Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

26401
Total
1955
Critical
7975
High
8228
Medium
CVE ID Severity Score Description Published
CVE-2026-50005 HIGH 7.7 Brickcom cameras ship with default credentials that allows any unauthenticated remote attacker to silently access camera feeds. Jun 11, 2026
CVE-2026-41005 CRITICAL 9.0 Cloud Foundry UAA incorrectly treated XML encryption to the Service Provider (confidentiality) as a substitute for XML signatures from the Identity Provider (authenticity) in two … Jun 11, 2026
CVE-2026-53782 HIGH 7.4 Summarize before 0.17.0 contains a server-side request forgery vulnerability that allows attackers who control a podcast RSS feed to direct the host to fetch transcript … Jun 11, 2026
CVE-2026-53781 MEDIUM 4.3 Summarize before 0.17.0 contains a resource exhaustion vulnerability that allows remote attackers to cause disk exhaustion by serving media responses that bypass the enforced size … Jun 11, 2026
CVE-2026-49973 CRITICAL 9.4 Hermes WebUI before version 0.51.358 contains an improper access control vulnerability that allows unauthenticated remote attackers to hijack initial setup by submitting the _set_password parameter … Jun 11, 2026
CVE-2026-49949 MEDIUM 5.3 CodexBar before 0.33.0 contains a credential forwarding vulnerability that allows network-adjacent attackers to intercept sensitive credentials by issuing cross-origin or HTTP-downgrade redirects to the shared … Jun 11, 2026
CVE-2026-46622 HIGH 8.1 SolidInvoice is an open-source invoicing platform. Prior to version 2.3.17, API tokens used to authenticate all REST API requests are stored as plaintext strings in … Jun 11, 2026
CVE-2026-46489 HIGH 8.1 SolidInvoice is an open-source invoicing platform. Prior to version 2.3.17, the company logo upload feature accepts any file type without validation. An authenticated administrator can … Jun 11, 2026
CVE-2026-45802 UNKNOWN FPDI is a collection of PHP classes that facilitate reading pages from existing PDF documents and using them as templates in FPDF. Prior to version … Jun 11, 2026
CVE-2026-45175 UNKNOWN Idira Endpoint Privilege Manager Agent versions prior to 26.5 exhibit improper access control within internal agent validation processes. A local attacker could potentially bypass built-in … Jun 11, 2026
CVE-2026-12038 UNKNOWN Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. Reason: This candidate was issued in error. Notes: All references and descriptions in this … Jun 11, 2026
CVE-2026-53702 MEDIUM 6.5 A stack buffer overflow flaw was found in the GStreamer H.265 codec parser library (gst-plugins-bad). When parsing a buffering period SEI message, the parser uses … Jun 11, 2026
CVE-2026-53701 MEDIUM 6.5 An out-of-bounds write vulnerability was found in GStreamer's H.266/VVC PPS picture partition parser in gst-plugins-bad. In the multi-slice-in-tile processing of gst_h266_parser_parse_picture_partition() (gsth266parser.c), the loop iterates … Jun 11, 2026
CVE-2026-52860 UNKNOWN Vim is an open source, command line text editor. Prior to version 9.2.0597, Vim's Python omni-completion executes reconstructed function and class definitions from the current … Jun 11, 2026
CVE-2026-52859 UNKNOWN Vim is an open source, command line text editor. Prior to version 9.2.0565, the update_snapshot() function in src/terminal.c copies the visible terminal screen into the … Jun 11, 2026
CVE-2026-52858 UNKNOWN Vim is an open source, command line text editor. Prior to version 9.2.0561, the Python omni-completion script in python3complete.vim for Vim with the +python3 interpreter … Jun 11, 2026
CVE-2026-48547 HIGH 7.3 KanaDojo contains a command injection vulnerability that allows an attacker with pull request access to execute arbitrary shell commands by inserting shell metacharacters into the … Jun 11, 2026
CVE-2026-47250 MEDIUM 6.1 mcp-server-kubernetes is a Model Context Protocol server for Kubernetes cluster management. Prior to version 3.7.0, the kubectl_generic tool in mcp-server-kubernetes passes user-supplied flags directly to … Jun 11, 2026
CVE-2026-47189 UNKNOWN Quest Bot is an opensource modern Discord Bot built for moderation, utilities and support. Prior to version 1.0.5, the AutoMod remove flow looks up and … Jun 11, 2026
CVE-2026-47188 UNKNOWN Quest Bot is an opensource modern Discord Bot built for moderation, utilities and support. Prior to version 1.0.5, the latest release suppresses mentions in several … Jun 11, 2026
CVE-2026-47181 UNKNOWN PenguinMod-BackendApi is the backend api for penguinmod. Prior to version 1.0.0, a NoSQL injection vulnerability in the password reset endpoint allows any authenticated user to … Jun 11, 2026
CVE-2026-47177 UNKNOWN Quest Bot is an opensource modern Discord Bot built for moderation, utilities and support. Prior to version 1.0.4, a user who can configure bot settings … Jun 11, 2026
CVE-2026-47176 UNKNOWN Quest Bot is an opensource modern Discord Bot built for moderation, utilities and support. Prior to version 1.0.4, a user who can configure bot settings … Jun 11, 2026
CVE-2026-47175 UNKNOWN Quest Bot is an opensource modern Discord Bot built for moderation, utilities and support. Prior to version 1.0.4, several moderation commands echo user-controlled reason text … Jun 11, 2026
CVE-2026-47174 UNKNOWN In Duck Site before version 1.0.1, the repository has a deploy workflow that runs after the build workflow completes. The build workflow runs on pull … Jun 11, 2026