2026

    An unauthorized access vulnerability exists in the PcSuite APP. The vulnerability can be exploited by attackers to Unauthorized access to the victim’s device.

    Published: 12 Jun 2026
    6.9
    Medium

    CVE-2026-12060

    Last Modified: 12 Jun 2026

    Heptabase developed by Hepta Platforms has a Exposed Dangerous Method or Function vulnerability, allowing unauthenticated remote attackers to leverage social engineering techniques to trick a victim into opening or loading a malicious webpage within the Heptabase application, thereby gaining unauthorized access to camera and microphone permissions.

    Published: 12 Jun 2026
    8.7
    High

    CVE-2026-12059

    Last Modified: 12 Jun 2026

    The SSH service of CelloOS developed by Cellopoint has an Improper Access Control vulnerability, allowing authenticated remote attackers to bypass the enforced command restrictions and execute operating system commands outside the originally authorized scope.

    Published: 12 Jun 2026
    5.9
    Medium

    CVE-2026-9271

    Last Modified: 12 Jun 2026

    Vulnerability Title

    Published: 12 Jun 2026
    3.5
    Low

    CVE-2026-9269

    Last Modified: 12 Jun 2026

    The Secure Copy Content Protection and Content Locking WordPress plugin before 5.1.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup).

    Published: 12 Jun 2026
    7.5
    High

    CVE-2026-44892

    Last Modified: 15 Jun 2026

    Netty is a network application framework for development of protocol servers and clients. Prior to version 4.2.15.Final, the default configuration of the `Http3ConnectionHandler` in the Netty HTTP/3 codec lacks an enforced maximum header size limit. When a peer does not explicitly specify `HTTP3_SETTINGS_MAX_FIELD_SECTION_SIZE`, the implementation defaults to an unbounded limit. This insecure default configuration allows a malicious client or server to send an enormous number of headers, leading to a memory exhaustion Denial of Service via an `OutOfMemoryError`. Version 4.2.15.Final contains a patch.

    Published: 12 Jun 2026
    8.7
    High

    CVE-2026-45169

    Last Modified: 12 Jun 2026

    Idira Privileged Access Manager (PAM) Self-Hosted Vault versions prior to 15.0.3, 14.6.5, 14.2.7, and 14.0.8 exhibit a validation vulnerability. Under specific circumstances and configuration scenarios, processing unexpected input could potentially lead to an unexpected service termination, resulting in a localized denial of service (DoS). CyberArk Security Bulletin: CA26-17

    Published: 12 Jun 2026
    9.9
    Critical

    CVE-2026-47370

    Last Modified: 12 Jun 2026

    A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in certain devices running UniFi OS to execute a Command Injection within such UniFi OS devices or instances.

    Published: 12 Jun 2026
    9.9
    Critical

    CVE-2026-47369

    Last Modified: 12 Jun 2026

    A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in certain devices running UniFi OS to escalate privileges within such UniFi OS devices or instances.

    Published: 12 Jun 2026
    5.9
    Medium

    CVE-2026-48613

    Last Modified: 12 Jun 2026

    SQL injection vulnerability in phpBB profile field migration due to improper handling of user-supplied profile field data during migration, allowing execution of arbitrary SQL queries. Only applies to phpBB forums that had been updated from versions prior to phpBB 3.3.8 and have not been updated to 3.3.11 or newer yet.

    Published: 12 Jun 2026
    8.6
    High

    CVE-2026-47368

    Last Modified: 12 Jun 2026

    A malicious actor with access to the network could exploit a Path Traversal vulnerability found in certain devices running UniFi OS to obtain data from such UniFi OS devices or instances.

    Published: 12 Jun 2026
    8
    High

    CVE-2026-48612

    Last Modified: 12 Jun 2026

    Improper state verification in the OAuth implementation could allow an attacker to manipulate the authentication flow and cause a victim’s account to be linked to an attacker-controlled account. This can result in unauthorized account linking and potential account takeover.

    Published: 12 Jun 2026
    9.9
    Critical

    CVE-2026-47367

    Last Modified: 12 Jun 2026

    A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UID Enterprise Agent to execute a Command Injection on the host device.

