Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

25897
Total
1938
Critical
7913
High
8158
Medium
CVE ID Severity Score Description Published
CVE-2026-53428 UNKNOWN Memory Allocation with Excessive Size Value vulnerability in leandrocp mdex allows an unauthenticated attacker to cause a denial of service through unbounded memory allocation. comrak_nif::lumis_adapter::LumisAdapter::parse_highlight_lines … Jun 29, 2026
CVE-2026-53427 UNKNOWN Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in leandrocp MDEx allows stored or reflected cross-site scripting via attacker-controlled Markdown. When syntax … Jun 29, 2026
CVE-2026-13757 MEDIUM 6.2 A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_message_get_attribute_array_value() form a mutually-recursive call chain with no recursion depth limit … Jun 29, 2026
CVE-2026-57960 MEDIUM 6.5 Hi.Events through 1.9.0 public check-in list endpoints use short_id as sole access control, allowing unauthenticated access to retrieve full attendee lists including emails and personal … Jun 29, 2026
CVE-2026-57959 MEDIUM 5.9 Hi.Events through 1.9.0 contains a promo code validation vulnerability where reservation validates usage count before asynchronous UpdateEventStatisticsJob increments it, allowing attackers to redeem limited promo … Jun 29, 2026
CVE-2026-57958 MEDIUM 6.1 Mixpost through 2.6.0 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to execute arbitrary JavaScript in authenticated users' browsers by crafting malicious OAuth … Jun 29, 2026
CVE-2026-57957 MEDIUM 4.7 Papermark through 0.22.0 contains a cross-origin resource sharing (CORS) misconfiguration vulnerability that allows unauthenticated remote attackers to perform credentialed cross-origin requests by exploiting the TUS-based … Jun 29, 2026
CVE-2026-57956 MEDIUM 6.4 SigNoz through 0.130.1 contains a broken access control vulnerability that allows authenticated users to access other organizations' alert rules by supplying a target rule UUID, … Jun 29, 2026
CVE-2026-57955 HIGH 8.5 SigNoz through 0.130.1 contains a SQL injection vulnerability that allows authenticated attackers to execute arbitrary ClickHouse queries by injecting URL-encoded quotes into the rule ID … Jun 29, 2026
CVE-2026-57954 MEDIUM 4.3 Elide through 7.1.17 fails to enforce @ReadPermission on client-supplied sort expressions in SortingImpl.getValidSortingRules, allowing attackers to sort collections by forbidden fields. Attackers can infer hidden … Jun 29, 2026
CVE-2026-57953 MEDIUM 5.4 Mythic before 3.4.0.60 contains an authorization bypass vulnerability that allows authenticated spectator-role users to perform unauthorized write operations by accessing the eventing_import_automatic_webhook endpoint registered under … Jun 29, 2026
CVE-2026-57952 MEDIUM 5.3 Mythic before 3.4.0.60 contains an authorization bypass vulnerability in four REST endpoints (c2profile_config_check_webhook, c2profile_redirect_rules_webhook, c2profile_get_ioc_webhook, c2profile_sample_message_webhook) that fail to verify payload ownership. An operator in … Jun 29, 2026
CVE-2026-57951 MEDIUM 6.5 Mythic before 3.4.0.60 contains a broken hasura permission filter on the payload_build_step table with an always-satisfied _or condition that bypasses operation-scoped access controls. Authenticated operators … Jun 29, 2026
CVE-2026-57950 HIGH 8.1 ruoyi-vue-pro through 2026.05, fixed in commit 5d1fd70 contains a broken access control vulnerability in ErpSaleOrderController that allows attackers with erp:sale-out permissions to gain unauthorized access … Jun 29, 2026
CVE-2026-57949 MEDIUM 6.5 ruoyi-vue-pro through 2026.05, fixed in commit c779a47, contains a missing authorization vulnerability in the CRM module's GET /admin-api/crm/follow-up-record/get endpoint that allows authenticated users to read … Jun 29, 2026
CVE-2026-57948 MEDIUM 6.8 Pinpoint through version 3.1.0 contains an insecure session management vulnerability that allows attackers to access the pinpointJwt session cookie due to missing HttpOnly and Secure … Jun 29, 2026
CVE-2026-57947 HIGH 8.5 Pinpoint through 3.1.0 contains a server-side request forgery vulnerability in the webhook registration endpoint that allows authenticated users to register internal URLs due to missing … Jun 29, 2026
CVE-2026-57946 LOW 3.7 Invidious before version 2.20260626.0 contains a broken access control vulnerability that allows unauthenticated attackers to retrieve private playlist contents by accessing the RSS feed playlist … Jun 29, 2026
CVE-2026-57945 MEDIUM 4.3 PhotoPrism before 260601-a7d098548 contains a broken access control vulnerability that allows authenticated non-admin users to modify other users' profile information by sending requests to arbitrary … Jun 29, 2026
CVE-2026-57943 MEDIUM 5.9 LibrePhotos before 1.0.0 contains a broken object level authorization vulnerability in the SetPhotosShared endpoint that allows authenticated users to grant themselves access to other users' … Jun 29, 2026
CVE-2026-57942 MEDIUM 5.3 LibreTranslate through 1.9.7, fixed in commit 397fd22, contains an IP spoofing vulnerability in the get_remote_address() function that allows unauthenticated attackers to spoof client IP addresses … Jun 29, 2026
CVE-2026-56783 MEDIUM 6.5 Parseable before 2.9.2 contains an information disclosure vulnerability in the notification-target API endpoints that returns webhook tokens and basic-auth credentials in cleartext due to commented-out … Jun 29, 2026
CVE-2026-56782 CRITICAL 9.8 Gorse before 0.5.10 contains an authentication bypass vulnerability in the /api/dump and /api/restore endpoints that allows unauthenticated attackers to access protected functionality when admin_api_key is … Jun 29, 2026
CVE-2026-56781 MEDIUM 5.3 Teable before 2026-06-15T04-43-24Z.1912 contains an improper access control vulnerability that allows anonymous attackers to access hidden field data by supplying arbitrary field IDs in the … Jun 29, 2026
CVE-2026-56780 HIGH 7.5 Modoboa before 2.9.0 contains an insecure direct object reference vulnerability in the PUT /api/v1/accounts/{pk}/password/ endpoint that allows domain administrators to change any user's password. Attackers … Jun 29, 2026