Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

26395
Total
1955
Critical
7973
High
8225
Medium
CVE ID Severity Score Description Published
CVE-2025-68872 HIGH 7.1 Unauthenticated Cross Site Scripting (XSS) in Eli&#039;s WordCents adSense Widget with Analytics <= 1.3.03.27 versions. Jun 15, 2026
CVE-2025-68851 HIGH 7.1 Unauthenticated Cross Site Scripting (XSS) in Okay Toolkit <= 2.3 versions. Jun 15, 2026
CVE-2025-68840 HIGH 7.1 Unauthenticated Cross Site Scripting (XSS) in iRobots.txt SEO <= 1.1.2 versions. Jun 15, 2026
CVE-2025-68049 MEDIUM 6.3 Subscriber Broken Access Control in bunny.net <= 2.3.6 versions. Jun 15, 2026
CVE-2025-60175 MEDIUM 4.4 Administrator Server Side Request Forgery (SSRF) in PopAd <= 1.0.4 versions. Jun 15, 2026
CVE-2025-59133 HIGH 7.5 Custom role Insecure Direct Object References (IDOR) in Projectopia <= 5.1.25.2 versions. Jun 15, 2026
CVE-2026-54444 UNKNOWN Rejected reason: ]** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-49489. Reason: This candidate is a duplicate of CVE-2026-49489. Notes: All CVE users … Jun 15, 2026
CVE-2026-54296 UNKNOWN Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-12075. Reason: This candidate is a duplicate of CVE-2026-12075. Notes: All CVE users … Jun 15, 2026
CVE-2026-54295 UNKNOWN Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-12061. Reason: This candidate is a duplicate of CVE-2026-12061. Notes: All CVE users … Jun 15, 2026
CVE-2026-54294 UNKNOWN Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-12072. Reason: This candidate is a duplicate of CVE-2026-12072. Notes: All CVE users … Jun 15, 2026
CVE-2026-54292 UNKNOWN Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-12074. Reason: This candidate is a duplicate of CVE-2026-12074. Notes: All CVE users … Jun 15, 2026
CVE-2026-53705 HIGH 7.6 A flaw was found in GStreamer's WavPack audio decoder in gst-plugins-good. When processing a specially crafted WavPack file, an integer overflow in the buffer size … Jun 15, 2026
CVE-2026-53704 HIGH 7.1 A flaw was found in GStreamer's RealMedia demuxer in the gst-plugins-ugly package. When processing a RealMedia file containing a specially crafted FILEINFO metadata section, the … Jun 15, 2026
CVE-2026-53703 HIGH 7.1 A vulnerability was found in the GStreamer RealMedia demuxer (gst-plugins-ugly). When processing a RealMedia (.rm) file, the demuxer parses MDPR (media properties) chunks to configure … Jun 15, 2026
CVE-2026-52722 HIGH 7.1 A signed integer overflow vulnerability was found in GStreamer's VMnc decoder. A crafted VMnc stream with large cursor dimensions can overflow signed integer payload-size arithmetic, … Jun 15, 2026
CVE-2026-52721 MEDIUM 5.3 Multiple out-of-bounds read vulnerabilities were found in GStreamer's pcapparse element. Malformed PCAP records can trigger reads beyond buffer boundaries during IPv4/TCP header parsing. This element … Jun 15, 2026
CVE-2026-52720 HIGH 8.8 A heap buffer overflow vulnerability was found in GStreamer's librfb (RFB/VNC client). The rectangle bounds check incorrectly validates area rather than individual dimensions, allowing a … Jun 15, 2026
CVE-2026-52719 HIGH 7.1 An out-of-bounds read vulnerability was found in the VA JPEG decoder in GStreamer's gst-plugins-bad. The JPEG parser reads a segment length value from the bitstream … Jun 15, 2026
CVE-2026-52718 MEDIUM 6.5 A denial of service vulnerability was found in GStreamer's AV1 codec parser in gst-plugins-bad. The gst_av1_parser_parse_tile_list_obu() function passes a byte count to a bit-reader API … Jun 15, 2026
CVE-2026-50892 UNKNOWN Incorrect access control in the "Let's Encrypt" certificate download endpoint of Nginx Proxy Manager v2.14.0 allows authenticated attackers to obtain the TLS private key material … Jun 15, 2026
CVE-2026-50891 UNKNOWN Incorrect access control in the /admin/api/config component of Filestash v0.4.0 allows attackers to escalate privileges via sending a crafted request. Jun 15, 2026
CVE-2026-50890 UNKNOWN Bernd Bestel grocy v4.6.0 was discovered to contain a SQL injection vulnerability in the product-group parameter at /stockreports/spendings. This vulnerability allows attackers to access sensitive … Jun 15, 2026
CVE-2026-50889 UNKNOWN An input handling flaw in the HTTP refresh token process of LLDAP v0.6.2 allows attackers to cause a Denial of Service (DoS) via sending a … Jun 15, 2026
CVE-2026-50888 UNKNOWN An authenticated Server-Side Request Forgery (SSRF) in the custom scraper subsystem component of Benjamin Jonard Koillection v1.8.0 allows attackers to scan internal resources via supplying … Jun 15, 2026
CVE-2026-50887 CRITICAL 9.1 A Server-Side Request Forgery (SSRF) in the automatic short URL title resolution component of shlink v5.0.1 allows attackers to scan internal resources via supplying a … Jun 15, 2026