Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
25897
Total
1938
Critical
7913
High
8158
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-11979 | UNKNOWN | — | libxml2 is vulnerable to multiple stack-based buffer overflows in the xmlcatalog utility when running in --shell mode. The usershell() function processes user input using fixed-size … | Jun 29, 2026 |
| CVE-2026-41992 | UNKNOWN | — | GNU gzip contains a global buffer overflow vulnerability in the LZH decompression logic caused by improper reuse of shared global state between different decompression formats … | Jun 29, 2026 |
| CVE-2026-41991 | UNKNOWN | — | GNU gzip contains a vulnerability in the gzexe utility related to insecure temporary file handling. When the mktemp utility is not available in the user’s … | Jun 29, 2026 |
| CVE-2026-13564 | HIGH | 8.8 | A vulnerability was found in Edimax EW-7478APC 1.04. Affected is the function formPPPoESetup of the file /goform/formPPPoESetup of the component POST Request Handler. Performing a … | Jun 29, 2026 |
| CVE-2026-13563 | HIGH | 8.8 | A vulnerability has been found in Edimax EW-7478APC 1.04. This impacts the function formL2TPSetup of the file /goform/formL2TPSetup of the component POST Request Handler. Such … | Jun 29, 2026 |
| CVE-2026-13562 | HIGH | 8.8 | A flaw has been found in Edimax EW-7478APC 1.04. This affects the function formiNICSiteSurvey of the file /goform/formiNICSiteSurvey of the component POST Request Handler. This … | Jun 29, 2026 |
| CVE-2026-13561 | MEDIUM | 6.3 | A vulnerability was detected in Edimax EW-7478APC 1.04. The impacted element is the function formiNICbasic of the file /goform/formiNICbasic of the component POST Request Handler. … | Jun 29, 2026 |
| CVE-2026-13560 | MEDIUM | 6.3 | A security vulnerability has been detected in Edimax EW-7478APC 1.04. The affected element is the function formAccept of the file /goform/formAccept of the component POST … | Jun 29, 2026 |
| CVE-2026-13559 | HIGH | 7.3 | A weakness has been identified in code-projects Real State Services 1.0. Impacted is an unknown function of the file /single-list_sale.php?action=add. Executing a manipulation of the … | Jun 29, 2026 |
| CVE-2026-13558 | LOW | 3.5 | A security flaw has been discovered in CodeAstro Complaint Management System 1.0. This issue affects some unknown processing of the file /report/addreport of the component … | Jun 29, 2026 |
| CVE-2026-57346 | HIGH | 7.1 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Epiphyt Embed Privacy allows Path Traversal. This issue affects Embed Privacy: from … | Jun 29, 2026 |
| CVE-2026-25707 | HIGH | 8.8 | A relative path traversal bug problem when processing repository metadata in libzypp before 17.38.10 could be used by remote attackers supplying repositories to overwrite files … | Jun 29, 2026 |
| CVE-2026-13601 | HIGH | 7.1 | A flaw was found in Yelp due to an overly permissive Content Security Policy (CSP) implementation provided by yelp-xsl. A malicious Flatpak application can open … | Jun 29, 2026 |
| CVE-2026-13557 | MEDIUM | 4.3 | A vulnerability was identified in itsourcecode Online Hotel Management System 1.0. This vulnerability affects unknown code of the file /admin/mod_room/controller.php?action=add of the component POST Request … | Jun 29, 2026 |
| CVE-2026-13556 | MEDIUM | 4.3 | A vulnerability was determined in itsourcecode Online Hotel Management System 1.0. This affects an unknown part of the file /admin/mod_users/controller.php?action=edit of the component POST Request … | Jun 29, 2026 |
| CVE-2026-13555 | HIGH | 7.3 | A vulnerability was found in itsourcecode Online Hotel Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/mod_users/controller.php?action=add. The manipulation … | Jun 29, 2026 |
| CVE-2026-13554 | MEDIUM | 4.3 | A vulnerability has been found in itsourcecode Online Hotel Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/mod_amenities/controller.php?action=add of … | Jun 29, 2026 |
| CVE-2026-13553 | HIGH | 7.3 | A flaw has been found in itsourcecode Online Hotel Management System 1.0. Affected is an unknown function of the file /admin/mod_amenities/controller.php?action=add. Executing a manipulation of … | Jun 29, 2026 |
| CVE-2026-13552 | HIGH | 7.3 | A vulnerability was detected in itsourcecode Online Hotel Management System 1.0. This impacts an unknown function of the file /admin/mod_amenities/controller.php?action=edit. Performing a manipulation of the … | Jun 29, 2026 |
| CVE-2026-9267 | UNKNOWN | — | Eclipse tinydtls before commit b3efd41ad111a4920f599f51ffa4f5e9f1e72221 contains an out-of-bounds read vulnerability in the check_server_certificate() function that allows unauthenticated attackers to trigger reads beyond valid buffer boundaries … | Jun 29, 2026 |
| CVE-2026-57966 | MEDIUM | 4.4 | A path traversal vulnerability was found in spice-vdagent. This flaw allows a malicious or compromised SPICE host to write arbitrary files to any location on … | Jun 29, 2026 |
| CVE-2026-57965 | MEDIUM | 5.1 | A flaw was found in spice-vdagent. A malicious or compromised SPICE host can trigger an integer overflow by sending a specially crafted message. This vulnerability … | Jun 29, 2026 |
| CVE-2026-57676 | MEDIUM | 4.3 | Authorization Bypass Through User-Controlled Key vulnerability in Matteo Manna Simple User Avatar allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Simple User … | Jun 29, 2026 |
| CVE-2026-22078 | HIGH | 7.3 | Because O+ Connect's IPC service does not authenticate clients, external applications can escalate privileges and perform sensitive actions through the IPC channel. | Jun 29, 2026 |
| CVE-2026-13595 | MEDIUM | 6.8 | A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a … | Jun 29, 2026 |