Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
25897
Total
1938
Critical
7913
High
8158
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-46406 | UNKNOWN | — | Claude Code is an agentic coding tool. From 2.1.59 until 2.1.128, the Claude Code /copy command wrote responses to a hardcoded, predictable path (/tmp/claude/response.md) without … | Jun 29, 2026 |
| CVE-2026-13579 | MEDIUM | 6.3 | A weakness has been identified in itsourcecode Hospital Management System 1.0. Affected by this issue is some unknown functionality of the file /patientchangepassword.php. Executing a … | Jun 29, 2026 |
| CVE-2026-13578 | MEDIUM | 6.3 | A security flaw has been discovered in itsourcecode Hospital Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /patientdetail.php. Performing … | Jun 29, 2026 |
| CVE-2026-13574 | LOW | 3.3 | A vulnerability was determined in llvm llvm-project up to 22.1.6. This impacts the function GCRelocateInst::getBasePtr in the library llvm/lib/IR/IntrinsicInst.cpp of the component Bitcode File Handler. … | Jun 29, 2026 |
| CVE-2026-13573 | LOW | 3.3 | A vulnerability was found in llvm llvm-project up to 22.1.6. This affects the function llvm::StringMap::insert in the library /lib/IR/ValueSymbolTable.cpp of the component ValueSymbolTable Module. The … | Jun 29, 2026 |
| CVE-2026-13572 | MEDIUM | 6.3 | A vulnerability has been found in itsourcecode Hospital Management System 1.0. The impacted element is an unknown function of the file /insertbillingrecord.php. The manipulation of … | Jun 29, 2026 |
| CVE-2026-13571 | MEDIUM | 5.3 | A flaw has been found in SourceCodester Simple Food Ordering System 1.0. The affected element is an unknown function of the file /cart.php. Executing a … | Jun 29, 2026 |
| CVE-2026-56457 | MEDIUM | 4.3 | HCL DevOps Deploy / HCL Launch is susceptible to an exposure of sensitive information vulnerability in output logs. This exposure could allow an attacker with … | Jun 29, 2026 |
| CVE-2026-54371 | HIGH | 7.1 | attr before version 2.6.0 contains a symlink traversal vulnerability in the getfattr and setfattr utilities that allows local attackers to escalate privileges by replacing a … | Jun 29, 2026 |
| CVE-2026-54370 | MEDIUM | 6.3 | acl before version 2.4.0 contains a time-of-check to time-of-use (TOCTOU) race condition vulnerability that allows local attackers to escalate privileges by replacing a pathname component … | Jun 29, 2026 |
| CVE-2026-54369 | HIGH | 7.1 | acl before version 2.4.0 contains a symlink traversal vulnerability in the libacl pathname-based functions acl_get_file(), acl_set_file(), acl_extended_file(), and acl_delete_def_file() that allows local attackers to escalate … | Jun 29, 2026 |
| CVE-2026-40524 | HIGH | 8.1 | FrontAccounting before 2.4.20 contains a SQL injection vulnerability in the get_gl_transactions() function where the filter_type parameter is concatenated directly into a SQL IN() clause without … | Jun 29, 2026 |
| CVE-2026-40523 | HIGH | 8.1 | FrontAccounting before 2.4.20 contains a SQL injection vulnerability in the Audit Trail report handler that allows authenticated attackers with SA_GLANALYTIC permission to execute arbitrary SQL … | Jun 29, 2026 |
| CVE-2026-40522 | HIGH | 7.1 | FrontAccounting before 2.4.20 contains a SQL injection vulnerability in the Bank Statement report handler that allows authenticated attackers to extract arbitrary database data by injecting … | Jun 29, 2026 |
| CVE-2026-40521 | HIGH | 8.8 | FrontAccounting before 2.4.20 contains a path traversal vulnerability in the attachment upload handler that allows authenticated attackers to execute arbitrary code by uploading files with … | Jun 29, 2026 |
| CVE-2026-13676 | HIGH | 7.5 | fast-uri versions 2.3.1 through 3.1.2 and 4.0.0 fail to canonicalize Unicode (IDN) hostnames for HTTP-family URLs. The IDN conversion path calls a helper that does … | Jun 29, 2026 |
| CVE-2026-13570 | LOW | 3.5 | A vulnerability was detected in SourceCodester Inventory Management System 1.0. Impacted is an unknown function of the file /api/users_handler.php of the component User Registration Endpoint. … | Jun 29, 2026 |
| CVE-2026-13569 | MEDIUM | 4.7 | A security vulnerability has been detected in weng-xianhu EyouCMS up to 1.7.1. This issue affects some unknown processing of the file /index.php of the component … | Jun 29, 2026 |
| CVE-2026-13568 | HIGH | 7.3 | A weakness has been identified in SourceCodester Inventory Management System 1.0. This vulnerability affects unknown code of the file /api/users_handler.php of the component User Registration … | Jun 29, 2026 |
| CVE-2026-13567 | MEDIUM | 4.3 | A security flaw has been discovered in code-projects Online Music Site 1.0. This affects an unknown part of the file /Frontend/Feedback.php of the component POST … | Jun 29, 2026 |
| CVE-2026-13566 | HIGH | 7.3 | A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0. Affected by this issue is some unknown functionality of the file /preview3.php. The … | Jun 29, 2026 |
| CVE-2026-13565 | HIGH | 7.3 | A vulnerability was determined in SourceCodester Class and Exam Timetabling System 1.0/1.php. Affected by this vulnerability is an unknown functionality of the file /edit_class1.php. Executing … | Jun 29, 2026 |
| CVE-2026-13165 | UNKNOWN | — | SzafirHost verifies the downloaded native library archive with one JarFile parser (reading the Central Directory) but extracts native libraries with JarInputStream parser (reading sequentially from … | Jun 29, 2026 |
| CVE-2026-12856 | HIGH | 8.8 | A flaw was found in the vscode-java extension, which provides Java language support for Visual Studio Code. The extension incorrectly trusts all Markdown content in … | Jun 29, 2026 |
| CVE-2026-12616 | UNKNOWN | — | The /v1/upload/sbom endpoint extracts the iss claim from the attacker-supplied JWT with signature verification disabled, then interpolates that string into three log statements before any … | Jun 29, 2026 |