CVE Feed

    Dashboard / CVE

    8.7
    High

    CVE-2026-21837

    Last Modified: 10 Jun 2026

    HCL Digital Experience is affected by an OS command injection vulnerability in the Digital Asset Management API.  An attacker may execute arbitrary operating system commands, typically inheriting the privileges of the vulnerable application, which could possibly lead to a complete system takeover and data compromise.

    Published: 5 Jun 2026
    5.6
    Medium

    CVE-2026-10732

    Last Modified: 5 Jun 2026

    All versions of the package decompress are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip) when extracting a ZIP archive containing two entries with the same path - the first being a symlink to an arbitrary target and the second being a regular file - the file content is written through the symlink to the target location outside the output directory. This is due to the microtask processing order that checks readlink for the second file before resolving symlink for the first file. An attacker can write arbitrary file on the host filesystem potentially leading to remote code execution by providing a specially crafted ZIP archive. **Note:** This bypasses all existing path traversal protections including preventWritingThroughSymlink, added as a part of the fix for [CVE-2020-12265](https://security.snyk.io/vuln/SNYK-JS-DECOMPRESS-557358).

    Published: 5 Jun 2026
    7.3
    High

    CVE-2026-50593

    Last Modified: 5 Jun 2026

    Graphite before 1.3.15 has an integer underflow and resultant out-of-bounds write via Graphite actions, because slotat does not ensure that an offset is within the allowed slot-map range.

    Published: 5 Jun 2026
    6.4
    Medium

    CVE-2026-50592

    Last Modified: 5 Jun 2026

    In Znuny LTS before 6.5.21 and Znuny before 7.3.3, there is reflected XSS in AdminCommunicationLog (aka the communication log administration view).

    Published: 5 Jun 2026
    5.4
    Medium

    CVE-2026-50591

    Last Modified: 5 Jun 2026

    In Znuny LTS before 6.5.21 and Znuny before 7.3.3, XSS can occur via stored user preferences.

    Published: 5 Jun 2026
    9.8
    Critical

    CVE-2026-7763

    Last Modified: 6 Jun 2026

    A heap-based buffer overflow vulnerability in the morse.ko HaLow Wi-Fi kernel driver in Morse Micro HaLowLink 2 software versions prior to 2.11.13 allows an unauthenticated attacker within radio range to cause a Denial of Service (kernel panic) or potentially achieve Remote Code Execution via a crafted 802.11ah beacon frame containing a malformed Traffic Indication Map (TIM) Information Element. The function morse_page_slicing_process_tim_element() in page_slicing.c derives the TIM bitmap length directly from a received IE field without validating it against the fixed-size destination buffer before passing it to memset and memcpy operations, allowing up to 252 bytes of attacker-controlled data to be written beyond the buffer boundary. Because beacons are broadcast frames processed during passive scanning, no authentication, association, or user interaction is required.

    Published: 5 Jun 2026
    9.8
    Critical

    CVE-2026-7762

    Last Modified: 5 Jun 2026

    A heap-based buffer overflow vulnerability in the dot11ah.ko HaLow Wi-Fi kernel driver in Morse Micro HaLowLink 2 software versions prior to 2.11.13 allows an unauthenticated attacker within radio range to cause a Denial of Service (kernel panic) or potentially achieve Remote Code Execution via a crafted 802.11ah beacon or probe response frame containing a malformed S1G Capabilities Information Element (IE element ID 0xD9). The function morse_dot11ah_find_s1g_caps_for_bssid() uses the IE length field directly as the size argument to memcpy without validating it against the 15-byte destination buffer. An attacker can supply up to 255 bytes, causing an overflow of up to 240 bytes of attacker-controlled data into adjacent kernel heap memory. The vulnerability is triggerable during normal scanning without authentication, association, or user interaction.

