Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
26395
Total
1955
Critical
7973
High
8225
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-50886 | CRITICAL | 9.1 | Incorrect access control in the webhook management component of Project Firefly III v6.5.9 allows attackers to scan internal resources via a crafted POST request. | Jun 15, 2026 |
| CVE-2026-50885 | HIGH | 7.5 | Incorrect access control in the share-based read endpoints of Sismics Docs (Teedy) v1.11 allow unauthorized attackers to access sensitive endpoints via a crafted request. | Jun 15, 2026 |
| CVE-2026-50884 | UNKNOWN | — | Incorrect access control in statping-ng v0.93.0 allows attackers to escalate privileges to Administrator and access sensitive components. | Jun 15, 2026 |
| CVE-2026-50883 | CRITICAL | 9.6 | An HTML injection vulnerability in the /src/highlight.rs component of matze wastebin v3.4.1 allows attackers to execute arbitrary scripts via a crafted payload. | Jun 15, 2026 |
| CVE-2026-50882 | HIGH | 7.5 | An issue in the /api/v0/pastes endpoint of anna-is-cute paste v0.1.1 allows attackers to cause a Denial of Service (DoS) via a crafted POST request. | Jun 15, 2026 |
| CVE-2026-50881 | UNKNOWN | — | Incorrect access control in the impworks Bonsai v6.0 allows authenticated attackers with Editor privileges to escalate privileges to Administrator and execute unauthorized account, password, and … | Jun 15, 2026 |
| CVE-2026-50880 | CRITICAL | 9.8 | An issue in the sendmail transport integration component of YouTransfer v1.0.6 allows attackers to execute arbitrary code via supplying a crafted request. | Jun 15, 2026 |
| CVE-2026-50879 | HIGH | 7.5 | An issue in the uploadPostHandler component of Andrei Marcu linx-server v2.3.8 allows attackers to cause a Denial of Service (DoS) via a crafted POST request. | Jun 15, 2026 |
| CVE-2026-50878 | HIGH | 7.5 | An issue in the attachment handling component of Feuerhamster MailForm v1.1.0 allows attackers to cause a Denial of Service (DoS) via a crafted request. | Jun 15, 2026 |
| CVE-2026-50877 | HIGH | 7.5 | An issue in Zhoros SuperBin v1.0.0 allows attackers to execute a directory traversal via supplying files with names containing traversal characters. | Jun 15, 2026 |
| CVE-2026-50876 | UNKNOWN | — | A cross-site scripting (XSS) vulnerability in Deck9 Input v2.0.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload. | Jun 15, 2026 |
| CVE-2026-50875 | UNKNOWN | — | Incorrect access control in the /{form}/webhooks/{webhook} endpoint of Deck9 Input v2.0.1 allows authenticated attackers to arbitrarily modify or delete another tenant's webhook via a crafted … | Jun 15, 2026 |
| CVE-2026-50874 | UNKNOWN | — | An OS command injection vulnerability in the /manage/features/media component of kanishka-linux Reminiscence v0.3.0 allows attackers to execute arbitrary commands via supplying a crafted input. | Jun 15, 2026 |
| CVE-2026-50873 | CRITICAL | 9.8 | An arbitrary file upload vulnerability in the attachment handling component of flatnotes v5.5.4 allows attackers to execute arbitrary code via uploading a crafted HTML or … | Jun 15, 2026 |
| CVE-2026-50872 | CRITICAL | 9.8 | An issue in the loopback request handling component of fossar selfoss v2.20-SNAPSHOT allows attackers to execute arbitrary commands and obtain sensitive information via supplying a … | Jun 15, 2026 |
| CVE-2026-50871 | CRITICAL | 9.8 | An OS command injection vulnerability in the media archiving and export pipeline component of kanishka-linux Reminiscence v0.3.0 allows attackers to execute arbitrary commands via supplying … | Jun 15, 2026 |
| CVE-2026-50870 | HIGH | 7.5 | An information disclosure vulnerability in the configuration endpoint of Ben Busby whoogle-search v1.2.3 allows attackers to obtain sensitive information via a crafted GET request. | Jun 15, 2026 |
| CVE-2026-50869 | CRITICAL | 9.8 | An issue in the api/plugin.php component of Bludit v3.19.0 allows attackers to execute a directory traversal via supplying a crafted request. | Jun 15, 2026 |
| CVE-2026-49954 | HIGH | 7.2 | Discuz! X5.0 releases 20260320 through 20260610 contain a local file inclusion vulnerability that allows authenticated administrators to execute arbitrary code by importing a specially crafted … | Jun 15, 2026 |
| CVE-2026-49953 | MEDIUM | 6.5 | Discuz! X5.0 releases 20260320 through 20260610 contains a CAPTCHA bypass vulnerability that allows unauthenticated remote attackers to defeat challenge controls by exploiting limited complexity and … | Jun 15, 2026 |
| CVE-2026-49952 | CRITICAL | 9.1 | Discuz! X5.0 releases 20260320 through 20260501 contains an authentication bypass vulnerability that allows unauthenticated remote attackers to gain unauthorized access to database backup and restore … | Jun 15, 2026 |
| CVE-2026-48114 | CRITICAL | 9.8 | Metacat is data repository software that helps researchers preserve, share, and discover data. Versions 2.0.0 and and above contain an unauthenticated SQL injection in the … | Jun 15, 2026 |
| CVE-2026-47835 | HIGH | 8.6 | In Spring AI Vector Stores, special characters could be used to force the execution of arbitrary queries in Elasticsearch, OpenSearch, and GemFire VectorDB. Affected components: … | Jun 15, 2026 |
| CVE-2026-45390 | CRITICAL | 9.1 | In OCaml-tar before 3.4.0, a crafted archive with ../ path segments in its name allows escaping the current working directory. This is not desired behavior, … | Jun 15, 2026 |
| CVE-2026-45389 | CRITICAL | 9.1 | In OCaml-TLS before 2.1.0, the server implementation does insufficient checks of the certificate provided by the client (when doing client authentication), which allows impersonation with … | Jun 15, 2026 |