CVE Feed

    Dashboard / CVE

    6.3
    Medium

    CVE-2026-47909

    Last Modified: 11 Jun 2026

    Dreamweaver Desktop versions 21.7 and earlier are affected by an Improper Input Validation vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.

    Published: 9 Jun 2026
    6.3
    Medium

    CVE-2026-47910

    Last Modified: 11 Jun 2026

    Dreamweaver Desktop versions 21.7 and earlier are affected by an Incorrect Authorization vulnerability that could lead to arbitrary file system read. An attacker could exploit this vulnerability to access sensitive files and directories outside the intended access scope. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.

    Published: 9 Jun 2026
    8.6
    High

    CVE-2026-47907

    Last Modified: 23 Jun 2026

    Dreamweaver Desktop versions 21.7 and earlier are affected by an Improper Access Control vulnerability that could result in arbitrary code execution in the context of the current user. An attacker could exploit this vulnerability to execute arbitrary code. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.

    Published: 9 Jun 2026
    8.6
    High

    CVE-2026-47906

    Last Modified: 11 Jun 2026

    Dreamweaver Desktop versions 21.7 and earlier are affected by a Dependency on Vulnerable Third-Party Component vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file. Scope is changed.

    Published: 9 Jun 2026
    7.8
    High

    CVE-2026-47908

    Last Modified: 11 Jun 2026

    Dreamweaver Desktop versions 21.7 and earlier are affected by an Access of Uninitialized Pointer vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 9 Jun 2026
    8.5
    High

    CVE-2026-11824

    Last Modified: 11 Jun 2026

    SQLite before 3.53.2 contains a heap-based buffer overflow vulnerability in the FTS5 full-text search extension that allows attackers to cause a crash or execute arbitrary code by supplying a crafted database with malicious continuation page metadata specifying a szLeaf value smaller than 4. Attackers can trigger an integer underflow in fts5ChunkIterate() causing an inflated remaining byte count during FTS5 MATCH query processing, leading to a heap buffer overflow of attacker-controlled data in applications compiled with SQLITE_ENABLE_FTS5.

    Published: 9 Jun 2026
    7.8
    High

    CVE-2026-48306

    Last Modified: 11 Jun 2026

    Substance3D - Sampler versions 6.0.0 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 9 Jun 2026
    7.8
    High

    CVE-2026-34710

    Last Modified: 11 Jun 2026

    Substance3D - Sampler versions 6.0.0 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 9 Jun 2026
    7.8
    High

    CVE-2026-48305

    Last Modified: 11 Jun 2026

    Substance3D - Sampler versions 6.0.0 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 9 Jun 2026
    7.8
    High

    CVE-2026-34709

    Last Modified: 11 Jun 2026

    Substance3D - Sampler versions 6.0.0 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 9 Jun 2026
    5.1
    Medium

    CVE-2026-47106

    Last Modified: 14 Jul 2026

    Ellucian Banner Self-Service before the April T2 release (2025-04-23) contains a stored cross-site scripting vulnerability in the course search functionality that allows authenticated Banner ERP users to inject malicious payloads into faculty and course fields by exploiting missing HTML encoding during DOM insertion. An attacker with Banner ERP write access can store malicious JavaScript in fields such as faculty displayName, emailAddress, subjectDescription, or courseTitle; these values are subsequently served unsanitized by the unauthenticated getFacultyMeetingTimes API endpoint, causing arbitrary script execution in the browser of any user who views the affected course's meeting times.

    Published: 9 Jun 2026
    5.1
    Medium

    CVE-2026-32856

    Last Modified: 14 Jul 2026

    Ellucian Banner Self-Service before the April T2 release (2025-04-23) contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to execute arbitrary JavaScript in a victim's browser by injecting unsanitized input through the toDateFormat request parameter in the dateConverter endpoint. Attackers can craft a malicious URL targeting the unauthenticated dateConverter endpoint to steal session cookies or perform other malicious actions in the context of the victim's browser session.