    Published: 12 Jun 2026
    8.1
    High

    CVE-2026-48610

    Last Modified: 12 Jun 2026

    Under certain network configurations, a malicious actor with access to network could exploit an Improper Access Control vulnerability found in certain devices running UniFi OS to make unauthorized changes to such UniFi OS devices.

    Published: 12 Jun 2026
    7.2
    High

    CVE-2026-47366

    Last Modified: 12 Jun 2026

    Improper verification of access permissions when modifying permissions through the Administration Control Panel (ACP) allowed an authenticated administrator to grant permissions beyond the level authorized for their account, resulting in privilege escalation within the administrative interface.

    Published: 12 Jun 2026
    9.9
    Critical

    CVE-2026-47365

    Last Modified: 12 Jun 2026

    Argument injection vulnerability in WordPress Toolkit before 6.11.0 as used in cPanel & WHM, allows remote authenticated users to bypass cross-tenant authorization and execute arbitrary wp-toolkit CLI commands as another account.

    Published: 12 Jun 2026
    9.8
    Critical

    CVE-2026-48611

    Last Modified: 31 Jul 2026

    Improper authentication checks in the OAuth implementation allow account hijacking even when OAuth is not configured or enabled leading to unauthorized access in default installations.

    Published: 12 Jun 2026
    6.3
    Medium

    CVE-2026-20746

    Last Modified: 28 Aug 2026

    Virtual attribute handling in Ping Identity PingDirectory in affected versions allows only authorized users to exhaust java memory heap when recent login history is enabled and copying virtual attributes that reference ds-privilege-name values.

    Published: 12 Jun 2026
    8.7
    High

    CVE-2026-11933

    Last Modified: 12 Jun 2026

    A use-after-free vulnerability exists in MongoDB Server's server-side JavaScript engine when converting BSON documents to JavaScript arrays. An authenticated user with read privileges who is able to run server-side JavaScript (for example, via $where or $function) can cause the server to access memory that has already been freed. This may result in disclosure of information from the mongod process memory or a denial of service through a server crash.

    Published: 12 Jun 2026
    6.4
    Medium

    CVE-2026-9125

    Last Modified: 28 Aug 2026

    The Presto Player plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'link_url' parameter of the [presto_player_overlay] shortcode in versions up to, and including, 4.2.0 This is due to insufficient input sanitization and output escaping in the getOverlays() function, which copies the link_url shortcode attribute directly into the overlay configuration without scheme validation, allowing javascript: URIs to survive and be rendered as the href of a clickable anchor element by the presto-dynamic-overlay-ui web component. This makes it possible for authenticated attackers, with contributor-level access and above, to inject arbitrary web scripts in pages that will execute whenever a user accesses an injected page.

    Published: 12 Jun 2026
    7.5
    High

    CVE-2026-45170

    Last Modified: 23 Jun 2026

    Idira Vendor PAM - Self-Hosted Connector versions prior 1.1.100504 under specific conditions and configuration scenarios, TLS certificate validation may not be fully enforced. CyberArk Security Bulletin: CA26-17

    Published: 12 Jun 2026
    7.1
    High

    CVE-2026-53704

    Last Modified: 8 Sept 2026

    A flaw was found in GStreamer's RealMedia demuxer in the gst-plugins-ugly package. When processing a RealMedia file containing a specially crafted FILEINFO metadata section, the demuxer parses variable-name and variable-value pairs using re_skip_pascal_string() without validating that offsets remain within the mapped buffer. Additionally, the element count controlling the parsing loop is read from attacker-controlled data without validation, which can cause an infinite loop. A crafted RealMedia file can cause the application to crash, hang, or potentially read limited adjacent memory contents.

    Published: 12 Jun 2026
    7.6
    High

    CVE-2026-53705

    Last Modified: 3 Aug 2026

    A flaw was found in GStreamer's WavPack audio decoder in gst-plugins-good. When processing a specially crafted WavPack file, an integer overflow in the buffer size calculation (4 * block_samples * channels) in gst_wavpack_dec_handle_frame() causes a very small heap allocation. The WavPack library then writes decoded audio samples far beyond the allocated buffer, resulting in heap memory corruption. This affects both 32-bit and 64-bit systems since the arithmetic is performed in 32-bit integers before promotion to the allocation size type. A remote attacker could use this flaw to crash an application or potentially execute arbitrary code by convincing a user to open a malicious WavPack audio file.

