CVE-2026-56450 Medium 5.1

AIL did not restrict repeated failed attempts to verify a two-factor authentication (OTP) code. An attacker who had reached the 2FA verification step, such

22 Jun 2026, 13:02 UTC View advisory →
CVE-2026-56448 High 8.3

A path traversal vulnerability exists in AIL Framework before the release containing commit 0041456af25da0cdea1c1c4624e46baff2731d8f. An authenticated AIL

22 Jun 2026, 12:54 UTC View advisory →
CVE-2026-56447 Critical 9.3

MISP allowed an authenticated site administrator to set the Kafka_rdkafka_config setting to an arbitrary filesystem path. MISP subsequently parsed the refe

22 Jun 2026, 12:39 UTC View advisory →
CVE-2026-56446 High 8.7

MISP allowed a site administrator to configure an arbitrary filesystem path for the NDJSON error log used by JsonLogTool. Because log entries can include a

22 Jun 2026, 12:31 UTC View advisory →
CVE-2026-56425 Critical 9.3

The Azure Active Directory (AAD) authentication implementation contained multiple weaknesses in its OAuth 2.0 authorization flow that could allow attackers

22 Jun 2026, 12:25 UTC View advisory →
CVE-2026-56424 High 7.1

MISP core contained multiple broken access-control flaws where authorization checks were performed against the wrong entity, or where ownership/editability

22 Jun 2026, 12:17 UTC View advisory →
CVE-2026-56423 Critical 9.4

MISP Core contained broken access-control checks in the bulk deletion flows for Event Reports and Sharing Groups. The affected deleteSelection handlers aut

22 Jun 2026, 11:56 UTC View advisory →
CVE-2026-56422 Critical 9.4

Multiple MISP core controllers and model capture paths accepted client-controlled request fields such as primary keys (id) and ownership/scope foreign keys

22 Jun 2026, 11:43 UTC View advisory →
CVE-2026-56412 Medium 4.9

libexpat before 2.8.2 does not consider XML_TOK_DATA_CHARS in doCdataSection and thus lacks handler call depth tracking for various calls from within handl

21 Jun 2026, 15:58 UTC View advisory →
CVE-2026-56411 Medium 6.9

xmlwf in libexpat before 2.8.2 has an integer overflow in endDoctypeDecl via NOTATION declarations.

21 Jun 2026, 15:56 UTC View advisory →
CVE-2026-56410 Medium 6.9

xmlwf in libexpat before 2.8.2 has an integer overflow in resolveSystemId.

21 Jun 2026, 15:55 UTC View advisory →
CVE-2026-56409 Medium 6.5

xmlwf in libexpat before 2.8.2 has an integer overflow for the output filename when -d outputDir is used.

21 Jun 2026, 15:52 UTC View advisory →
CVE-2026-56408 Medium 6.9

libexpat before 2.8.2 has an integer overflow in copyString.

21 Jun 2026, 15:51 UTC View advisory →
CVE-2026-56407 Medium 6.9

libexpat before 2.8.2 has an integer overflow in doProlog that is related to storeEntityValue and entity textLen.

21 Jun 2026, 15:49 UTC View advisory →
CVE-2026-56406 Medium 6.9

libexpat before 2.8.2 has an integer overflow in XML_ParseBuffer because it lacked a check that was present in XML_Parse.

21 Jun 2026, 15:48 UTC View advisory →
CVE-2026-56405 Medium 6.9

libexpat before 2.8.2 has an integer overflow in getAttributeId.

21 Jun 2026, 15:47 UTC View advisory →
CVE-2026-56404 Medium 6.9

libexpat before 2.8.2 has an integer overflow in addBinding.

21 Jun 2026, 15:45 UTC View advisory →
CVE-2026-56403 Medium 6.9

libexpat before 2.8.2 has an integer overflow in storeAtts.

