Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
25167
Total
1824
Critical
7698
High
7899
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-34099 | CRITICAL | 9.8 | Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in job_info.php (line 16): SELECT * FROM jobs where id = '\".$_GET['id'].\"'. … | Jul 01, 2026 |
| CVE-2026-34098 | MEDIUM | 4.6 | Guardian language-system fails to sanitize the id GET parameter before inserting it into HTML source and form action attributes in media.php (lines 119, 129). An … | Jul 01, 2026 |
| CVE-2026-34097 | MEDIUM | 4.6 | Guardian language-system fails to sanitize the id GET parameter before inserting it into multiple HTML form action attributes in text_file.php (lines 94, 101, 323, 403, … | Jul 01, 2026 |
| CVE-2026-34096 | MEDIUM | 4.6 | Guardian language-system fails to sanitize the name GET parameter before outputting it into an HTML input value attribute in designer.php (line 57). An authenticated attacker … | Jul 01, 2026 |
| CVE-2026-27409 | MEDIUM | 5.3 | Missing Authorization vulnerability in Webba Plugins Webba Booking allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Webba Booking: from n/a through 6.4.13. | Jul 01, 2026 |
| CVE-2026-20244 | HIGH | 7.5 | A vulnerability in the DMG file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition, or possibly other expanded … | Jul 01, 2026 |
| CVE-2026-20243 | HIGH | 7.5 | A vulnerability in the ALZ file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition, or possibly other expanded … | Jul 01, 2026 |
| CVE-2026-20217 | HIGH | 7.5 | A vulnerability in the PESpin file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition, or possibly other expanded … | Jul 01, 2026 |
| CVE-2026-20216 | HIGH | 7.5 | A vulnerability in the InstallShield file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device. … | Jul 01, 2026 |
| CVE-2026-20215 | HIGH | 7.5 | A vulnerability in the 7z file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition, or possibly other expanded … | Jul 01, 2026 |
| CVE-2026-20214 | HIGH | 7.5 | A vulnerability in the FSG file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition, or possibly other expanded … | Jul 01, 2026 |
| CVE-2026-20213 | HIGH | 7.5 | A vulnerability in the PE file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition, or possibly other expanded … | Jul 01, 2026 |
| CVE-2026-20191 | HIGH | 7.5 | A vulnerability in Cisco Catalyst Center could allow an unauthenticated, remote attacker to read arbitrary files from a restricted container. This vulnerability is due to … | Jul 01, 2026 |
| CVE-2026-13211 | MEDIUM | 4.3 | The genucenter web interface before version 8.0p11 unnecessarily exposes sensitive SNMP authentication and encryption keys in its HTTP responses to users with the “Service” or … | Jul 01, 2026 |
| CVE-2026-12480 | MEDIUM | 5.5 | Keras versions up to and including 3.13.2 are vulnerable to an arbitrary HDF5 file read due to an incomplete fix for CVE-2026-1669. The vulnerability resides … | Jul 01, 2026 |
| CVE-2026-8857 | UNKNOWN | — | A vulnerability in Wikimedia Foundation timeline. This vulnerability is associated with program files scripts/EasyTimeline.Pl, includes/Timeline.Php. This issue affects timeline: from * before 1.46.0, 1.45.4, 1.44.6, … | Jul 01, 2026 |
| CVE-2026-8480 | MEDIUM | 4.3 | A vulnerability was discovered on Stormshield Network Security 4.3.0 to 4.3.41 (included), 4.4.0 to 4.8.15 (included) , 5.0.2 EA to 5.0.5 (included) A revoked client … | Jul 01, 2026 |
| CVE-2026-58127 | CRITICAL | 9.8 | PACSgear MediaWriter 5.2.1 exposes a .NET Remoting TCP service on port 9000 via PacsgearMediaServerEngine.dll, registered with ObjectURIs RemoteObj and UIRemoteObj, without any authentication requirement. By … | Jul 01, 2026 |
| CVE-2026-58126 | CRITICAL | 9.8 | PACSgear PACS Scan 5.2.1 contains an unauthenticated remote code execution vulnerability that allows remote attackers to read and write arbitrary files by exploiting an exposed … | Jul 01, 2026 |
| CVE-2026-58038 | UNKNOWN | — | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation timeline. This vulnerability is associated with program files includes/Timeline.Php, … | Jul 01, 2026 |
| CVE-2026-58037 | UNKNOWN | — | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Language/Language.Php, … | Jul 01, 2026 |
| CVE-2026-58036 | UNKNOWN | — | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Api/ApiQueryAllUsers.Php, includes/Api/ApiQueryUsers.Php, includes/Permissions/PermissionManager.Php, includes/User/UserGroupManager.Php. | Jul 01, 2026 |
| CVE-2026-58033 | UNKNOWN | — | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Actions/InfoAction.Php. This issue affects MediaWiki: … | Jul 01, 2026 |
| CVE-2026-58032 | UNKNOWN | — | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files resources/src/mediawiki.Api/index.Js. … | Jul 01, 2026 |
| CVE-2026-58030 | UNKNOWN | — | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Wikimedia Foundation SyntaxHighlight_GeSHi. This vulnerability is associated with program files includes/SyntaxHighlight.Php. … | Jul 01, 2026 |