Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

25897
Total
1938
Critical
7913
High
8158
Medium
CVE ID Severity Score Description Published
CVE-2026-11979 UNKNOWN libxml2 is vulnerable to multiple stack-based buffer overflows in the xmlcatalog utility when running in --shell mode. The usershell() function processes user input using fixed-size … Jun 29, 2026
CVE-2026-41992 UNKNOWN GNU gzip contains a global buffer overflow vulnerability in the LZH decompression logic caused by improper reuse of shared global state between different decompression formats … Jun 29, 2026
CVE-2026-41991 UNKNOWN GNU gzip contains a vulnerability in the gzexe utility related to insecure temporary file handling. When the mktemp utility is not available in the user’s … Jun 29, 2026
CVE-2026-13564 HIGH 8.8 A vulnerability was found in Edimax EW-7478APC 1.04. Affected is the function formPPPoESetup of the file /goform/formPPPoESetup of the component POST Request Handler. Performing a … Jun 29, 2026
CVE-2026-13563 HIGH 8.8 A vulnerability has been found in Edimax EW-7478APC 1.04. This impacts the function formL2TPSetup of the file /goform/formL2TPSetup of the component POST Request Handler. Such … Jun 29, 2026
CVE-2026-13562 HIGH 8.8 A flaw has been found in Edimax EW-7478APC 1.04. This affects the function formiNICSiteSurvey of the file /goform/formiNICSiteSurvey of the component POST Request Handler. This … Jun 29, 2026
CVE-2026-13561 MEDIUM 6.3 A vulnerability was detected in Edimax EW-7478APC 1.04. The impacted element is the function formiNICbasic of the file /goform/formiNICbasic of the component POST Request Handler. … Jun 29, 2026
CVE-2026-13560 MEDIUM 6.3 A security vulnerability has been detected in Edimax EW-7478APC 1.04. The affected element is the function formAccept of the file /goform/formAccept of the component POST … Jun 29, 2026
CVE-2026-13559 HIGH 7.3 A weakness has been identified in code-projects Real State Services 1.0. Impacted is an unknown function of the file /single-list_sale.php?action=add. Executing a manipulation of the … Jun 29, 2026
CVE-2026-13558 LOW 3.5 A security flaw has been discovered in CodeAstro Complaint Management System 1.0. This issue affects some unknown processing of the file /report/addreport of the component … Jun 29, 2026
CVE-2026-57346 HIGH 7.1 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Epiphyt Embed Privacy allows Path Traversal. This issue affects Embed Privacy: from … Jun 29, 2026
CVE-2026-25707 HIGH 8.8 A relative path traversal bug problem when processing repository metadata in libzypp before 17.38.10 could be used by remote attackers supplying repositories to overwrite files … Jun 29, 2026
CVE-2026-13601 HIGH 7.1 A flaw was found in Yelp due to an overly permissive Content Security Policy (CSP) implementation provided by yelp-xsl. A malicious Flatpak application can open … Jun 29, 2026
CVE-2026-13557 MEDIUM 4.3 A vulnerability was identified in itsourcecode Online Hotel Management System 1.0. This vulnerability affects unknown code of the file /admin/mod_room/controller.php?action=add of the component POST Request … Jun 29, 2026
CVE-2026-13556 MEDIUM 4.3 A vulnerability was determined in itsourcecode Online Hotel Management System 1.0. This affects an unknown part of the file /admin/mod_users/controller.php?action=edit of the component POST Request … Jun 29, 2026
CVE-2026-13555 HIGH 7.3 A vulnerability was found in itsourcecode Online Hotel Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/mod_users/controller.php?action=add. The manipulation … Jun 29, 2026
CVE-2026-13554 MEDIUM 4.3 A vulnerability has been found in itsourcecode Online Hotel Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/mod_amenities/controller.php?action=add of … Jun 29, 2026
CVE-2026-13553 HIGH 7.3 A flaw has been found in itsourcecode Online Hotel Management System 1.0. Affected is an unknown function of the file /admin/mod_amenities/controller.php?action=add. Executing a manipulation of … Jun 29, 2026
CVE-2026-13552 HIGH 7.3 A vulnerability was detected in itsourcecode Online Hotel Management System 1.0. This impacts an unknown function of the file /admin/mod_amenities/controller.php?action=edit. Performing a manipulation of the … Jun 29, 2026
CVE-2026-9267 UNKNOWN Eclipse tinydtls before commit b3efd41ad111a4920f599f51ffa4f5e9f1e72221 contains an out-of-bounds read vulnerability in the check_server_certificate() function that allows unauthenticated attackers to trigger reads beyond valid buffer boundaries … Jun 29, 2026
CVE-2026-57966 MEDIUM 4.4 A path traversal vulnerability was found in spice-vdagent. This flaw allows a malicious or compromised SPICE host to write arbitrary files to any location on … Jun 29, 2026
CVE-2026-57965 MEDIUM 5.1 A flaw was found in spice-vdagent. A malicious or compromised SPICE host can trigger an integer overflow by sending a specially crafted message. This vulnerability … Jun 29, 2026
CVE-2026-57676 MEDIUM 4.3 Authorization Bypass Through User-Controlled Key vulnerability in Matteo Manna Simple User Avatar allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Simple User … Jun 29, 2026
CVE-2026-22078 HIGH 7.3 Because O+ Connect's IPC service does not authenticate clients, external applications can escalate privileges and perform sensitive actions through the IPC channel. Jun 29, 2026
CVE-2026-13595 MEDIUM 6.8 A flaw was found in the libblkid library of util-linux. During nested partition probing, the BSD, Minix, Solaris x86, and UnixWare partition probers cache a … Jun 29, 2026