21 Jun 2026, 15:43 UTC View advisory →
CVE-2026-54665 Medium 6.3

Apache NiFi 0.0.1 through 2.9.0 support building qualified URLs from one of several HTTP request headers that provide an alternative to the standard Host h

22 Jun 2026, 07:34 UTC View advisory →
CVE-2026-54100 High 8.3

A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. WMCO establishes SSH connections to Windows worker

22 Jun 2026, 12:46 UTC View advisory →
CVE-2026-54099 High 8.8

A flaw was found in the Windows Machine Config Operator (WMCO) for Red Hat OpenShift Container Platform. The WICD CSR auto-approver validates that a Certif

22 Jun 2026, 12:46 UTC View advisory →
CVE-2026-44914 High 7.5

Apache NiFi 1.12.0 through 2.9.0 are missing authorization when replacing Process Groups that include extension components with specific Required Permissio

22 Jun 2026, 07:38 UTC View advisory →
CVE-2026-44913 Medium 5.2

Improper escaping of database table names in the CaptureChangeMySQL Processor included with Apache NiFi 1.2.0 through 2.9.0 allows for injecting SQL comman

22 Jun 2026, 07:36 UTC View advisory →
CVE-2026-44911 Low 2.3

Authorization handling for component configuration verification requests in Apache NiFi 1.15.0 through 2.9.0 allows clients with read access to submit prop

22 Jun 2026, 07:37 UTC View advisory →
CVE-2026-42129 High 7.7

The Loki datasource plugin's callResource handler contains a path traversal vulnerability. An authenticated Viewer-role user can escape the plugin's resour

22 Jun 2026, 13:18 UTC View advisory →
CVE-2026-28381 Critical 9.6

The Snowflake datasource allows for GET/PUT commands, which can allow any user with access to run queries against the data source to read/write files betwe

22 Jun 2026, 13:20 UTC View advisory →
CVE-2026-12888 Low 2

An HTML injection vulnerability exists in the Google Chat webhook notification sent by Thinkst Applied Research Canarytokens, enabling Interface Manipulati

22 Jun 2026, 13:05 UTC View advisory →
CVE-2026-12863 Medium 5.1

An unvalidated redirect was contained in Venueless' social login functionality and could be exploited for phishing using trusted domains.

22 Jun 2026, 08:41 UTC View advisory →
CVE-2026-12862 Medium 5.1

Untrusted user data was passed verbatim to Excel exports for administrators. This allowed formula injection which can be used to compromise the environment

22 Jun 2026, 08:26 UTC View advisory →
CVE-2026-12845 Unscored

** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this candidate have be

22 Jun 2026 View advisory →
CVE-2026-12823 Medium 4.8

A security flaw has been discovered in Browserbase up to 20260526. This impacts an unknown function of the component Autobrowse Trace Artifact Handler. The

21 Jun 2026, 23:45 UTC View advisory →
CVE-2026-12822 Medium 4.8

A vulnerability was identified in langflow-ai langflow up to 1.9.3. This affects an unknown function of the component Bundle URL Loader. The manipulation l

21 Jun 2026, 23:30 UTC View advisory →
CVE-2026-12821 Medium 5.3

A vulnerability was determined in FlowiseAI Flowise up to 3.1.2. The impacted element is an unknown function of the file packages/components/nodes/document

21 Jun 2026, 23:15 UTC View advisory →
CVE-2026-12815 Medium 5.3

A vulnerability has been found in coollabsio coolify 4.0.0. Impacted is an unknown function of the component Image Name Handler. Such manipulation leads to

21 Jun 2026, 23:00 UTC View advisory →
CVE-2026-12814 Medium 5.3

A flaw has been found in Comfast CF-WR631AX V3 up to 2.7.0.8. This issue affects the function system of the file /cgi-bin/mbox-config?section=ping_config o

21 Jun 2026, 22:45 UTC View advisory →
CVE-2026-12813 Medium 5.3

A vulnerability was detected in activepieces up to 0.83.0. This vulnerability affects the function handleUrlFile in the library packages/server/engine/src/

21 Jun 2026, 22:30 UTC View advisory →
CVE-2026-12812 Medium 5.1

A security vulnerability has been detected in Radware Cyber Controller up to 10.11.0. This affects an unknown part of the component HTML Report Generation.