    Published: 9 Jun 2026
    8.5
    High

    CVE-2026-11822

    Last Modified: 11 Jun 2026

    SQLite before 3.53.2 contains memory corruption vulnerabilities in the FTS5 full-text search extension that allow attackers to cause process crashes, memory exhaustion, or arbitrary code execution by supplying a crafted database with malformed FTS5 page data. Attackers can trigger an out-of-bounds read in fts5LeafSeek() via an attacker-controlled loop bound and a heap buffer overflow write in fts5ChunkIterate() through a crafted continuation page causing an integer underflow, exploitable when an FTS5 MATCH query is executed against the malicious database.

    Published: 9 Jun 2026
    8.6
    High

    CVE-2026-6444

    Last Modified: 10 Jun 2026

    A flaw exists in the FlashArray Purity management interface where an authenticated low-privileged user may, under specific conditions, access functionality beyond their assigned privileges.

    Published: 9 Jun 2026
    8.7
    High

    CVE-2026-6445

    Last Modified: 10 Jun 2026

    A flaw exists in FlashArray Purity where insufficient filtering of certain data paths could expose sensitive information to an authenticated user with low privileges.

    Published: 9 Jun 2026
    7.8
    High

    CVE-2026-8863

    Last Modified: 10 Jun 2026

    Multiple Microsoft-sigend UEFI SHIM bootloaders are vulnerable to SecureBoot bypass. An attacker with administrative privileges or the ability to modify the boot process could use one of the vulnerable shim bootloaders to bypass Secure Boot protections and execute arbitrary code before the operating system loads. Specific UEFI DBX update is required to block these vulnerable boot loaders.

    Published: 9 Jun 2026
    9.8
    Critical

    CVE-2026-10045

    Last Modified: 10 Jun 2026

    Shenzhen Kangda Xin Intelligent Network Technology Company's router, model DR300, version 2.1.2.121, contains hardcoded login credentials and has telnet enabled by default on WAN and LAN interfaces. These vulnerabilities allow attackers to read and write to memory, modify firmware stored in flash, inspect active connections, and view currently connected devices.

    Published: 9 Jun 2026
    5.7
    Medium

    CVE-2026-40639

    Last Modified: 10 Jun 2026

    Dell Client Platform BIOS contains a Weak Encoding for Password vulnerability. An unauthenticated attacker with physical access could potentially exploit this vulnerability, leading to Elevation of Privileges.

    Published: 9 Jun 2026
    6.3
    Medium

    CVE-2026-44275

    Last Modified: 10 Jun 2026

    Dell/Alienware Purchased Apps, versions prior to 1.1.32.0, contain an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Arbitrary File Write

    Published: 9 Jun 2026
    7.8
    High

    CVE-2026-34707

    Last Modified: 10 Jun 2026

    InCopy versions 21.3, 20.5.3 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 9 Jun 2026
    7.8
    High

    CVE-2026-34706

    Last Modified: 10 Jun 2026

    InCopy versions 21.3, 20.5.3 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 9 Jun 2026
    7.8
    High

    CVE-2026-34708

    Last Modified: 10 Jun 2026

    InCopy versions 21.3, 20.5.3 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 9 Jun 2026
    7.8
    High

    CVE-2026-34701

    Last Modified: 10 Jun 2026

    InDesign Desktop versions 21.3, 20.5.3 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 9 Jun 2026
    7.8
    High

    CVE-2026-34695

    Last Modified: 10 Jun 2026

    InDesign Desktop versions 21.3, 20.5.3 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 9 Jun 2026
    5.5
    Medium

    CVE-2026-34704

    Last Modified: 10 Jun 2026

    InDesign Desktop versions 21.3, 20.5.3 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 9 Jun 2026
    7.8
    High

    CVE-2026-34700

    Last Modified: 10 Jun 2026

    InDesign Desktop versions 21.3, 20.5.3 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 9 Jun 2026
    7.8
    High

