Vulnerabilities
Vulnerable Software
Security Vulnerabilities
The Route OpenShift resource allows to define routes to make pods reachable at a subdomain through HAProxy. It was found that the checks performed on the spec.path YAML stanza in a Route document was insufficient and could allow a controlled injection of the HAProxy configuration.
CVSS Score
8.8
EPSS Score
0.001
Published
2026-06-02
MLflow 3.9.0 with basic-auth (`--app-name basic-auth`) fails to enforce authorization checks for multiple Gateway API 'list' endpoints. Specifically, the `BEFORE_REQUEST_HANDLERS` dictionary in `mlflow/server/auth/__init__.py` does not include entries for `ListGatewaySecretInfos`, `ListGatewayEndpoints`, and `ListGatewayModelDefinitions`. This allows any authenticated user, regardless of their assigned permissions, to enumerate all gateway secrets, endpoints, and model definitions. This vulnerability exposes sensitive information, such as API keys, endpoint configurations, and proprietary model definitions, to unauthorized users.
CVSS Score
6.5
EPSS Score
0.002
Published
2026-06-02
eLabFTW is an open source electronic lab notebook. Prior to version 5.4.2, in certain cases, an authenticated user performing a numeric reference/search can return results that include resources the requesting user is not authorized to view. The exposed information is limited (only the title). Attempts to access the underlying protected resource content remain blocked by authorization checks. Version 5.4.2 fixes the issue. # Affected Scope Cross-scope visibility of titles. No confirmed bypass of content-level access controls # Preconditions An authenticated user account No special privileges required beyond standard access # Impact This may enable unauthorized disclosure of sensitive information if confidential data is included in resource titles. Examples could include project names, patient identifiers, or other regulated information embedded in titles.
CVSS Score
4.3
EPSS Score
0.002
Published
2026-06-01
Kiteworks is a private data network (PDN). Prior to version 9.3.0,ultiple SQL Injection vulnerabilities in Kiteworks Secure Data Forms could be exploited by an authenticated attacker with the FormBuilder role to retrieve information on or modify other users' form definitions and some global configuration parameters. Upgrade Kiteworks to version 9.3.0 or later to receive a patch.
CVSS Score
7.6
EPSS Score
0.007
Published
2026-06-01
Memory corruption while processing IOCTL calls for escape operations.
CVSS Score
7.8
EPSS Score
0.001
Published
2026-06-01
Memory corruption while processing multiple IOCTL command for escape operations.
CVSS Score
7.8
EPSS Score
0.001
Published
2026-06-01
Memory Corruption when accessing shared buffers without validation of concurrent user-mode input modifications.
CVSS Score
7.8
EPSS Score
0.001
Published
2026-06-01
Memory corruption while using Strongbox due to missing bounds check.
CVSS Score
8.8
EPSS Score
0.001
Published
2026-06-01
Memory corruption while using Strongbox due to buffer overflow.
CVSS Score
8.8
EPSS Score
0.001
Published
2026-06-01
Memory Corruption when processing fastboot commands to set display mode.
CVSS Score
7.2
EPSS Score
0.001
Published
2026-06-01


Contact Us

Shodan ® - All rights reserved