21 Jun 2026, 22:15 UTC View advisory →
CVE-2026-12811 Medium 5.3

A weakness has been identified in kortix-ai suna up to 0.8.38. Affected by this issue is the function router.replace/router.push of the file apps/frontend/

21 Jun 2026, 22:00 UTC View advisory →
CVE-2026-12810 Medium 5.3

A security flaw has been discovered in Edimax BR-6478AC V2 1.23. Affected by this vulnerability is the function mp of the file /goform/mp of the component

21 Jun 2026, 21:45 UTC View advisory →
CVE-2026-12809 Medium 5.3

A vulnerability was identified in Edimax BR-6478AC V2 1.23. Affected is the function wiz_5in1_redirect of the file /goform/wiz_5in1_redirect of the compone

21 Jun 2026, 21:30 UTC View advisory →
CVE-2026-12808 Medium 5.3

A vulnerability was determined in Edimax BR-6478AC V2 1.23. This impacts the function stainfo of the file /goform/stainfo of the component POST Request Han

21 Jun 2026, 20:45 UTC View advisory →
CVE-2026-12807 Medium 5.3

A vulnerability was found in Edimax BR-6478AC V2 1.23. This affects the function setWAN of the file /goform/setWAN of the component POST Request Handler. T

21 Jun 2026, 19:45 UTC View advisory →
CVE-2026-12806 High 8.7

A vulnerability has been found in Edimax BR-6478AC V2 1.23. The impacted element is the function formWlSiteSurvey of the file /goform/formWlSiteSurvey of t

21 Jun 2026, 19:30 UTC View advisory →
CVE-2026-12805 Medium 5.3

A flaw has been found in OFFIS DCMTK up to 3.7.0. The affected element is the function XMLNode::parseFile in the library ofstd/libsrc/ofxml.cc. Executing a

21 Jun 2026, 19:15 UTC View advisory →
CVE-2026-12804 Medium 5.3

A vulnerability was detected in lemonldap-ng up to 2.23.0. Impacted is an unknown function in the library lemonldap-ng-portal/lib/Lemonldap/NG/Portal/CDC.p

21 Jun 2026, 18:30 UTC View advisory →
CVE-2026-12602 High 8.8

Incorrect default permissions in ArubaSign, affecting versions prior to v4.6.6. The vulnerability is caused by the assignment of inappropriate permissions

22 Jun 2026, 12:34 UTC View advisory →
CVE-2026-12581 High 7.7

EasyFlow .NET developed by Digiwin has a Session Fixation vulnerability. If unauthenticated remote attackers replace a specific session ID for a user, they

22 Jun 2026, 09:30 UTC View advisory →
CVE-2026-12580 Medium 5.1

EasyFlow .NET developed by Digiwin has a Stored Cross-Site Scripting vulnerability, allowing authenticated remote attackers to inject persistent JavaScript

22 Jun 2026, 09:26 UTC View advisory →
CVE-2026-11748 Medium 6.9

A vulnerability has been identified in centraldogma-server-auth-shiro versions prior to 0.84.0, where the SearchFirstActiveDirectoryRealm substitutes the l

22 Jun 2026, 02:37 UTC View advisory →
CVE-2026-11746 Critical 9.4

A vulnerability has been identified in centraldogma-server versions prior to 0.84.0, where enabling ZooKeeper replication without setting replication.secre

22 Jun 2026, 02:35 UTC View advisory →
CVE-2026-11745 High 8.8

A vulnerability has been identified in centraldogma-server-mirror-git versions prior to 0.84.0, where the Git mirror SSH client does not verify remote host