    CVE-2026-34696

    Last Modified: 10 Jun 2026

    InDesign Desktop versions 21.3, 20.5.3 and earlier are affected by a Use After Free vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 9 Jun 2026
    5.5
    Medium

    CVE-2026-34703

    Last Modified: 10 Jun 2026

    InDesign Desktop versions 21.3, 20.5.3 and earlier are affected by a NULL Pointer Dereference vulnerability that could result in an application denial-of-service. An attacker could exploit this vulnerability to crash the application, leading to a denial-of-service condition. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 9 Jun 2026
    7.8
    High

    CVE-2026-34698

    Last Modified: 10 Jun 2026

    InDesign Desktop versions 21.3, 20.5.3 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 9 Jun 2026
    7.8
    High

    CVE-2026-34699

    Last Modified: 10 Jun 2026

    InDesign Desktop versions 21.3, 20.5.3 and earlier are affected by a Heap-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 9 Jun 2026
    5.5
    Medium

    CVE-2026-34705

    Last Modified: 10 Jun 2026

    InDesign Desktop versions 21.3, 20.5.3 and earlier are affected by an out-of-bounds read vulnerability that could lead to disclosure of sensitive memory. An attacker could leverage this vulnerability to disclose sensitive information. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 9 Jun 2026
    7.8
    High

    CVE-2026-34697

    Last Modified: 10 Jun 2026

    InDesign Desktop versions 21.3, 20.5.3 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 9 Jun 2026
    7.8
    High

    CVE-2026-48293

    Last Modified: 11 Jun 2026

    InDesign Desktop versions 21.3, 20.5.3 and earlier are affected by an out-of-bounds write vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 9 Jun 2026
    7.8
    High

    CVE-2026-34702

    Last Modified: 10 Jun 2026

    InDesign Desktop versions 21.3, 20.5.3 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitation of this issue requires user interaction in that a victim must open a malicious file.

    Published: 9 Jun 2026
    7.8
    High

    CVE-2026-50511

    Last Modified: 10 Jun 2026

    Improper link resolution before file access ('link following') in Microsoft PC Manager allows an authorized attacker to elevate privileges locally.

    Published: 9 Jun 2026
    7.8
    High

    CVE-2026-50512

    Last Modified: 8 Jul 2026

    Missing authentication for critical function in Microsoft PC Manager allows an authorized attacker to elevate privileges locally.

    Published: 9 Jun 2026
    8.7
    High

    CVE-2026-50636

    Last Modified: 10 Jun 2026

    The RemoteControl API methods invite_participants and remind_participants pass a caller-supplied token-ID array into TokenDynamic::findUninvited(), which concatenates the values directly into a tid IN ('...') SQL clause without parameterization or input validation. A remote, authenticated attacker holding the tokens/update permission on a survey can inject a crafted array element to perform SQL injection. Because LimeSurvey configures its PDO connection with emulated prepared statements (emulatePrepare = true) and does not disable MySQL multi-statements, the injection supports stacked queries: the attacker can append arbitrary additional statements (INSERT/UPDATE/DELETE/DROP/CREATE) after the original SELECT. This permits both arbitrary read of any data in the database, such as administrator bcrypt password hashes (lime_users), survey response PII, session records, and global settings, all recoverable via a SLEEP() time-based blind oracle, and arbitrary write/destruction of that data, including directly overwriting the administrator password hash for immediate account takeover or dropping/truncating tables. Reads and writes extend to any schema the application's database user can access. The RemoteControl interface (RPCInterface = json/xml) must be enabled, which is not the default.

