Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
25897
Total
1938
Critical
7913
High
8158
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-53428 | UNKNOWN | — | Memory Allocation with Excessive Size Value vulnerability in leandrocp mdex allows an unauthenticated attacker to cause a denial of service through unbounded memory allocation. comrak_nif::lumis_adapter::LumisAdapter::parse_highlight_lines … | Jun 29, 2026 |
| CVE-2026-53427 | UNKNOWN | — | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in leandrocp MDEx allows stored or reflected cross-site scripting via attacker-controlled Markdown. When syntax … | Jun 29, 2026 |
| CVE-2026-13757 | MEDIUM | 6.2 | A flaw was found in p11-kit. The RPC message attribute parsing functions p11_rpc_message_get_attribute() and p11_rpc_message_get_attribute_array_value() form a mutually-recursive call chain with no recursion depth limit … | Jun 29, 2026 |
| CVE-2026-57960 | MEDIUM | 6.5 | Hi.Events through 1.9.0 public check-in list endpoints use short_id as sole access control, allowing unauthenticated access to retrieve full attendee lists including emails and personal … | Jun 29, 2026 |
| CVE-2026-57959 | MEDIUM | 5.9 | Hi.Events through 1.9.0 contains a promo code validation vulnerability where reservation validates usage count before asynchronous UpdateEventStatisticsJob increments it, allowing attackers to redeem limited promo … | Jun 29, 2026 |
| CVE-2026-57958 | MEDIUM | 6.1 | Mixpost through 2.6.0 contains a reflected cross-site scripting vulnerability that allows unauthenticated attackers to execute arbitrary JavaScript in authenticated users' browsers by crafting malicious OAuth … | Jun 29, 2026 |
| CVE-2026-57957 | MEDIUM | 4.7 | Papermark through 0.22.0 contains a cross-origin resource sharing (CORS) misconfiguration vulnerability that allows unauthenticated remote attackers to perform credentialed cross-origin requests by exploiting the TUS-based … | Jun 29, 2026 |
| CVE-2026-57956 | MEDIUM | 6.4 | SigNoz through 0.130.1 contains a broken access control vulnerability that allows authenticated users to access other organizations' alert rules by supplying a target rule UUID, … | Jun 29, 2026 |
| CVE-2026-57955 | HIGH | 8.5 | SigNoz through 0.130.1 contains a SQL injection vulnerability that allows authenticated attackers to execute arbitrary ClickHouse queries by injecting URL-encoded quotes into the rule ID … | Jun 29, 2026 |
| CVE-2026-57954 | MEDIUM | 4.3 | Elide through 7.1.17 fails to enforce @ReadPermission on client-supplied sort expressions in SortingImpl.getValidSortingRules, allowing attackers to sort collections by forbidden fields. Attackers can infer hidden … | Jun 29, 2026 |
| CVE-2026-57953 | MEDIUM | 5.4 | Mythic before 3.4.0.60 contains an authorization bypass vulnerability that allows authenticated spectator-role users to perform unauthorized write operations by accessing the eventing_import_automatic_webhook endpoint registered under … | Jun 29, 2026 |
| CVE-2026-57952 | MEDIUM | 5.3 | Mythic before 3.4.0.60 contains an authorization bypass vulnerability in four REST endpoints (c2profile_config_check_webhook, c2profile_redirect_rules_webhook, c2profile_get_ioc_webhook, c2profile_sample_message_webhook) that fail to verify payload ownership. An operator in … | Jun 29, 2026 |
| CVE-2026-57951 | MEDIUM | 6.5 | Mythic before 3.4.0.60 contains a broken hasura permission filter on the payload_build_step table with an always-satisfied _or condition that bypasses operation-scoped access controls. Authenticated operators … | Jun 29, 2026 |
| CVE-2026-57950 | HIGH | 8.1 | ruoyi-vue-pro through 2026.05, fixed in commit 5d1fd70 contains a broken access control vulnerability in ErpSaleOrderController that allows attackers with erp:sale-out permissions to gain unauthorized access … | Jun 29, 2026 |
| CVE-2026-57949 | MEDIUM | 6.5 | ruoyi-vue-pro through 2026.05, fixed in commit c779a47, contains a missing authorization vulnerability in the CRM module's GET /admin-api/crm/follow-up-record/get endpoint that allows authenticated users to read … | Jun 29, 2026 |
| CVE-2026-57948 | MEDIUM | 6.8 | Pinpoint through version 3.1.0 contains an insecure session management vulnerability that allows attackers to access the pinpointJwt session cookie due to missing HttpOnly and Secure … | Jun 29, 2026 |
| CVE-2026-57947 | HIGH | 8.5 | Pinpoint through 3.1.0 contains a server-side request forgery vulnerability in the webhook registration endpoint that allows authenticated users to register internal URLs due to missing … | Jun 29, 2026 |
| CVE-2026-57946 | LOW | 3.7 | Invidious before version 2.20260626.0 contains a broken access control vulnerability that allows unauthenticated attackers to retrieve private playlist contents by accessing the RSS feed playlist … | Jun 29, 2026 |
| CVE-2026-57945 | MEDIUM | 4.3 | PhotoPrism before 260601-a7d098548 contains a broken access control vulnerability that allows authenticated non-admin users to modify other users' profile information by sending requests to arbitrary … | Jun 29, 2026 |
| CVE-2026-57943 | MEDIUM | 5.9 | LibrePhotos before 1.0.0 contains a broken object level authorization vulnerability in the SetPhotosShared endpoint that allows authenticated users to grant themselves access to other users' … | Jun 29, 2026 |
| CVE-2026-57942 | MEDIUM | 5.3 | LibreTranslate through 1.9.7, fixed in commit 397fd22, contains an IP spoofing vulnerability in the get_remote_address() function that allows unauthenticated attackers to spoof client IP addresses … | Jun 29, 2026 |
| CVE-2026-56783 | MEDIUM | 6.5 | Parseable before 2.9.2 contains an information disclosure vulnerability in the notification-target API endpoints that returns webhook tokens and basic-auth credentials in cleartext due to commented-out … | Jun 29, 2026 |
| CVE-2026-56782 | CRITICAL | 9.8 | Gorse before 0.5.10 contains an authentication bypass vulnerability in the /api/dump and /api/restore endpoints that allows unauthenticated attackers to access protected functionality when admin_api_key is … | Jun 29, 2026 |
| CVE-2026-56781 | MEDIUM | 5.3 | Teable before 2026-06-15T04-43-24Z.1912 contains an improper access control vulnerability that allows anonymous attackers to access hidden field data by supplying arbitrary field IDs in the … | Jun 29, 2026 |
| CVE-2026-56780 | HIGH | 7.5 | Modoboa before 2.9.0 contains an insecure direct object reference vulnerability in the PUT /api/v1/accounts/{pk}/password/ endpoint that allows domain administrators to change any user's password. Attackers … | Jun 29, 2026 |