Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
26395
Total
1955
Critical
7973
High
8225
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2025-68872 | HIGH | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Eli's WordCents adSense Widget with Analytics <= 1.3.03.27 versions. | Jun 15, 2026 |
| CVE-2025-68851 | HIGH | 7.1 | Unauthenticated Cross Site Scripting (XSS) in Okay Toolkit <= 2.3 versions. | Jun 15, 2026 |
| CVE-2025-68840 | HIGH | 7.1 | Unauthenticated Cross Site Scripting (XSS) in iRobots.txt SEO <= 1.1.2 versions. | Jun 15, 2026 |
| CVE-2025-68049 | MEDIUM | 6.3 | Subscriber Broken Access Control in bunny.net <= 2.3.6 versions. | Jun 15, 2026 |
| CVE-2025-60175 | MEDIUM | 4.4 | Administrator Server Side Request Forgery (SSRF) in PopAd <= 1.0.4 versions. | Jun 15, 2026 |
| CVE-2025-59133 | HIGH | 7.5 | Custom role Insecure Direct Object References (IDOR) in Projectopia <= 5.1.25.2 versions. | Jun 15, 2026 |
| CVE-2026-54444 | UNKNOWN | — | Rejected reason: ]** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-49489. Reason: This candidate is a duplicate of CVE-2026-49489. Notes: All CVE users … | Jun 15, 2026 |
| CVE-2026-54296 | UNKNOWN | — | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-12075. Reason: This candidate is a duplicate of CVE-2026-12075. Notes: All CVE users … | Jun 15, 2026 |
| CVE-2026-54295 | UNKNOWN | — | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-12061. Reason: This candidate is a duplicate of CVE-2026-12061. Notes: All CVE users … | Jun 15, 2026 |
| CVE-2026-54294 | UNKNOWN | — | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-12072. Reason: This candidate is a duplicate of CVE-2026-12072. Notes: All CVE users … | Jun 15, 2026 |
| CVE-2026-54292 | UNKNOWN | — | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-12074. Reason: This candidate is a duplicate of CVE-2026-12074. Notes: All CVE users … | Jun 15, 2026 |
| CVE-2026-53705 | HIGH | 7.6 | A flaw was found in GStreamer's WavPack audio decoder in gst-plugins-good. When processing a specially crafted WavPack file, an integer overflow in the buffer size … | Jun 15, 2026 |
| CVE-2026-53704 | HIGH | 7.1 | A flaw was found in GStreamer's RealMedia demuxer in the gst-plugins-ugly package. When processing a RealMedia file containing a specially crafted FILEINFO metadata section, the … | Jun 15, 2026 |
| CVE-2026-53703 | HIGH | 7.1 | A vulnerability was found in the GStreamer RealMedia demuxer (gst-plugins-ugly). When processing a RealMedia (.rm) file, the demuxer parses MDPR (media properties) chunks to configure … | Jun 15, 2026 |
| CVE-2026-52722 | HIGH | 7.1 | A signed integer overflow vulnerability was found in GStreamer's VMnc decoder. A crafted VMnc stream with large cursor dimensions can overflow signed integer payload-size arithmetic, … | Jun 15, 2026 |
| CVE-2026-52721 | MEDIUM | 5.3 | Multiple out-of-bounds read vulnerabilities were found in GStreamer's pcapparse element. Malformed PCAP records can trigger reads beyond buffer boundaries during IPv4/TCP header parsing. This element … | Jun 15, 2026 |
| CVE-2026-52720 | HIGH | 8.8 | A heap buffer overflow vulnerability was found in GStreamer's librfb (RFB/VNC client). The rectangle bounds check incorrectly validates area rather than individual dimensions, allowing a … | Jun 15, 2026 |
| CVE-2026-52719 | HIGH | 7.1 | An out-of-bounds read vulnerability was found in the VA JPEG decoder in GStreamer's gst-plugins-bad. The JPEG parser reads a segment length value from the bitstream … | Jun 15, 2026 |
| CVE-2026-52718 | MEDIUM | 6.5 | A denial of service vulnerability was found in GStreamer's AV1 codec parser in gst-plugins-bad. The gst_av1_parser_parse_tile_list_obu() function passes a byte count to a bit-reader API … | Jun 15, 2026 |
| CVE-2026-50892 | UNKNOWN | — | Incorrect access control in the "Let's Encrypt" certificate download endpoint of Nginx Proxy Manager v2.14.0 allows authenticated attackers to obtain the TLS private key material … | Jun 15, 2026 |
| CVE-2026-50891 | UNKNOWN | — | Incorrect access control in the /admin/api/config component of Filestash v0.4.0 allows attackers to escalate privileges via sending a crafted request. | Jun 15, 2026 |
| CVE-2026-50890 | UNKNOWN | — | Bernd Bestel grocy v4.6.0 was discovered to contain a SQL injection vulnerability in the product-group parameter at /stockreports/spendings. This vulnerability allows attackers to access sensitive … | Jun 15, 2026 |
| CVE-2026-50889 | UNKNOWN | — | An input handling flaw in the HTTP refresh token process of LLDAP v0.6.2 allows attackers to cause a Denial of Service (DoS) via sending a … | Jun 15, 2026 |
| CVE-2026-50888 | UNKNOWN | — | An authenticated Server-Side Request Forgery (SSRF) in the custom scraper subsystem component of Benjamin Jonard Koillection v1.8.0 allows attackers to scan internal resources via supplying … | Jun 15, 2026 |
| CVE-2026-50887 | CRITICAL | 9.1 | A Server-Side Request Forgery (SSRF) in the automatic short URL title resolution component of shlink v5.0.1 allows attackers to scan internal resources via supplying a … | Jun 15, 2026 |