Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

25301
Total
1888
Critical
7733
High
7926
Medium
CVE ID Severity Score Description Published
CVE-2026-34108 CRITICAL 9.8 Guardian language-system passes the id GET parameter directly into a PHP exec() call in text.php (line 15) without sanitization: exec(\"php jobs/text.php \".$login_session.\" \".$_GET['id'].\" ...\"). No … Jul 01, 2026
CVE-2026-34107 CRITICAL 9.8 Guardian language-system passes the id GET parameter directly into a PHP exec() call in translate.php (line 14) without sanitization: exec(\"php jobs/translate.php \".$login_session.\" \".$_GET['id'].\" ...\"). No … Jul 01, 2026
CVE-2026-34106 CRITICAL 9.8 Guardian language-system passes the id GET parameter directly into a PHP exec() call in subtitles.php (line 19) without sanitization: exec(\"php jobs/subtitle_rendering.php \".$login_session.\" \".$_GET['id'].\" ...\"). No … Jul 01, 2026
CVE-2026-34105 CRITICAL 9.8 Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in translate_text.php (line 15): SELECT id, filename, extension, type FROM files where … Jul 01, 2026
CVE-2026-34104 CRITICAL 9.8 Guardian language-system passes the name GET parameter directly into an unsanitized SQL query in designer.php (line 124): SELECT * FROM complex WHERE name='\".$_GET['name'].\"'. An authenticated … Jul 01, 2026
CVE-2026-34103 CRITICAL 9.8 Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in subtitles.php (line 16): SELECT id, filename, extension, type FROM files where … Jul 01, 2026
CVE-2026-34102 CRITICAL 9.8 Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in job_info_get.php (line 16): SELECT * FROM jobs where input1 = '\".$_GET['id'].\"'. … Jul 01, 2026
CVE-2026-34101 CRITICAL 9.8 Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in text_file.php (line 17): SELECT id, filename, extension, type, duration, owner, private … Jul 01, 2026
CVE-2026-34100 CRITICAL 9.8 Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in media.php (line 17): SELECT id, filename, extension, type, duration, owner, private … Jul 01, 2026
CVE-2026-34099 CRITICAL 9.8 Guardian language-system passes the id GET parameter directly into an unsanitized SQL query in job_info.php (line 16): SELECT * FROM jobs where id = '\".$_GET['id'].\"'. … Jul 01, 2026
CVE-2026-34098 MEDIUM 4.6 Guardian language-system fails to sanitize the id GET parameter before inserting it into HTML source and form action attributes in media.php (lines 119, 129). An … Jul 01, 2026
CVE-2026-34097 MEDIUM 4.6 Guardian language-system fails to sanitize the id GET parameter before inserting it into multiple HTML form action attributes in text_file.php (lines 94, 101, 323, 403, … Jul 01, 2026
CVE-2026-34096 MEDIUM 4.6 Guardian language-system fails to sanitize the name GET parameter before outputting it into an HTML input value attribute in designer.php (line 57). An authenticated attacker … Jul 01, 2026
CVE-2026-27409 MEDIUM 5.3 Missing Authorization vulnerability in Webba Plugins Webba Booking allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Webba Booking: from n/a through 6.4.13. Jul 01, 2026
CVE-2026-20244 HIGH 7.5 A vulnerability in the DMG file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition, or possibly other expanded … Jul 01, 2026
CVE-2026-20243 HIGH 7.5 A vulnerability in the ALZ file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition, or possibly other expanded … Jul 01, 2026
CVE-2026-20217 HIGH 7.5 A vulnerability in the PESpin file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition, or possibly other expanded … Jul 01, 2026
CVE-2026-20216 HIGH 7.5 A vulnerability in the InstallShield file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device. … Jul 01, 2026
CVE-2026-20215 HIGH 7.5 A vulnerability in the 7z file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition, or possibly other expanded … Jul 01, 2026
CVE-2026-20214 HIGH 7.5 A vulnerability in the FSG file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition, or possibly other expanded … Jul 01, 2026
CVE-2026-20213 HIGH 7.5 A vulnerability in the PE file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition, or possibly other expanded … Jul 01, 2026
CVE-2026-20191 HIGH 7.5 A vulnerability in Cisco Catalyst Center could allow an unauthenticated, remote attacker to read arbitrary files from a restricted container.  This vulnerability is due to … Jul 01, 2026
CVE-2026-13211 MEDIUM 4.3 The genucenter web interface before version 8.0p11 unnecessarily exposes sensitive SNMP authentication and encryption keys in its HTTP responses to users with the “Service” or … Jul 01, 2026
CVE-2026-12480 MEDIUM 5.5 Keras versions up to and including 3.13.2 are vulnerable to an arbitrary HDF5 file read due to an incomplete fix for CVE-2026-1669. The vulnerability resides … Jul 01, 2026
CVE-2026-8857 UNKNOWN A vulnerability in Wikimedia Foundation timeline. This vulnerability is associated with program files scripts/EasyTimeline.Pl, includes/Timeline.Php. This issue affects timeline: from * before 1.46.0, 1.45.4, 1.44.6, … Jul 01, 2026