22 Jun 2026, 02:33 UTC View advisory →
CVE-2026-11373 Unscored

Net::Statsite::Client versions through 1.1.0 for Perl allow metric injections. Net::Statsite::Client is a client for the statsite protocol, which is a vari

22 Jun 2026, 11:28 UTC View advisory →
CVE-2026-10601 Medium 5.4

The Tempo and Loki datasource plugins construct backend HTTP requests by interpolating user-supplied input into URL paths without sanitization, enabling pa

22 Jun 2026, 13:18 UTC View advisory →
CVE-2026-10561 Critical 10

IBM Langflow OSS 1.0.0 through 1.9.3 has an vulnerability due to an improper isolation of Python execution combined with an authentication bypass that allo

22 Jun 2026, 13:22 UTC View advisory →
CVE-2026-10530 Unscored

The Pie Register WordPress plugin before 3.8.4.10 does not use sufficiently random values when generating its account verification tokens, allowing unauthe

22 Jun 2026, 06:00 UTC View advisory →
CVE-2026-9162 Medium 4.3

Mattermost versions 11.7.x <= 11.7.0, 11.6.x <= 11.6.2, 11.5.x <= 11.5.5, 10.11.x <= 10.11.17 fail to invalidate cached authentication state for active Web

22 Jun 2026, 13:36 UTC View advisory →
CVE-2026-9029 High 7.3

The geomap panel's XYZ tile layer has a sanitize-then-interpolate ordering bug. sanitizeTextPanelContent() runs on the raw template string before getTempla

22 Jun 2026, 13:18 UTC View advisory →
CVE-2026-8918 High 7.1

A permissive list of allowed inputs in ASUS Armoury Crate allows a local administrator to perform arbitrary memory read/write operations or cause a system

22 Jun 2026, 02:00 UTC View advisory →
CVE-2026-8157 High 8.8

The Vitepos WordPress plugin before 3.4.2 does not properly restrict the roles that can be assigned when creating new users via one of its REST API endpoin

22 Jun 2026, 06:00 UTC View advisory →
CVE-2026-8074 Low 3.8

Mattermost versions 11.7.x <= 11.7.0, 10.11.x <= 10.11.17 fail to enforce bot-specific permission checks on the user active status endpoint, which allows a

22 Jun 2026, 13:37 UTC View advisory →
CVE-2026-7859 Medium 5.3

The Motors WordPress plugin before 1.4.110 does not have proper authorisation and CSRF checks on one of its AJAX actions, allowing unauthenticated attacker

22 Jun 2026, 06:00 UTC View advisory →
CVE-2026-7167 Medium 6.9

The vulnerability arises when the system fails to properly validate the 'email' field during the authentication process, allowing unverified or fake email

22 Jun 2026, 12:50 UTC View advisory →
CVE-2026-7166 Critical 9.2

Vulnerability involving the exposure of sensitive data provided without adequate protection. The API exposes email and phone number data from the ‘email’ a

22 Jun 2026, 12:47 UTC View advisory →
CVE-2026-7165 Critical 9.4

The vulnerability is present in the ‘/addJugador’ endpoint: * The 'keyJugador' and 'keyJugadorObjectiu' parameters allow the modification of other users’ i

22 Jun 2026, 12:46 UTC View advisory →
CVE-2026-6858 High 7.1

The Transbank Webpay WordPress plugin before 1.14.0 does not sanitize and escape logs to be displayed, allowing unauthenticated users to perform Stored XSS

22 Jun 2026, 06:00 UTC View advisory →
CVE-2026-6673 Medium 6.4

Mattermost versions 11.7.x <= 11.7.0, 11.6.x <= 11.6.2, 11.5.x <= 11.5.5, 10.11.x <= 10.11.17 fail to authenticate Atlassian Connect installed callbacks, a