    Published: 9 Jun 2026
    8.7
    High

    CVE-2026-50635

    Last Modified: 9 Jun 2026

    LimeSurvey constructs account password-reset links from the client-supplied HTTP Host header without validating it. The optional allowedHosts allowlist that would constrain this is undefined in the default (and documented) configuration, so LSHttpRequest::checkIsAllowedHost() results in no operation. A remote, unauthenticated attacker who submits a forgotten-password request for a known account (requiring only the target's username and email) with a spoofed Host header causes LimeSurvey to email that account a reset link whose hostname is attacker-controlled while embedding the genuine validation_key. When the recipient or an automated inbound mail-security link scanner dereferences the link, the valid reset token is disclosed to the attacker, who replays it against the legitimate host's newPassword endpoint to set a new password and take over the account.

    Published: 9 Jun 2026
    6.8
    Medium

    CVE-2026-28237

    Last Modified: 16 Jun 2026

    Unrestricted resource allocation in AMD uProf may be exploitable to consume excessive system resources, potentially leading to a loss of availability.

    Published: 9 Jun 2026
    6.8
    Medium

    CVE-2026-0466

    Last Modified: 16 Jun 2026

    Improper access control in AMD uProf may allow a local attacker with user privileges to write to the kernel-shared memory section, potentially resulting in crash or denial of service.

    Published: 9 Jun 2026
    6.3
    Medium

    CVE-2026-41116

    Last Modified: 10 Jun 2026

    Dell Inventory Collector Client, versions prior to 13.8.0, contain an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Arbitrary File Write.

    Published: 9 Jun 2026
    4
    Medium

    CVE-2025-54509

    Last Modified: 31 Jul 2026

    Improper access control for register interface in the Input-Output Memory Management Unit (IOMMU) could allow a privileged attacker to cause non-coherent accesses by the AMD Secure Processor (ASP), potentially resulting in loss of integrity.

    Published: 9 Jun 2026
    8
    High

    CVE-2026-34693

    Last Modified: 11 Jun 2026

    Adobe Experience Manager Forms JEE versions LTS SP1, 6.5.24.0 and earlier are affected by a reflected Cross-Site Scripting (XSS) vulnerability. An attacker could exploit this vulnerability to inject malicious scripts into a web page, potentially gaining elevated access or control over the victim's account or session. Exploit depends on conditions beyond the attacker's control. Exploitation of this issue requires user interaction in that a victim must visit a maliciously crafted URL or interact with a compromised web page. Scope is changed.

    Published: 9 Jun 2026
    4.8
    Medium

    CVE-2026-34694

    Last Modified: 23 Jun 2026

    Adobe Experience Manager Forms JEE versions LTS SP1, 6.5.24.0 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-privileged attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field. Scope is changed.

    Published: 9 Jun 2026
    9.3
    Critical

    CVE-2026-34691

    Last Modified: 11 Jun 2026

    Adobe Experience Manager Forms JEE versions LTS SP1, 6.5.24.0 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by an attacker to inject malicious scripts into vulnerable form fields. Malicious JavaScript may be executed in a victim's browser when they browse to the page containing the vulnerable field, potentially gaining elevated access or control over the victim's account or session. Scope is changed.

    Published: 9 Jun 2026
    7.8
    High

    CVE-2026-44804

    Last Modified: 12 Jun 2026

    Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

    Published: 9 Jun 2026
    7.8
    High

    CVE-2026-44813

    Last Modified: 12 Jun 2026

    Use after free in Windows DWM Core Library allows an authorized attacker to elevate privileges locally.

    Published: 9 Jun 2026
    7.5
    High

    CVE-2026-42993

    Last Modified: 15 Jun 2026

    Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.

    Published: 9 Jun 2026
    7.8
    High

    CVE-2026-44812

    Last Modified: 10 Jun 2026

    Integer overflow or wraparound in Windows Win32K - GRFX allows an unauthorized attacker to execute code locally.

    Published: 9 Jun 2026
    7.8
    High

    CVE-2026-44803

    Last Modified: 10 Jun 2026

    Integer overflow or wraparound in Windows Win32K - GRFX allows an unauthorized attacker to execute code locally.

    Published: 9 Jun 2026