    Published: 5 Jun 2026
    7.2
    High

    CVE-2026-41567

    Last Modified: 5 Jun 2026

    Moby is an open source container framework. In versions prior to 29.5.1 and in moby/moby v2 prior to v2.0.0-beta.14, when a compressed archive is uploaded to a container via `PUT /containers/{id}/archive` or piped through `docker cp -`, the daemon resolves decompression binaries (such as `xz` or `unpigz`) from the container's filesystem rather than the host's due to incorrect ordering of operations. A malicious container image containing a trojanized decompression binary can achieve arbitrary code execution with full daemon privileges, including host root UID and unrestricted capabilities, when a user uploads a compressed (xz or gzip) archive into that container. This issue is fixed in Docker Engine 29.5.1 and moby/moby v2.0.0-beta.14. Workarounds include only running containers from trusted images, using authorization plugins to restrict access to the `PUT /containers/{id}/archive` endpoint, and avoiding piping compressed archives into containers created from untrusted images

    Published: 5 Jun 2026
    1.9
    Low

    CVE-2026-11312

    Last Modified: 5 Jun 2026

    A vulnerability was found in bytedance InfiniStore up to 0.2.33. The impacted element is the function purge_kv_map in the library /src/infinistore.h of the component KV Map Handler. Performing a manipulation results in inefficient algorithmic complexity. The attack requires a local approach. The exploit has been made public and could be used. The project was informed of the problem early through an issue report but has not responded yet.

    Published: 5 Jun 2026
    4.5
    Medium

    CVE-2026-50590

    Last Modified: 5 Jun 2026

    In Mimecast Incydr before 2.6.0, arbitrary file access can occur.

    Published: 5 Jun 2026
    6
    Medium

    CVE-2026-11326

    Last Modified: 5 Jun 2026

    OpenAI Atlas before 1.2025.288.15 exposed privileged browser APIs to web content on *.openai.com origins. A cross-site scripting vulnerability in forum.openai.com could be used to access these functions, allowing access to browser history information and the ability to open or close tabs. OpenAI Atlas 1.2025.288.15 narrows access to these APIs to *.chatgpt.com; users should upgrade to 1.2025.288.15 or later.

    Published: 5 Jun 2026
    2.1
    Low

    CVE-2026-10878

    Last Modified: 5 Jun 2026

    A vulnerability was detected in D-Link DWR-M920 1.1.50/1.1.70. Affected is the function sub_41C8E8 of the file /boafrm/formSmsManage. Performing a manipulation of the argument action_value results in command injection. The attack is possible to be carried out remotely. The exploit is now public and may be used.

    Published: 5 Jun 2026
    9.1
    Critical

    CVE-2026-36500

    Last Modified: 8 Jun 2026

    An issue in the cluster-admin:backup-datastore component of Controller v12.0.5 allows attackers to execute a directory traversal via a crafted request.

    Published: 5 Jun 2026
    7
    High

    CVE-2026-50265

    Last Modified: 8 Jun 2026

    This CVE ID was assigned as a duplicate of CVE-2026-50292

    Published: 5 Jun 2026
    7.5
    High

    CVE-2026-36785

    Last Modified: 8 Jun 2026

    Shenzhen Tenda Technology Co., Ltd Tenda FH451 V1.0.0.9 was discovered to contain a stack overflow in the page parameter of the fromDhcpListClient function. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted HTTP request.

    Published: 5 Jun 2026
    6.5
    Medium

    CVE-2026-37737

    Last Modified: 7 Jun 2026

    sanic-cors version 2.2.0 and prior contains an improper regular expression in the try_match() function in sanic_cors/core.py that uses re.match without end-anchoring. This allows an attacker to bypass CORS origin allowlists by registering a domain that begins with a trusted origin string, to gain unauthorized access to cross-origin requests for authenticated resources.

    Published: 5 Jun 2026
    5.3
    Medium

    CVE-2020-25900

    Last Modified: 7 Jun 2026

    HelloTalk through 3.4.1 stores full-precision GPS coordinates even when the user had intended to share only a country or city. Furthermore, these coordinates are placed into a database on the client of other users. (The client side was changed in 2019 to encrypt that database.)

    Published: 5 Jun 2026
    7.5
    High

    CVE-2026-36501

    Last Modified: 9 Jun 2026

    An issue in the Externalizable.readExternal() component of Controller v12.0.5 allows attackers to cause a Denial of Service (DoS) via a crafted input.