22 Jun 2026, 13:38 UTC View advisory →
CVE-2026-6653 High 7

Use After Free in libxml2's xmlParseInternalSubset from GNOME libxml2 version 2.9.11 to 2.11.0 allows a remote attacker to cause a denial-of-service via ma

22 Jun 2026, 12:40 UTC View advisory →
CVE-2026-6645 High 7.3

An insecure process execution vulnerability exists in the pc-printer-updater.exe component of the PaperCut Print Deploy Client for Windows. The application

22 Jun 2026, 03:24 UTC View advisory →
CVE-2026-6062 Medium 6.4

Mattermost versions 11.7.x <= 11.7.0, 11.6.x <= 11.6.2, 11.5.x <= 11.5.5, 10.11.x <= 10.11.17 Fail to validate channel ownership of an existing subscriptio

22 Jun 2026, 13:40 UTC View advisory →
CVE-2026-5139 Medium 5.4

Mattermost versions 11.7.x <= 11.7.0, 11.6.x <= 11.6.2, 11.5.x <= 11.5.5, 10.11.x <= 10.11.17 fail to enforce administrator authorization on the {{setDefau

22 Jun 2026, 13:34 UTC View advisory →
CVE-2026-4259 High 7.1

The ultimate-woocommerce-auction-pro WordPress plugin through 2.4.5 does not sanitise and escape a parameter before outputting it back in the page, leading

22 Jun 2026, 06:00 UTC View advisory →
CVE-2026-4110 Unscored

The ultimate-woocommerce-auction-pro WordPress plugin through 2.4.5 does not sanitise and escape a parameter before outputting it back in the page, leading

22 Jun 2026, 06:00 UTC View advisory →
CVE-2025-66389 Unscored

GitHub Copilot 1.372.0 allows filesystem access outside of a workspace folder (without user approval) via a file-handler URI parameter to fetch_webpage. Th

22 Jun 2026, 00:00 UTC View advisory →
CVE-2025-66336 Unscored

Apache Doris MCP Server contains a SQL injection vulnerability in a metadata query path. A user-controlled database name is directly interpolated into a SQ

22 Jun 2026, 06:55 UTC View advisory →
CVE-2025-62198 Unscored

An authenticated user can perform XSS. This issue affects Apache Atlas versions 2.4.0 and earlier. Users are recommended to upgrade to version 2.5.0, which

22 Jun 2026, 07:47 UTC View advisory →
CVE-2025-33128 Medium 5.4

IBM Engineering Workflow Management 7.0.3 through 7.0.3 Interim Fix 020, and 7.1 through 7.1 Interim Fix 007 is vulnerable to cross-site scripting. This vu

22 Jun 2026, 13:20 UTC View advisory →
CVE-2025-4994 High 8.7

The SafeLine SL6 and SL6+ devices integrated into elevator emergency intercom systems are vulnerable to an authentication bypass. This vulnerability allows

22 Jun 2026, 08:10 UTC View advisory →
CVE-2025-2669 Medium 6

IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data versions 4.8, 5.0, 5.1, 5.2, 5.3 could allow a privileged user to perform operations

22 Jun 2026, 13:18 UTC View advisory →
CVE-2024-54178 Medium 6.5

IBM Db2 on Cloud Pak for Data and Db2 Warehouse on Cloud Pak for Data versions 4.8,5.0,5.1,5.2,5.3 could allow an authenticated user to cause a denial of s

22 Jun 2026, 13:15 UTC View advisory →
CVE-2023-45796 High 8.1

A stored cross-site scripting vulnerability in the Runtime component of Pilz PASvisu before 1.14.1 and PMI v8xx up to and including 2.0.33992 allows a low-

22 Jun 2026, 09:04 UTC View advisory →
CVE-2023-45795 High 7.8

A cross-site scripting vulnerability in the Builder Component of Pilz PASvisu before 1.14.1 allows a local unauthenticated attacker to inject malicious jav

22 Jun 2026, 09:06 UTC View advisory →