    Published: 12 Jun 2026
    7.1
    High

    CVE-2026-53703

    Last Modified: 5 Aug 2026

    A vulnerability was found in the GStreamer RealMedia demuxer (gst-plugins-ugly). When processing a RealMedia (.rm) file, the demuxer parses MDPR (media properties) chunks to configure audio streams. For audio stream header versions 4 and 5, the parser reads fields such as codec type, packet size, sample rate, channel count, and extra codec data length from fixed offsets within the chunk without first checking that the chunk contains enough data. If a malicious file provides an MDPR chunk that is too small to contain a complete audio stream header, the parser reads beyond the end of the buffer. This can cause the application to crash. In some cases, bytes read past the buffer boundary may be incorporated into stream metadata, which could result in limited information disclosure.

    Published: 12 Jun 2026
    5.5
    Medium

    CVE-2026-12893

    Last Modified: 12 Jun 2026

    A flaw was found in the GStreamer gst-libav plugin. A NULL pointer dereference in the demuxer error handler can be triggered when processing malformed media files, such as crafted Musepack (.mpc) files. When a user or application opens such a file using GStreamer, the application crashes, resulting in a denial of service.

    Published: 12 Jun 2026
    4.3
    Medium

    CVE-2026-49482

    Last Modified: 12 Jun 2026

    ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 - #141, ClipBucket v5 contains an improper neutralization of SQL wildcard characters in the subtitle editing endpoint. An authenticated user can send a % character as the number parameter to overwrite all subtitle titles of any video they own in a single HTTP request. This issue has been patched in version 5.5.3 - #141.

    Published: 11 Jun 2026
    6.5
    Medium

    CVE-2026-47238

    Last Modified: 13 Jun 2026

    ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 - #133, a normal authenticated user can edit another user's video subtitles because of a lack of authorization. They can upload subtitles, edit their name or delete them. This issue has been patched in version 5.5.3 - #133.

    Published: 11 Jun 2026
    9.8
    Critical

    CVE-2026-45060

    Last Modified: 12 Jun 2026

    ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 - #129, the actions/progress_video.php endpoint is vulnerable to blind SQL injection. Any unauthenticated user can exploit the ids parameter to execute SQL queries and exfiltrate sensitive data. This issue has been patched in version 5.5.3 - #129.

    Published: 11 Jun 2026
    9.8
    Critical

    CVE-2026-42846

    Last Modified: 12 Jun 2026

    ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 - #140, ClipBucket's Remote Play feature allows any authenticated user to add a video by importing an external URL as the source. Some shell commands are run with the URL as a parameter. The URL is concatenated directly into shell commands without escaping then executed, so any shell metacharacter in the URL is interpreted. This results in arbitrary command execution. This issue has been patched in version 5.5.3 - #140.

    Published: 11 Jun 2026
    8.8
    High

    CVE-2026-45418

    Last Modified: 12 Jun 2026

    ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 - #132, any authenticated user who can upload videos can add multiple subtitles from different files and change their title (English, Spanish...). The POST /actions/subtitle_edit.php request used to change their title includes a number parameter which is vulnerable to SQL Injection. A boolean-based blind SQL injection can be used to exfiltrate sensitive data. This issue has been patched in version 5.5.3 - #132.

