Common Vulnerabilities and Exposures (CVE)

CVE-2020-18169

Jun 10, 2026 15:40:35 UTC

A vulnerability in the Windows installer XML (WiX) toolset of TechSmith Snagit 19.1.1.2860 allows attackers to escalate privileges. NOTE: Exploit of the Snagit installer would require the end user to ignore other safety mechanisms provided ...

CVE-2026-45569

Jun 10, 2026 15:38:17 UTC

Roxy-WI is a web interface for managing Haproxy, Nginx, Apache and Keepalived servers. In versions 8.2.6.4 and prior, ommit d4d10006 ("Expand validation to block .. in config_file_name and configver for improved security") added a line in a...

CVE-2026-26237

Jun 10, 2026 15:37:12 UTC

A missing authorization vulnerability has been reported to affect QuMagie. The remote attackers can then exploit the vulnerability to access unauthorized data or perform unauthorized actions. We have already fixed the vulnerability in the ...

CVE-2026-53436

Jun 10, 2026 15:36:40 UTC

Jenkins 2.567 and earlier, LTS 2.555.2 and earlier improperly determines that a redirect URL after login is legitimately pointing to Jenkins when it contains relative path segments (`./` or `../`), allowing attackers to perform phishing att...

CVE-2026-38360

Jun 10, 2026 15:34:05 UTC

Directory Traversal vulnerability in fohrloop dash-uploader v.0.1.0 through v.0.7.0a2 allows a remote attacker to execute arbitrary code via the dash_uploader/httprequesthandler.py, BaseHttpRequestHandler.get_temp_root(), BaseHttpRequestHan...

CVE-2026-0416

Jun 10, 2026 15:33:32 UTC

Authenticated administrators connected to the local network can modify router functionality beyond what is intended through the standard management interface.

CVE-2026-53439

Jun 10, 2026 15:33:30 UTC

Missing permission checks in Jenkins 2.567 and earlier, LTS 2.555.2 and earlier allow attackers with Overall/Read permission to determine other users' configured timezone and to enumerate view names of other users' "My Views".

CVE-2026-4480

Jun 10, 2026 15:32:05 UTC

A flaw was found in the Samba printing subsystem. Samba passes the client-controlled job description string to the command configured with the "print command" setting via the "%J" substitution character without escaping shell meta character...

CVE-2026-53438

Jun 10, 2026 15:32:02 UTC

A missing permission check in Jenkins 2.567 and earlier, LTS 2.555.2 and earlier allows attackers with Item/Cancel permission, but lacking Item/Read permission, to cancel queue items they do not have permission to view.

CVE-2026-4408

Jun 10, 2026 15:31:57 UTC

A flaw was found in Samba. A remote attacker can exploit a misconfiguration in Samba file servers and classic domain controllers that use the "check password script" feature. If this script is configured with the %u substitution character, ...

CVE-2026-3012

Jun 10, 2026 15:31:47 UTC

A flaw was found in Samba’s certificate auto-enrollment Group Policy handling. When certificate auto-enrollment is enabled, Samba may retrieve a CA certificate over an unencrypted HTTP connection and install it into the local trust store wi...

CVE-2026-1933

Jun 10, 2026 15:31:37 UTC

A flaw was found in Samba’s handling of NTFS-style reparse points on shares configured with read only = yes. Due to missing SMB-layer access checks, authenticated users with underlying filesystem write permissions may create or delete repar...

CVE-2026-0412

Jun 10, 2026 15:30:26 UTC

Insufficient input validation vulnerability in NETGEAR JR6150 (AC750 WiFi Router 802.11ac Dual Band Gigabit released in 2014) allows administrators connected to the local network to make unauthorized modification of router software and func...

CVE-2026-38361

Jun 10, 2026 15:28:24 UTC

Multiple unauthenticated denial-of-service (DoS) issues in fohrloop dash-uploader v0.1.0 through v0.7.0a2. The chunked-upload handler (dash_uploader/httprequesthandler.py, dash_uploader/upload.py) trusts unsanitized, attacker-controlled upl...

CVE-2026-0410

Jun 10, 2026 15:24:02 UTC

Authenticated administrators connected to the local network can gain elevated access to the router and make unauthorized changes to router software and functionality.