Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

26391
Total
1955
Critical
7971
High
8223
Medium
CVE ID Severity Score Description Published
CVE-2026-1764 MEDIUM 5.6 A flaw was found in GNOME localsearch (previously known as tracker-miners) MP3 Extractor. When processing specially crafted MP3 files containing ID3v2.4 tags, a missing bounds … Jun 16, 2026
CVE-2026-12162 MEDIUM 5.5 Improper host validation in the social login autofill feature in Devolutions Remote Desktop Manager 2026.2.8 allows an attacker to disclose stored social login credentials via … Jun 16, 2026
CVE-2026-12161 HIGH 8.8 Improper input validation in the SSH Elevate Shell feature in Devolutions Remote Desktop Manager 2026.2.7 allows an authenticated user with permission to create or modify … Jun 16, 2026
CVE-2026-9262 MEDIUM 6.5 Use of a non-secure protocol as the default FTP configuration in Canon EOS Network Setting Tool Version 1.5.0 or earlier Jun 16, 2026
CVE-2026-9261 MEDIUM 6.8 Use of weak SSH cryptographic algorithms in Canon EOS Network Setting Tool Version 1.5.0 or earlier Jun 16, 2026
CVE-2026-9260 MEDIUM 6.2 Use of hard-coded cryptographic keys in Canon EOS Network Setting Tool Version 1.5.0 or earlier Jun 16, 2026
CVE-2026-9259 MEDIUM 6.5 Improper validation of server certificates in Canon EOS Network Setting Tool Version 1.5.0 or earlier Jun 16, 2026
CVE-2026-9258 MEDIUM 6.5 Improper validation of SSH host keys in Canon EOS Network Setting Tool Version 1.5.0 or earlier Jun 16, 2026
CVE-2026-53430 UNKNOWN Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in elixir-grpc grpc (GRPC.Compressor.Gzip, GRPC.Message modules) allows a denial of service via a gzip decompression bomb. … Jun 15, 2026
CVE-2026-48854 UNKNOWN Allocation of Resources Without Limits or Throttling vulnerability in elixir-grpc grpc allows unauthenticated attackers to exhaust the BEAM's memory and crash the server by streaming … Jun 15, 2026
CVE-2026-48853 UNKNOWN Deserialization of Untrusted Data and Allocation of Resources Without Limits or Throttling vulnerabilities in elixir-grpc grpc allow unauthenticated attackers to crash the BEAM node via … Jun 15, 2026
CVE-2026-48723 HIGH 7.8 The browserstack-cypress-cli is BrowserStack's CLI which allows users to run Cypress tests on BrowserStack. Versions prior to 1.36.4 are vulnerable to OS command injection via … Jun 15, 2026
CVE-2026-48599 UNKNOWN Authorization Bypass Through User-Controlled Key vulnerability in elixir-grpc grpc allows authenticated attackers to access or modify resources belonging to other users by smuggling a conflicting … Jun 15, 2026
CVE-2026-12205 CRITICAL 9.1 Crypt::DSA versions before 1.21 for Perl reused the nonce across signatures, leading to private-key recovery. Crypt::DSA::sign caches the per-signature nonce material in the Key object … Jun 15, 2026
CVE-2026-5064 UNKNOWN Potential security vulnerabilities have been identified in the HP One Agent for certain HP PC products, which might allow for escalation of privilege and/or denial … Jun 15, 2026
CVE-2026-48714 CRITICAL 9.1 i18next-http-middleware is a middleware to be used with Node.js web frameworks like express or Fastify and also for Deno. In versions prior to 3.9.7, the … Jun 15, 2026
CVE-2026-48713 CRITICAL 9.1 Versions prior to 2.6.6 are vulnerable to prototype pollution via crafted missing-key strings when used to persist missing translation keys (e.g. via i18next-http-middleware's missingKeyHandler exposed … Jun 15, 2026
CVE-2026-48157 MEDIUM 6.1 Slim is a PHP micro framework that enables users to write simple web applications and APIs. In versions 4.4.0 through 4.15, if an application uses … Jun 15, 2026
CVE-2026-48017 HIGH 8.8 DbGate is cross-platform database manager. In versions 7.1.8 and prior, the POST /runners/load-reader endpoint in DbGate accepts a functionName parameter that is directly interpolated into … Jun 15, 2026
CVE-2026-12087 UNKNOWN Socket versions before 2.041 for Perl have an out-of-bounds heap read. In Socket.xs, pack_ip_mreq_source() checks the length of its source argument before the argument is … Jun 15, 2026
CVE-2026-11832 UNKNOWN Dancer2::Plugin::Auth::OAuth versions before 0.22 for Perl default to a predictable nonce. The default nonce was generated using an MD5 hash of the epoch time, which … Jun 15, 2026
CVE-2026-9691 CRITICAL 9.8 Unauthenticated PHP Object Injection in Integration for ActiveCampaign and Contact Form 7, WPForms, Elementor, Ninja Forms <= 1.1.1 versions. Jun 15, 2026
CVE-2026-52703 CRITICAL 9.6 Unauthenticated Path Traversal in FastDup <= 2.7.2 versions. Jun 15, 2026
CVE-2026-52702 HIGH 7.1 Unauthenticated Cross Site Scripting (XSS) in SEO Redirection <= 9.17 versions. Jun 15, 2026
CVE-2026-52700 HIGH 8.5 Subscriber SQL Injection in WCMultiShipping <= 3.0.2 versions. Jun 15, 2026