Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
26395
Total
1955
Critical
7973
High
8225
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-45388 | CRITICAL | 9.1 | In OCaml-TLS before 2.1.0, the client implementation does insufficient checks of the certificate provided by the server, which allows impersonation with certificates that are not … | Jun 15, 2026 |
| CVE-2026-41708 | HIGH | 7.5 | In Spring Cloud Sleuth, it is possible for a user to provide specially crafted calls that may cause a denial-of-service (DoS) condition. The application is … | Jun 15, 2026 |
| CVE-2026-39197 | UNKNOWN | — | An issue in the /util/http/prelude.rs endpoint of Datadog, Inc Vector v0.54.0 allows attackers to cause a Denial of Service (DoS) via a crafted request or … | Jun 15, 2026 |
| CVE-2026-39196 | CRITICAL | 9.8 | Datadog, Inc Vector v0.54.0 was discovered to contain a SQL injection vulnerability in the set_uri_query parameter in the KeyPartitioner::partition function. This vulnerability allows attackers to … | Jun 15, 2026 |
| CVE-2026-39118 | UNKNOWN | — | An issue in Iru, Inc Kandji Agent before v.4.7.5(5374) allows a local attacker to escalate privileges via a client validation gap to invoke restricted agent … | Jun 15, 2026 |
| CVE-2026-39007 | HIGH | 7.5 | An issue in Observeinc's Observe v.2026-01-28 and before allows a remote attacker to obtain sensitive information via the CSV Log export component. | Jun 15, 2026 |
| CVE-2026-39006 | CRITICAL | 9.8 | An issue in SNMP4J-Agent 3.8.3 allows a remote attacker to execute arbitrary code via the snmp4jCfgStoragePath component. | Jun 15, 2026 |
| CVE-2026-38812 | CRITICAL | 9.8 | RuoYi v4.8.2 is vulnerable to SQL Injection via the /tool/gen/createTable endpoint. The issue affects the code generation module and may allow an authenticated attacker with … | Jun 15, 2026 |
| CVE-2026-38329 | CRITICAL | 9.8 | Bludit CMS before version 3.18.4 allows Remote Code Execution (RCE) via the API Plugin. The POST /api/files/{key} endpoint in bl-plugins/api/plugin.php fails to perform authorization checks … | Jun 15, 2026 |
| CVE-2026-38065 | UNKNOWN | — | Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_ims_on_with_apn via the ims_apn parameter. | Jun 15, 2026 |
| CVE-2026-38064 | UNKNOWN | — | Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_dial_call via the dialNumber parameter. | Jun 15, 2026 |
| CVE-2026-38063 | UNKNOWN | — | Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_radio_on_with_ia_apn via the ia parameter. | Jun 15, 2026 |
| CVE-2026-38062 | UNKNOWN | — | Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_set_rat_mode via the ratMode parameter. | Jun 15, 2026 |
| CVE-2026-38061 | UNKNOWN | — | Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_set_volume via the volume parameter. | Jun 15, 2026 |
| CVE-2026-38060 | UNKNOWN | — | Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_unlock_sim via the pin parameter. | Jun 15, 2026 |
| CVE-2026-37216 | UNKNOWN | — | Ruoyi 4.8.2 is vulnerable to Cross Site Scripting (XSS) at the interface /system/notice/add. | Jun 15, 2026 |
| CVE-2026-36933 | MEDIUM | 6.8 | An issue in Boyleep K11, y108 firmware v.2.3.0.11291 allows a physically proximate attacker to execute arbitrary code via the factory test feature. | Jun 15, 2026 |
| CVE-2026-36670 | HIGH | 8.8 | A Time-Based Blind SQL Injection vulnerability in the alias_management module of OpenSIPS Control Panel (opensips-cp) prior to version 9.3.3 allows authenticated attackers to execute arbitrary … | Jun 15, 2026 |
| CVE-2026-36537 | CRITICAL | 9.8 | ThingsBoard v4.3.0.1 is vulnerable to an authentication bypass during the OAuth authorization code exchange. The application improperly trusts user-supplied identity data within the user parameter … | Jun 15, 2026 |
| CVE-2026-36521 | UNKNOWN | — | PublicCMS V5.202506.d has a Cross Site Scripting (XSS) vulnerability in the site configuration management module. | Jun 15, 2026 |
| CVE-2026-36213 | HIGH | 7.8 | An issue in Microvirt MEmu Android Emulator 9.2.7.0 allows a local attacker to escalate privileges via the MemuService.exe component. | Jun 15, 2026 |
| CVE-2026-30121 | CRITICAL | 9.1 | remotion-dev remotion v4.0.409 was discovered to contain an arbitrary file write vulnerability. | Jun 15, 2026 |
| CVE-2026-30120 | CRITICAL | 9.8 | remotion-dev remotion v4.0.409 was discovered to contain a remote code execution (RCE) vulnerability. | Jun 15, 2026 |
| CVE-2026-11931 | MEDIUM | 5.5 | Incorrect default permissions in Kiro IDE on macOS and Linux before version 0.11.133 could expose the authentication token cache file to other local users or … | Jun 15, 2026 |
| CVE-2025-70102 | MEDIUM | 6.3 | A NULL pointer dereference occurs in Roy Marples NetworkConfiguration/dhcpcd 10.3.0 while parsing configuration options. In parse_option() (src/if-options.c:1886), the code performs a member access on a … | Jun 15, 2026 |