Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
33925
Total
2632
Critical
10022
High
10229
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-36235 | UNKNOWN | — | A SQL injection vulnerability was found in the scheduleSubList.php file of itsourcecode Online Student Enrollment System v1.0. The reason for this issue is that the … | Apr 10, 2026 |
| CVE-2026-36234 | UNKNOWN | — | itsourcecode Online Student Enrollment System v1.0 is vulnerable to SQL Injection in newCourse.php via the 'coursename' parameter. | Apr 10, 2026 |
| CVE-2026-36233 | UNKNOWN | — | A SQL injection vulnerability was found in the assignInstructorSubjects.php file of itsourcecode Online Student Enrollment System v1.0. The reason for this issue is that attackers … | Apr 10, 2026 |
| CVE-2026-36232 | UNKNOWN | — | A SQL injection vulnerability was found in the instructorClasses.php file of itsourcecode Online Student Enrollment System v1.0. The reason for this issue is that the … | Apr 10, 2026 |
| CVE-2026-31262 | UNKNOWN | — | Cross Site Scripting vulnerability in Altenar Sportsbook Software Platform (SB2) v.2.0 allows a remote attacker to obtain sensitive information and execute arbitrary code via the … | Apr 10, 2026 |
| CVE-2026-29861 | UNKNOWN | — | PHP-MYSQL-User-Login-System v1.0 was discovered to contain a SQL injection vulnerability via the username parameter at login.php. | Apr 10, 2026 |
| CVE-2026-23782 | UNKNOWN | — | An issue was discovered in BMC Control-M/MFT 9.0.20 through 9.0.22. An API management endpoint allows unauthenticated users to obtain both an API identifier and its … | Apr 10, 2026 |
| CVE-2026-23780 | UNKNOWN | — | An issue was discovered in BMC Control-M/MFT 9.0.20 through 9.0.22. A SQL injection vulnerability in the MFT API's debug interface allows an authenticated attacker to … | Apr 10, 2026 |
| CVE-2025-44560 | UNKNOWN | — | owntone-server 2ca10d9 is vulnerable to Buffer Overflow due to lack of recursive checking. | Apr 10, 2026 |
| CVE-2026-6069 | HIGH | 7.5 | NASM’s disasm() function contains a stack based buffer overflow when formatting disassembly output, allowing an attacker triggered out-of-bounds write when `slen` exceeds the buffer capacity. | Apr 10, 2026 |
| CVE-2026-6068 | MEDIUM | 6.5 | NASM contains a heap use after free vulnerability in response file (-@) processing where a dangling pointer to freed memory is stored in the global … | Apr 10, 2026 |
| CVE-2026-6067 | HIGH | 7.5 | A heap buffer overflow vulnerability exists in the Netwide Assembler (NASM) due to a lack of bounds checking in the obj_directive() function. This vulnerability can … | Apr 10, 2026 |
| CVE-2026-40217 | HIGH | 8.8 | LiteLLM through 2026-04-08 allows remote attackers to execute arbitrary code via bytecode rewriting at the /guardrails/test_custom_code URI. | Apr 10, 2026 |
| CVE-2026-33092 | HIGH | 7.8 | Local privilege escalation due to improper handling of environment variables. The following products are affected: Acronis True Image OEM (macOS) before build 42571, Acronis True … | Apr 10, 2026 |
| CVE-2025-5804 | HIGH | 7.5 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Case Themes Case Theme User allows PHP Local File … | Apr 10, 2026 |
| CVE-2025-58920 | HIGH | 7.1 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Zootemplate Cerato allows Reflected XSS.This issue affects Cerato: from n/a through 2.2.18. | Apr 10, 2026 |
| CVE-2025-58913 | HIGH | 8.1 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in CactusThemes VideoPro allows PHP Local File Inclusion.This issue affects … | Apr 10, 2026 |
| CVE-2026-5774 | UNKNOWN | — | Improper synchronization of the userTokens map in the API server in Canonical Juju 4.0.5, 3.6.20, and 2.9.56 may allow an authenticated user to possibly cause … | Apr 10, 2026 |
| CVE-2026-5412 | CRITICAL | 9.9 | In Juju versions prior to 2.9.57 and 3.6.21, an authorization issue exists in the Controller facade. An authenticated user can call the CloudSpec API method … | Apr 10, 2026 |
| CVE-2026-5777 | UNKNOWN | — | This vulnerability exists in the Atom 3x Projector due to improper exposure of the Android Debug Bridge (ADB) service over the local network without authentication … | Apr 10, 2026 |
| CVE-2026-39304 | HIGH | 7.5 | Denial of Service via Out of Memory vulnerability in Apache ActiveMQ Client, Apache ActiveMQ Broker, Apache ActiveMQ. ActiveMQ NIO SSL transports do not correctly handle … | Apr 10, 2026 |
| CVE-2026-31412 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: usb: gadget: f_mass_storage: Fix potential integer overflow in check_command_size_in_blocks() The `check_command_size_in_blocks()` function calculates the data … | Apr 10, 2026 |
| CVE-2026-6057 | CRITICAL | 9.8 | FalkorDB Browser 1.9.3 contains an unauthenticated path traversal vulnerability in the file upload API that allows remote attackers to write arbitrary files and achieve remote … | Apr 10, 2026 |
| CVE-2026-4162 | HIGH | 7.1 | The Gravity SMTP plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 2.1.4. This is due to the plugin not … | Apr 10, 2026 |
| CVE-2021-47961 | HIGH | 8.1 | A plaintext storage of a password vulnerability in Synology SSL VPN Client before 1.4.5-0684 allows remote attackers to access or influence the user's PIN code … | Apr 10, 2026 |