GreatXML bypasses BitLocker via Defender offline scan artifacts, giving SYSTEM shell in Recovery Mode. No patch exists. Any machine that ran an offline scan is vulnerable. On June 10, security researcher Chaotic Eclipse (aka Nightmare Eclipse) published a new working exploit dubbed GreatXML that bypasses BitLocker and opens a command shell with full SYSTEM privileges […]
A vulnerability was found in Vmware Spring Web Services up to 3.1.8/4.0.18/4.1.3/5.0.1. It has been rated as critical. Affected by this issue is some unknown functionality. The manipulation leads to server-side request forgery.
This vulnerability is traded as CVE-2026-40999. It is possible to initiate the attack remotely. There is no exploit available.
Upgrading the affected component is advised.
A vulnerability categorized as problematic has been discovered in Vmware Spring Web Services up to 3.1.8/4.0.18/4.1.3/5.0.1. This affects an unknown part. The manipulation results in xml external entity reference.
This vulnerability is known as CVE-2026-40998. It is possible to launch the attack remotely. No exploit is available.
It is advisable to upgrade the affected component.
A vulnerability labeled as problematic has been found in Vmware Spring Web Services up to 3.1.8/4.0.18/4.1.3/5.0.1. This issue affects some unknown processing. Such manipulation leads to authentication bypass by capture-replay.
This vulnerability is uniquely identified as CVE-2026-41000. The attack can be launched remotely. No exploit exists.
The affected component should be upgraded.
A vulnerability classified as problematic has been found in Vmware Spring for GraphQL up to 1.3.8/1.4.5/2.0.3. The impacted element is an unknown function. The manipulation leads to deserialization.
This vulnerability is referenced as CVE-2026-41699. Remote exploitation of the attack is possible. No exploit is available.
It is recommended to upgrade the affected component.
A vulnerability, which was classified as problematic, has been found in Vmware Spring Boot up to 2.7.33/3.3.19/3.4.16/3.5.14/4.0.6. This impacts an unknown function. This manipulation causes insecure temporary file.
This vulnerability is tracked as CVE-2026-41001. The attack is restricted to local execution. No exploit exists.
It is advisable to upgrade the affected component.
A vulnerability was found in Red Hat Directory Server and Enterprise Linux. It has been declared as critical. This affects the function read_schema_dse of the component 389 Directory Server. Executing a manipulation can lead to heap-based buffer overflow.
This vulnerability is registered as CVE-2026-11884. It is possible to launch the attack remotely. No exploit is available.
A vulnerability was found in Microsoft .NET. It has been rated as problematic. This vulnerability affects unknown code. This manipulation causes link following.
This vulnerability is handled as CVE-2026-45491. It is possible to launch the attack on the local host. There is not any exploit available.
Upgrading the affected component is advised.
A vulnerability marked as problematic has been reported in Poppler. This issue affects the function tilingPatternFill of the component Splash Backend. The manipulation leads to integer overflow.
This vulnerability is traded as CVE-2026-10118. An attack has to be approached locally. There is no exploit available.
A vulnerability was found in Microsoft .NET SDK. It has been declared as critical. This affects an unknown part. The manipulation results in improper authorization.
This vulnerability is known as CVE-2026-45490. Attacking locally is a requirement. No exploit is available.
It is recommended to upgrade the affected component.
A vulnerability was found in SQLFluff up to 4.1.x. It has been rated as problematic. The impacted element is an unknown function. This manipulation causes resource consumption.
The identification of this vulnerability is CVE-2026-46374. It is possible to initiate the attack remotely. There is no exploit available.
Upgrading the affected component is advised.
A vulnerability was found in Debian debusine up to 0.14.8. It has been declared as critical. Affected is an unknown function of the component Parser. Executing a manipulation can lead to unrestricted upload.
This vulnerability appears as CVE-2026-11853. The attack may be performed from remote. There is no available exploit.
It is recommended to upgrade the affected component.