    Published: 5 Jun 2026
    6.1
    Medium

    CVE-2026-38579

    Last Modified: 9 Jun 2026

    Multiple reflected Cross-Site Scripting (XSS) vulnerabilities in damasac thaipalliative_lte through version 3.0 allow remote attackers to inject arbitrary web script or HTML via the idFormMain parameter (line 24), the id parameter (lines 25, 75), and the ptid_key parameter (lines 26, 42) in /substudy/ezform.php. User input is echoed into HTML attributes and JavaScript contexts without encoding.

    Published: 5 Jun 2026
    5.3
    Medium

    CVE-2026-50589

    Last Modified: 16 Jun 2026

    In OpenStack Ironic 32 before 37.0.0, an unauthenticated malicious user could submit a crafted JSON string to some endpoints on the API or JSON-RPC service and effect a service crash.

    Published: 4 Jun 2026
    5.5
    Medium

    CVE-2026-10877

    Last Modified: 8 Jun 2026

    A security vulnerability has been detected in SourceCodester Ship Ferry Ticket Reservation System up to 1.0. This impacts an unknown function of the file /admin/login.php of the component Admin Login. Such manipulation of the argument Username leads to sql injection. The attack can be executed remotely. The exploit has been disclosed publicly and may be used.

    Published: 4 Jun 2026
    2.1
    Low

    CVE-2026-10876

    Last Modified: 8 Jun 2026

    A weakness has been identified in SourceCodester Ship Ferry Ticket Reservation System 1.0. This affects an unknown function of the file /admin/. This manipulation of the argument page causes improper authorization. Remote exploitation of the attack is possible. The exploit has been made available to the public and could be used for attacks.

    Published: 4 Jun 2026
    7.2
    High

    CVE-2026-10586

    Last Modified: 12 Jun 2026

    The Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 6.1.3 via the `save_ai_generated_image()` function. This makes it possible for authenticated attackers, with Author-level access and above, to make web requests to arbitrary locations originating from the web application and can be used to query and modify information from internal services.

    Published: 4 Jun 2026
    4.3
    Medium

    CVE-2026-11302

    Last Modified: 8 Jun 2026

    Insufficient policy enforcement in Chrome for iOS in Google Chrome on iOS prior to 149.0.7827.53 allowed a remote attacker to bypass discretionary access control via a crafted HTML page. (Chromium security severity: Low)

    Published: 4 Jun 2026
    5.1
    Medium

    CVE-2026-11276

    Last Modified: 5 Jun 2026

    Inappropriate implementation in Cast in Google Chrome prior to 149.0.7827.53 allowed an attacker on the local network segment to bypass discretionary access control via malicious network traffic. (Chromium security severity: Low)

    Published: 4 Jun 2026
    8.3
    High

    CVE-2026-11256

    Last Modified: 5 Jun 2026

    Integer overflow in GPU in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: Low)

    Published: 4 Jun 2026
    7.5
    High

    CVE-2026-11255

    Last Modified: 5 Jun 2026

    Insufficient validation of untrusted input in Storage Access API in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)

    Published: 4 Jun 2026
    4.3
    Medium

    CVE-2026-11254

    Last Modified: 5 Jun 2026

    Inappropriate implementation in Permissions in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)

    Published: 4 Jun 2026
    4.3
    Medium

    CVE-2026-11253

    Last Modified: 5 Jun 2026

    Inappropriate implementation in Permissions in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)

    Published: 4 Jun 2026
    4.3
    Medium

    CVE-2026-11252

    Last Modified: 5 Jun 2026

    Insufficient policy enforcement in Content Settings in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass discretionary access control via a crafted HTML page. (Chromium security severity: Low)

    Published: 4 Jun 2026
    3.1
    Low

    CVE-2026-11251

    Last Modified: 5 Jun 2026

    Insufficient policy enforcement in Password Manager in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to bypass discretionary access control via a crafted HTML page. (Chromium security severity: Low)

    Published: 4 Jun 2026
    9.6
    Critical

    CVE-2026-11250

    Last Modified: 5 Jun 2026

    Inappropriate implementation in DevTools in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low)

    Published: 4 Jun 2026
    4.7
    Medium

    CVE-2026-11249

    Last Modified: 5 Jun 2026

    Use after free in Network in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to obtain potentially sensitive information from process memory via a crafted HTML page. (Chromium security severity: Low)

