Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
26391
Total
1955
Critical
7971
High
8223
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-1764 | MEDIUM | 5.6 | A flaw was found in GNOME localsearch (previously known as tracker-miners) MP3 Extractor. When processing specially crafted MP3 files containing ID3v2.4 tags, a missing bounds … | Jun 16, 2026 |
| CVE-2026-12162 | MEDIUM | 5.5 | Improper host validation in the social login autofill feature in Devolutions Remote Desktop Manager 2026.2.8 allows an attacker to disclose stored social login credentials via … | Jun 16, 2026 |
| CVE-2026-12161 | HIGH | 8.8 | Improper input validation in the SSH Elevate Shell feature in Devolutions Remote Desktop Manager 2026.2.7 allows an authenticated user with permission to create or modify … | Jun 16, 2026 |
| CVE-2026-9262 | MEDIUM | 6.5 | Use of a non-secure protocol as the default FTP configuration in Canon EOS Network Setting Tool Version 1.5.0 or earlier | Jun 16, 2026 |
| CVE-2026-9261 | MEDIUM | 6.8 | Use of weak SSH cryptographic algorithms in Canon EOS Network Setting Tool Version 1.5.0 or earlier | Jun 16, 2026 |
| CVE-2026-9260 | MEDIUM | 6.2 | Use of hard-coded cryptographic keys in Canon EOS Network Setting Tool Version 1.5.0 or earlier | Jun 16, 2026 |
| CVE-2026-9259 | MEDIUM | 6.5 | Improper validation of server certificates in Canon EOS Network Setting Tool Version 1.5.0 or earlier | Jun 16, 2026 |
| CVE-2026-9258 | MEDIUM | 6.5 | Improper validation of SSH host keys in Canon EOS Network Setting Tool Version 1.5.0 or earlier | Jun 16, 2026 |
| CVE-2026-53430 | UNKNOWN | — | Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in elixir-grpc grpc (GRPC.Compressor.Gzip, GRPC.Message modules) allows a denial of service via a gzip decompression bomb. … | Jun 15, 2026 |
| CVE-2026-48854 | UNKNOWN | — | Allocation of Resources Without Limits or Throttling vulnerability in elixir-grpc grpc allows unauthenticated attackers to exhaust the BEAM's memory and crash the server by streaming … | Jun 15, 2026 |
| CVE-2026-48853 | UNKNOWN | — | Deserialization of Untrusted Data and Allocation of Resources Without Limits or Throttling vulnerabilities in elixir-grpc grpc allow unauthenticated attackers to crash the BEAM node via … | Jun 15, 2026 |
| CVE-2026-48723 | HIGH | 7.8 | The browserstack-cypress-cli is BrowserStack's CLI which allows users to run Cypress tests on BrowserStack. Versions prior to 1.36.4 are vulnerable to OS command injection via … | Jun 15, 2026 |
| CVE-2026-48599 | UNKNOWN | — | Authorization Bypass Through User-Controlled Key vulnerability in elixir-grpc grpc allows authenticated attackers to access or modify resources belonging to other users by smuggling a conflicting … | Jun 15, 2026 |
| CVE-2026-12205 | CRITICAL | 9.1 | Crypt::DSA versions before 1.21 for Perl reused the nonce across signatures, leading to private-key recovery. Crypt::DSA::sign caches the per-signature nonce material in the Key object … | Jun 15, 2026 |
| CVE-2026-5064 | UNKNOWN | — | Potential security vulnerabilities have been identified in the HP One Agent for certain HP PC products, which might allow for escalation of privilege and/or denial … | Jun 15, 2026 |
| CVE-2026-48714 | CRITICAL | 9.1 | i18next-http-middleware is a middleware to be used with Node.js web frameworks like express or Fastify and also for Deno. In versions prior to 3.9.7, the … | Jun 15, 2026 |
| CVE-2026-48713 | CRITICAL | 9.1 | Versions prior to 2.6.6 are vulnerable to prototype pollution via crafted missing-key strings when used to persist missing translation keys (e.g. via i18next-http-middleware's missingKeyHandler exposed … | Jun 15, 2026 |
| CVE-2026-48157 | MEDIUM | 6.1 | Slim is a PHP micro framework that enables users to write simple web applications and APIs. In versions 4.4.0 through 4.15, if an application uses … | Jun 15, 2026 |
| CVE-2026-48017 | HIGH | 8.8 | DbGate is cross-platform database manager. In versions 7.1.8 and prior, the POST /runners/load-reader endpoint in DbGate accepts a functionName parameter that is directly interpolated into … | Jun 15, 2026 |
| CVE-2026-12087 | UNKNOWN | — | Socket versions before 2.041 for Perl have an out-of-bounds heap read. In Socket.xs, pack_ip_mreq_source() checks the length of its source argument before the argument is … | Jun 15, 2026 |
| CVE-2026-11832 | UNKNOWN | — | Dancer2::Plugin::Auth::OAuth versions before 0.22 for Perl default to a predictable nonce. The default nonce was generated using an MD5 hash of the epoch time, which … | Jun 15, 2026 |
| CVE-2026-9691 | CRITICAL | 9.8 | Unauthenticated PHP Object Injection in Integration for ActiveCampaign and Contact Form 7, WPForms, Elementor, Ninja Forms <= 1.1.1 versions. | Jun 15, 2026 |
| CVE-2026-52703 | CRITICAL | 9.6 | Unauthenticated Path Traversal in FastDup <= 2.7.2 versions. | Jun 15, 2026 |
| CVE-2026-52702 | HIGH | 7.1 | Unauthenticated Cross Site Scripting (XSS) in SEO Redirection <= 9.17 versions. | Jun 15, 2026 |
| CVE-2026-52700 | HIGH | 8.5 | Subscriber SQL Injection in WCMultiShipping <= 3.0.2 versions. | Jun 15, 2026 |