Vulnerabilities
Vulnerable Software
Security Vulnerabilities
Improper access control in the PAM account discovery feature in Devolutions Server 2026.1.19 and earlier allows an authenticated user without administrative privileges to delete network discovery scan configurations.
CVSS Score
5.4
EPSS Score
0.0
Published
2026-06-02
Improper access control in the permission validation component in Devolutions Server 2026.1.19 and earlier allows an authenticated user with entry edit privileges to modify asset information without the required permission.
CVSS Score
5.3
EPSS Score
0.0
Published
2026-06-02
An improper authorization vulnerability has been identified in Apache Kafka. The implementation of the CONSUMER_GROUP_DESCRIBE (69) API validates the DESCRIBE operation on the GROUP resource instead of the READ operation that documented in the official kafka documentation and the KIP-848. This discrepancy can result in misconfigured Access Control Lists (ACLs) and unintended security postures, like granting READ permission to users who should not be able to join/sync groups, or allowing users without READ permission (but with DESCRIBE permission) to access sensitive group metadata. The correct permission for CONSUMER_GROUP_DESCRIBE API is DESCRIBE GROUP so the current implementation is correct. However, the kafka documentation as well as the KIP-848 will be updated to reflect the correct permission. We advise the Kafka users to review existing group ACLs to ensure the principle of least privilege.
CVSS Score
4.3
EPSS Score
0.001
Published
2026-06-02
Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Apache Calcite. This issue affects Apache Calcite: from 1.5.0 before 1.42. Users are recommended to upgrade to version 1.42, which fixes the issue.
CVSS Score
6.5
EPSS Score
0.002
Published
2026-06-02
Kiteworks is a private data network (PDN). Prior to version 9.3.0,ultiple SQL Injection vulnerabilities in Kiteworks Secure Data Forms could be exploited by an authenticated attacker with the FormBuilder role to retrieve information on or modify other users' form definitions and some global configuration parameters. Upgrade Kiteworks to version 9.3.0 or later to receive a patch.
CVSS Score
7.6
EPSS Score
0.0
Published
2026-06-01
Memory corruption while processing IOCTL calls for escape operations.
CVSS Score
7.8
EPSS Score
0.0
Published
2026-06-01
Memory corruption while processing multiple IOCTL command for escape operations.
CVSS Score
7.8
EPSS Score
0.0
Published
2026-06-01
Memory Corruption when accessing shared buffers without validation of concurrent user-mode input modifications.
CVSS Score
7.8
EPSS Score
0.0
Published
2026-06-01
Memory corruption while using Strongbox due to missing bounds check.
CVSS Score
8.8
EPSS Score
0.0
Published
2026-06-01
Memory corruption while using Strongbox due to buffer overflow.
CVSS Score
8.8
EPSS Score
0.0
Published
2026-06-01


Contact Us

Shodan ® - All rights reserved