    Published: 4 Jun 2026
    8.8
    High

    CVE-2026-11248

    Last Modified: 5 Jun 2026

    Inappropriate implementation in Google Lens in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)

    Published: 4 Jun 2026
    3.1
    Low

    CVE-2026-11247

    Last Modified: 5 Jun 2026

    Insufficient policy enforcement in CustomTabs in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)

    Published: 4 Jun 2026
    5.3
    Medium

    CVE-2026-11246

    Last Modified: 5 Jun 2026

    Insufficient validation of untrusted input in IndexedDB in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to bypass same origin policy via a crafted HTML page. (Chromium security severity: Low)

    Published: 4 Jun 2026
    4.3
    Medium

    CVE-2026-11245

    Last Modified: 5 Jun 2026

    Inappropriate implementation in Payments in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)

    Published: 4 Jun 2026
    3.1
    Low

    CVE-2026-11244

    Last Modified: 5 Jun 2026

    Insufficient validation of untrusted input in WebAuthentication in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to bypass same origin policy via a crafted HTML page. (Chromium security severity: Low)

    Published: 4 Jun 2026
    7.5
    High

    CVE-2026-11242

    Last Modified: 5 Jun 2026

    Insufficient validation of untrusted input in Plugins in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to leak cross-origin data via a crafted HTML page. (Chromium security severity: Low)

    Published: 4 Jun 2026
    8
    High

    CVE-2026-11241

    Last Modified: 5 Jun 2026

    Insufficient validation of untrusted input in Cast in Google Chrome prior to 149.0.7827.53 allowed an attacker on the local network segment to perform privilege escalation via a crafted HTML page. (Chromium security severity: Low)

    Published: 4 Jun 2026
    3.1
    Low

    CVE-2026-11240

    Last Modified: 5 Jun 2026

    Insufficient validation of untrusted input in Loader in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Low)

    Published: 4 Jun 2026
    7.5
    High

    CVE-2026-11239

    Last Modified: 5 Jun 2026

    Inappropriate implementation in Extensions in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to perform privilege escalation via a crafted HTML page. (Chromium security severity: Low)

    Published: 4 Jun 2026
    5.9
    Medium

    CVE-2026-11238

    Last Modified: 5 Jun 2026

    Inappropriate implementation in DevTools in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malicious extension to obtain potentially sensitive information from process memory via a crafted Chrome Extension. (Chromium security severity: Low)

    Published: 4 Jun 2026
    6.5
    Medium

    CVE-2026-11226

    Last Modified: 6 Jun 2026

    Insufficient policy enforcement in PreviewTab in Google Chrome on Android prior to 149.0.7827.53 allowed a remote attacker who convinced a user to engage in specific UI gestures to bypass same origin policy via a crafted HTML page. (Chromium security severity: Low)

    Published: 4 Jun 2026
    6.5
    Medium

    CVE-2026-11225

    Last Modified: 6 Jun 2026

    Inappropriate implementation in WebUI in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform domain spoofing via a crafted domain name. (Chromium security severity: Low)

    Published: 4 Jun 2026
    6.5
    Medium

    CVE-2026-11223

    Last Modified: 5 Jun 2026

    Insufficient validation of untrusted input in Network in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to bypass same origin policy via a crafted HTML page. (Chromium security severity: Low)

    Published: 4 Jun 2026
    6.5
    Medium

    CVE-2026-11222

    Last Modified: 5 Jun 2026

    Incorrect security UI in Tab Strip in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform domain spoofing via a crafted HTML page. (Chromium security severity: Low)

    Published: 4 Jun 2026
    4.3
    Medium

    CVE-2026-11221

    Last Modified: 5 Jun 2026

    Insufficient validation of untrusted input in PointerLock in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTML page. (Chromium security severity: Low)

    Published: 4 Jun 2026
    6.5
    Medium

    CVE-2026-11220

    Last Modified: 5 Jun 2026

    Insufficient validation of untrusted input in Navigation in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML page. (Chromium security severity: Low)

    Published: 4 Jun 2026
    4.3
    Medium

    CVE-2026-11219

    Last Modified: 5 Jun 2026

    Inappropriate implementation in Navigation in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to bypass navigation restrictions via a crafted HTML page. (Chromium security severity: Low)

    Published: 4 Jun 2026