2026-06-12
2026-06-12 04:17Z
CRIT

CVE-2026-47369 — A malicious actor with access to the network and low privileges could exploit an

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47369

A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in certain devices running UniFi OS to escalate privileges within such UniFi OS devices or instances. CVSSv3.1 9.9 (CRITICAL)

CWECWE 20TYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-06-12
2026-06-12 04:17Z
HIGH

CVE-2026-47368 — A malicious actor with access to the network could exploit a Path Traversal vulnerability

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47368

A malicious actor with access to the network could exploit a Path Traversal vulnerability found in certain devices running UniFi OS to obtain data from such UniFi OS devices or instances. CVSSv3.1 8.6 (HIGH)

CWECWE 22TYPVulnerability
8.6
CVSS v3.1
93
Edit Score
2026-06-12
2026-06-12 04:17Z
CRIT

CVE-2026-47367 — A malicious actor with access to the network and low privileges could exploit an

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47367

A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UID Enterprise Agent to execute a Command Injection on the host device. CVSSv3.1 9.9 (CRITICAL)

CWECWE 20TYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-06-12
2026-06-12 04:17Z
CRIT

CVE-2026-47365 — Argument: injection vulnerability in WordPress Toolkit before 6.11.0 as used in cPanel & WHM

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-47365

Argument injection vulnerability in WordPress Toolkit before 6.11.0 as used in cPanel & WHM, allows remote authenticated users to bypass cross-tenant authorization and execute arbitrary wp-toolkit CLI commands as another account. CVSSv3.1 9.9 (CRITICAL)

CWECWE 88VNDArgumentTYPVulnerability
9.9
CVSS v3.1
100
Edit Score
2026-06-12
2026-06-12 02:16Z
HIGH

CVE-2026-45170 — Paloaltonetworks Idira_privilege_cloud_connector: Idira Vendor PAM - Self-Hosted Connector versions prior 1.1.100504 under specific conditions and configuration

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45170

Idira Vendor PAM - Self-Hosted Connector versions prior 1.1.100504 under specific conditions and configuration scenarios, TLS certificate validation may not be fully enforced. CyberArk Security Bulletin: CA26-17 CVSSv3.1 8.8 (HIGH) · EPSS 0th percentile

CWECWE 295VNDPaloaltonetworksVNDIdiraTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-12
2026-06-12 02:16Z
HIGH

CVE-2026-11933 — A use-after-free vulnerability exists in MongoDB Server's server-side JavaScript engine when converting BSON documents

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-11933

A use-after-free vulnerability exists in MongoDB Server's server-side JavaScript engine when converting BSON documents to JavaScript arrays. An authenticated user with read privileges who is able to run server-side JavaScript (for example, via $where or $function) can cause the server to access memory that has already been freed. This may result in disclosure of information from the mongod process memory or a denial of service through a server crash. CVSSv3.1 8.8 (HIGH)

CWECWE 787TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-11
2026-06-11 23:16Z
HIGH

CVE-2026-45418 — ClipBucket: The POST /actions/subtitle_edit.php request used to change their title includes a number parameter which

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45418

ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 - #132, any authenticated user who can upload videos can add multiple subtitles from different files and change their title (English, Spanish...). The POST /actions/subtitle_edit.php request used to change their title includes a number parameter which is vulnerable to SQL Injection. A boolean-based blind SQL injection can be used to exfiltrate sensitive data. This issue has been patched in version CVSSv3.1 8.8 (HIGH)

CWECWE 89VNDClipbucketTYPVulnerability
8.8
CVSS v3.1
94
Edit Score
728 × 90 / responsive · programmatic ad slot
2026-06-11
2026-06-11 23:16Z
CRIT

CVE-2026-45060 — ClipBucket: Prior to version 5.5.3 - #129, the actions/progress_video.php endpoint is vulnerable to blind SQL

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-45060

ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 - #129, the actions/progress_video.php endpoint is vulnerable to blind SQL injection. Any unauthenticated user can exploit the ids parameter to execute SQL queries and exfiltrate sensitive data. This issue has been patched in version 5.5.3 - #129. CVSSv3.1 9.8 (CRITICAL)

CWECWE 89VNDClipbucketTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-11
2026-06-11 23:16Z
CRIT

CVE-2026-42846 — ClipBucket: Prior to version 5.5.3 - #140, ClipBucket's Remote Play feature allows any authenticated user

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-42846

ClipBucket v5 is an open source video sharing platform. Prior to version 5.5.3 - #140, ClipBucket's Remote Play feature allows any authenticated user to add a video by importing an external URL as the source. Some shell commands are run with the URL as a parameter. The URL is concatenated directly into shell commands without escaping then executed, so any shell metacharacter in the URL is interpreted. This results in arbitrary command execution. This issue has been patched in CVSSv3.1 9.8 (CRITICAL)

CWECWE 78VNDClipbucketTYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-11
2026-06-11 22:16Z
HIGH

CVE-2026-6250 — Tp-link Tapo_c110_firmware: A remote authenticated attacker may redirect execution flow to existing internal functions, triggering an

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-6250

An authenticated format string vulnerability exists in the ONVIF service of Tapo C110 v2 due to improper handling of user-controlled input.  Externally controlled data is interpreted as a format string, which can be used to manipulate stack memory, including control flow data such as return addresses. A remote authenticated attacker may redirect execution flow to existing internal functions, triggering an unauthorized factory reset, leading to loss of configuration, dele CVSSv3.1 8.1 (HIGH) · EPSS 11th percentile

CWECWE 134VNDTp LinkTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-11
2026-06-11 22:16Z
CRIT

CVE-2026-49060 — Incorrect: Privilege Assignment vulnerability in Hippoo Mobile App for WooCommerce allows Privilege Escalation.

