Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
26383
Total
1955
Critical
7969
High
8219
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-12846 | CRITICAL | 10.0 | GV-I/O Box 4E is a smart embedded device with 4 input and 4 relays output that can be controlled over Ethernet and RS-485. DVRSearch is … | Jun 24, 2026 |
| CVE-2026-12488 | MEDIUM | 6.2 | A memory corruption vulnerability exists in the GV-Cloud functionality of GeoVision GV-VMS V20 20.0.2. A specially crafted network request can lead to a denial of … | Jun 24, 2026 |
| CVE-2026-12486 | CRITICAL | 9.1 | Multiple OS command injection vulnerabilities exist in the libNetSetObj.so functionality of GeoVision GV-I/O Box 4E 2.09. A specially crafted network packet can lead to command … | Jun 24, 2026 |
| CVE-2026-12485 | CRITICAL | 10.0 | GV-I/O Box 4E is a smart embedded device with 4 input and 4 relays output that can be controlled over Ethernet and RS-485. DVRSearch is … | Jun 24, 2026 |
| CVE-2026-3652 | HIGH | 7.2 | The ARForms plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `value` parameter of the `arf_save_incomplete_form_data` AJAX action in all versions up to, … | Jun 24, 2026 |
| CVE-2026-11614 | MEDIUM | 6.4 | The Xpro Addons — 140+ Widgets for Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'custom_attributes' parameter in all versions up … | Jun 24, 2026 |
| CVE-2026-12681 | UNKNOWN | — | Improper Validation of Specified Index, Position, or Offset in Input vulnerability in Google go-attestation. parseEfiSignatureList() does not advance the buffer past vendor bytes before reading … | Jun 24, 2026 |
| CVE-2026-54639 | HIGH | 8.8 | Style Dictionary, a build system for creating cross-platform styles, has a prototype pollution vulnerability starting in version 4.3.0 and prior to version 5.4.4. Impact users … | Jun 24, 2026 |
| CVE-2026-7574 | HIGH | 8.7 | Anthropic Claude Desktop Cowork VM image handling (confirmed across v1.1348.0 through v1.2278.0, including v1.1348.0, v1.1617.0, and v1.2278.0) validates only file presence and a version marker … | Jun 24, 2026 |
| CVE-2026-6458 | UNKNOWN | — | Missing cryptographic step in Caliptra Core Firmware (aes_256_gcm_update module) results in an incorrect GCM authentication tag. When the streaming AES-256-GCM API is used with empty … | Jun 24, 2026 |
| CVE-2026-5818 | UNKNOWN | — | Incorrect check of function return value in Caliptra Core Runtime Firmware (ActivateFirmwareCmd::activate_fw modules) allows bypass of Caliptra Core's verification of the MCU FW during a … | Jun 24, 2026 |
| CVE-2026-56785 | HIGH | 8.2 | FlatPress contains a stored cross-site scripting vulnerability in comment and contact forms where name, URL, and email fields are rendered without proper output encoding in … | Jun 23, 2026 |
| CVE-2026-54588 | CRITICAL | 9.6 | Poweradmin is a web-based DNS administration tool for PowerDNS server. Versions prior to 4.2.4 and 4.3.3 use the attacker-controlled `HTTP_HOST` request header as the authoritative … | Jun 23, 2026 |
| CVE-2026-48493 | MEDIUM | 5.5 | Snipe-IT is an IT asset/license management system. In versions prior to 8.6.0, a user with only users.edit can send a PATCH to /api/v1/users/{their_own_id} and grant … | Jun 23, 2026 |
| CVE-2026-47693 | MEDIUM | 6.9 | Poweradmin is a web-based DNS administration tool for PowerDNS server. Versions prior to 4.2.4 and 4.3.3 are vulnerable to CSV Injection (Formula Injection) in its … | Jun 23, 2026 |
| CVE-2026-12164 | MEDIUM | 4.4 | Fortra File Integrity Monitoring (FIM), formerly Tripwire Enterprise, versions prior to 9.4.0 may assign incorrect or elevated effective permissions to users created by the tetool … | Jun 23, 2026 |
| CVE-2026-12163 | MEDIUM | 5.5 | Fortra File Integrity Monitoring (FIM), formerly Tripwire Enterprise, versions prior to 9.4.0.1 contain a stored cross-site scripting (XSS) vulnerability in the Asset View UI component. … | Jun 23, 2026 |
| CVE-2026-11972 | UNKNOWN | — | When using the "tarfile" module with a file opened in "streaming mode" (mode="r|") the tarfile module did not properly handle EOF, making archive parsing take … | Jun 23, 2026 |
| CVE-2026-54518 | MEDIUM | 6.5 | jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.21.0 until 2.21.4 and 3.1.4, UnwrappedPropertyHandler.processUnwrappedCreatorProperties() replays buffered JSON into creator parameters … | Jun 23, 2026 |
| CVE-2026-9073 | MEDIUM | 6.2 | A flaw was found in foreman-mcp-server. This component utilizes two distinct logging mechanisms that can expose sensitive session and authentication data. One mechanism logs session … | Jun 23, 2026 |
| CVE-2026-56120 | UNKNOWN | — | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority as it's a duplicate of CVE-2026-56784. | Jun 23, 2026 |
| CVE-2026-54517 | MEDIUM | 5.3 | jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.21.0 until 2.21.4 and 3.1.4, in BeanDeserializer._deserializeUsingPropertyBased, the active-view (@JsonView) filter was … | Jun 23, 2026 |
| CVE-2026-54516 | MEDIUM | 5.3 | jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.21.0 until 2.21.4 and 3.1.4, POJOPropertiesCollector._renameProperties() allows a property with @JsonProperty("renamed") on … | Jun 23, 2026 |
| CVE-2026-54515 | MEDIUM | 5.3 | jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.8.0 until 2.18.9, 2.21.5, and 3.1.4, in BeanDeserializerBase.createContextual(), per-property @JsonIgnoreProperties exclusions are … | Jun 23, 2026 |
| CVE-2026-54514 | MEDIUM | 5.3 | jackson-databind contains the general-purpose data-binding functionality and tree-model for Jackson Data Processor. From 2.0.0 until 2.18.8, 2.21.4, and 3.1.4, JDKFromStringDeserializer constructed InetSocketAddress with new InetSocketAddress(host, … | Jun 23, 2026 |