    Published: 11 Jun 2026
    8.7
    High

    CVE-2026-45171

    Last Modified: 12 Jun 2026

    Incomplete input validation and improperly configured folder permissions within Idira Privileged Session Manager (PSM) versions prior to 15.0.3, 14.6.3, 14.2.5, and 14.0.5, an authenticated, low-privileged user could potentially execute arbitrary code. CyberArk Security Bulletin: CA26-17 and CA26-18

    Published: 11 Jun 2026
    8.7
    High

    CVE-2026-45172

    Last Modified: 12 Jun 2026

    Due to incomplete input validation in Idira Privileged Session Manager for SSH (PSMP) versions prior to 15.0.2, 14.6.3, 14.2.5, and 14.0.6, an authenticated, low-privileged user could potentially execute arbitrary commands on the PSMP host. CyberArk Security Bulletins: CA26-17 and CA26-18

    Published: 11 Jun 2026
    8.4
    High

    CVE-2026-45173

    Last Modified: 12 Jun 2026

    Idira Identity Browser Extension (Chrome, Firefox, and Edge builds) versions prior to 26.8.1 exhibit an origin validation flaw within its internal web-page verification routines. If an authenticated user navigates to a specially crafted webpage, this interaction could potentially allow a remote attacker to trigger unauthorized application interaction or execution parameters within the context of that authenticated browser session. CyberArk Security Bulletin: CA26-21

    Published: 11 Jun 2026
    8.5
    High

    CVE-2026-45174

    Last Modified: 12 Jun 2026

    Idira Endpoint Privilege Manager Linux Agent versions prior to 26.5 allow a local attacker to potentially compromise the agent daemon initialization. CyberArk Security Bulletin: CA26-19

    Published: 11 Jun 2026
    7.1
    High

    CVE-2026-42653

    Last Modified: 12 Jun 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in iova.Mihai SliceWP allows Stored XSS. This issue affects SliceWP: from n/a through 1.2.6.

    Published: 11 Jun 2026
    9.3
    Critical

    CVE-2026-39494

    Last Modified: 12 Jun 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WBW Plugins Product Filter by WBW allows Blind SQL Injection. This issue affects Product Filter by WBW: from n/a through 3.1.2.

    Published: 11 Jun 2026
    9.3
    Critical

    CVE-2026-42647

    Last Modified: 12 Jun 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Beardev JoomSport allows Blind SQL Injection. This issue affects JoomSport: from n/a through 5.7.7.

    Published: 11 Jun 2026
    9.8
    Critical

    CVE-2026-49060

    Last Modified: 12 Jun 2026

    Incorrect Privilege Assignment vulnerability in Hippoo Mobile App for WooCommerce allows Privilege Escalation. This issue affects Hippoo Mobile App for WooCommerce: from n/a through 1.9.4.

    Published: 11 Jun 2026
    7.5
    High

    CVE-2026-44890

    Last Modified: 12 Aug 2026

    Netty is a network application framework for development of protocol servers and clients. In netty-codec-redis prior to versions 4.1.135.Final and 4.2.15.Final, an attacker can cause DoS by sending crafted Redis payloads across multiple connections without `\r\n`. This exhausts the server's direct memory pool (OutOfDirectMemoryError), preventing legitimate connections from being processed. Versions 4.1.135.Final and 4.2.15.Final patch the issue.

    Published: 11 Jun 2026
    7.5
    High

    CVE-2026-44250

    Last Modified: 12 Aug 2026

    Netty is a network application framework for development of protocol servers and clients. In netty-codec-redis prior to versions 4.1.135.Final and 4.2.15.Final, an attacker can cause DoS by sending a crafted Redis payload with deeply nested arrays. This forces the server to allocate a massive number of state objects and collections, leading to memory exhaustion and an OutOfMemoryError. Versions 4.1.135.Final and 4.2.15.Final patch the issue.

    Published: 11 Jun 2026
    8.8
    High

    CVE-2026-12035

    Last Modified: 12 Jun 2026

    Use after free in Views in Google Chrome on Windows prior to 149.0.7827.115 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High)

    Published: 11 Jun 2026
    8.3
    High

    CVE-2026-12034

    Last Modified: 12 Jun 2026

    Insufficient validation of untrusted input in Linux Toolkit Theming in Google Chrome on Linux prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a malicious file. (Chromium security severity: High)

    Published: 11 Jun 2026
    5.3
    Medium

    CVE-2026-12033

    Last Modified: 12 Jun 2026

    Out of bounds read in VideoCapture in Google Chrome prior to 149.0.7827.115 allowed a remote attacker who had compromised the GPU process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: High)

    Published: 11 Jun 2026