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-49060

Incorrect Privilege Assignment vulnerability in Hippoo Mobile App for WooCommerce allows Privilege Escalation. This issue affects Hippoo Mobile App for WooCommerce: from n/a through 1.9.4. CVSSv3.1 9.8 (CRITICAL)

CWECWE 266TYPVulnerability
9.8
CVSS v3.1
99
Edit Score
2026-06-11
2026-06-11 22:16Z
HIGH

CVE-2026-44249 — Netty: In netty-handler prior to versions 4.1.135.Final and 4.2.15.Final, an attacker can bypass IPv6 subnet

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-44249

Netty is a network application framework for development of protocol servers and clients. In netty-handler prior to versions 4.1.135.Final and 4.2.15.Final, an attacker can bypass IPv6 subnet rules due to an incorrect masking operation in IpSubnetFilterRule.compareTo(). Valid public IP addresses can bypass the restrictions. Versions 4.1.135.Final and 4.2.15.Final patch the issue. CVSSv3.1 8.1 (HIGH)

CWECWE 284CWECWE 697VNDNettyTYPVulnerability
8.1
CVSS v3.1
91
Edit Score
2026-06-11
2026-06-11 22:16Z
CRIT

CVE-2026-42647 — Neutralization: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-42647

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Beardev JoomSport allows Blind SQL Injection. This issue affects JoomSport: from n/a through 5.7.7. CVSSv3.1 9.3 (CRITICAL)

CWECWE 89TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-06-11
2026-06-11 22:16Z
CRIT

CVE-2026-39494 — Neutralization: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-39494

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in WBW Plugins Product Filter by WBW allows Blind SQL Injection. This issue affects Product Filter by WBW: from n/a through 3.1.2. CVSSv3.1 9.3 (CRITICAL)

CWECWE 89TYPVulnerability
9.3
CVSS v3.1
97
Edit Score
2026-06-11
2026-06-11 22:16Z
HIGH

CVE-2026-12035 — Use: after free in Views in Google Chrome on Windows prior to 149.0.7827.115 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12035

Use after free in Views in Google Chrome on Windows prior to 149.0.7827.115 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-11
2026-06-11 22:16Z
HIGH

CVE-2026-12034 — Insufficient validation of untrusted input in Linux Toolkit Theming in Google Chrome on Linux

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12034

Insufficient validation of untrusted input in Linux Toolkit Theming in Google Chrome on Linux prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a malicious file. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)

CWECWE 20TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-06-11
2026-06-11 22:16Z
HIGH

CVE-2026-12031 — Inappropriate: implementation in Views in Google Chrome on Windows prior to 149.0.7827.115 allowed a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12031

Inappropriate implementation in Views in Google Chrome on Windows prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)

CWECWE 693VNDInappropriateTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-06-11
2026-06-11 22:16Z
HIGH

CVE-2026-12030 — Out: of bounds write in GPU in Google Chrome on Android prior to 149.0.7827.115

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12030

Out of bounds write in GPU in Google Chrome on Android prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)

CWECWE 122TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-06-11
2026-06-11 22:16Z
HIGH

CVE-2026-12029 — Use: after free in Video in Google Chrome on Windows prior to 149.0.7827.115 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12029

Use after free in Video in Google Chrome on Windows prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)

CWECWE 416TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-06-11
2026-06-11 22:16Z
HIGH

CVE-2026-12028 — Use: after free in GPU in Google Chrome on Android prior to 149.0.7827.115 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12028

Use after free in GPU in Google Chrome on Android prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)

CWECWE 416TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-06-11
2026-06-11 22:16Z
CRIT

CVE-2026-12027 — Inappropriate: implementation in Headless in Google Chrome prior to 149.0.7827.115 allowed a remote attacker

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12027

Inappropriate implementation in Headless in Google Chrome prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 9.6 (CRITICAL)

CWECWE 693CWECWE 250VNDInappropriateTYPVulnerability
9.6
CVSS v3.1
98
Edit Score
2026-06-11
2026-06-11 22:16Z
HIGH

CVE-2026-12023 — Use: after free in GPU in Google Chrome on Mac prior to 149.0.7827.115 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12023

Use after free in GPU in Google Chrome on Mac prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)

CWECWE 416TYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-06-11
2026-06-11 22:16Z
HIGH

CVE-2026-12022 — Race: in Safe Browsing in Google Chrome on Mac prior to 149.0.7827.115 allowed a

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12022

Race in Safe Browsing in Google Chrome on Mac prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a malicious file. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)

CWECWE 362VNDRaceTYPVulnerability
8.3
CVSS v3.1
92
Edit Score
2026-06-11
2026-06-11 22:16Z
HIGH

CVE-2026-12020 — Use: after free in Autofill in Google Chrome on Mac prior to 149.0.7827.115 allowed

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12020

Use after free in Autofill in Google Chrome on Mac prior to 149.0.7827.115 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.8 (HIGH)

CWECWE 416TYPVulnerability
8.8
CVSS v3.1
94
Edit Score
2026-06-11
2026-06-11 22:16Z
HIGH

CVE-2026-12019 — Heap: buffer overflow in Codecs in Google Chrome on Linux and ChromeOS prior to

NVD (auto-promoted CVEs)·nvd.nist.govCVE-2026-12019

Heap buffer overflow in Codecs in Google Chrome on Linux and ChromeOS prior to 149.0.7827.115 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via a crafted HTML page. (Chromium security severity: High) CVSSv3.1 8.3 (HIGH)

CWECWE 787VNDHeapTYPVulnerability
8.3
CVSS v3.1
92
Edit Score