Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
26832
Total
1978
Critical
8053
High
8297
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-42305 | HIGH | 8.8 | Dulwich is a pure-Python implementation of the Git file formats and protocols. Versions starting with 0.10.0 and prior to 1.2.5 have an arbitrary file write … | Jun 10, 2026 |
| CVE-2024-21944 | MEDIUM | 5.3 | Improper input validation for DIMM serial presence detect (SPD) metadata could allow an attacker with physical access, ring0 access on a system with a non-compliant … | Jun 10, 2026 |
| CVE-2026-53742 | MEDIUM | 5.4 | Simple Link Directory through 9.0.4 echoes embed shortcode attributes into HTML data attributes without escaping in the embedder template. Attackers with contributor access can craft … | Jun 10, 2026 |
| CVE-2026-53741 | MEDIUM | 5.4 | Simple Link Directory through 9.0.4 interpolates the sld_no_results_found option into a JavaScript string literal without encoding. Because sanitize_text_field leaves quotes intact, a stored payload breaks … | Jun 10, 2026 |
| CVE-2026-53740 | MEDIUM | 5.4 | Yoast Duplicate Post through 4.6 inserts an unescaped post title and permalink into the Classic Editor scheduled republish notice. Attackers can schedule a republish copy … | Jun 10, 2026 |
| CVE-2026-53739 | MEDIUM | 4.3 | Yoast Duplicate Post through 4.6 contains a cross-site request forgery vulnerability in the duplicate_post_dismiss_notice handler, which verifies no nonce or capability. Attackers can trick any … | Jun 10, 2026 |
| CVE-2026-53738 | HIGH | 8.1 | Copy & Delete Posts through 1.5.4 lets any plugin-enabled non-admin role invoke every operation in the cdp_action_handling AJAX handler. Attackers with an enabled role can … | Jun 10, 2026 |
| CVE-2026-53737 | MEDIUM | 6.1 | Juicer through 1.12.18 fails to escape remote feed API response fields before rendering them on the admin settings page. Attackers controlling the connected feed data … | Jun 10, 2026 |
| CVE-2026-53736 | MEDIUM | 4.3 | Easy Twitter Feeds before 1.2.13 contains a cross-site request forgery vulnerability in the duplicate_post action handler that lacks nonce verification. Attackers can trick an authenticated … | Jun 10, 2026 |
| CVE-2026-53634 | MEDIUM | 4.3 | Sharp is a content management framework built for Laravel as a package. From version 9.0.0 to before version 9.22.3, the create and store endpoints of … | Jun 10, 2026 |
| CVE-2026-50131 | HIGH | 8.6 | Fedify is a TypeScript library for building federated server apps powered by ActivityPub. Fedify previously addressed SSRF/internal network access in GHSA-p9cg-vqcc-grcx by adding public URL … | Jun 10, 2026 |
| CVE-2026-48110 | HIGH | 7.5 | Russh is a Rust SSH client & server library. From version 0.34.0 to before version 0.61.0, several russh client and server message handlers decoded attacker-controlled … | Jun 10, 2026 |
| CVE-2026-48108 | MEDIUM | 5.3 | Russh is a Rust SSH client & server library. From version 0.34.0-beta.1 to before version 0.61.0, russh did not enforce the SSH identification-string rules as … | Jun 10, 2026 |
| CVE-2026-48107 | MEDIUM | 6.5 | Russh is a Rust SSH client & server library. From version 0.37.0 to before version 0.61.0, in the russh client keyboard-interactive authentication path, a malicious … | Jun 10, 2026 |
| CVE-2026-48011 | LOW | 3.7 | Shopware is an open commerce platform. Prior to versions 6.6.10.18 and 6.7.10.1, an attacker is able to enumerate the usernames of administrator users by performing … | Jun 10, 2026 |
| CVE-2026-46705 | MEDIUM | 5.3 | Russh is a Rust SSH client & server library. From version 0.34.0-beta.1 to before version 0.61.0, the russh server authentication path keeps internal userauth state … | Jun 10, 2026 |
| CVE-2026-46702 | HIGH | 7.5 | Russh is a Rust SSH client & server library. From version 0.34.0 to before version 0.61.1, when SSH compression is enabled, russh accepted compressed packets … | Jun 10, 2026 |
| CVE-2026-46689 | UNKNOWN | — | Kanidm is an identity management platform. Prior to version 1.9.3, a single unauthenticated GET to any /scim/v1/... endpoint with a ?filter= query string of a … | Jun 10, 2026 |
| CVE-2026-46679 | HIGH | 7.5 | libp2p is a JavaScript Implementation of libp2p networking stack. Prior to version 15.0.23, three cooperating omissions in @libp2p/gossipsub allow an unauthenticated single peer to exhaust … | Jun 10, 2026 |
| CVE-2026-46673 | HIGH | 7.5 | Russh is a Rust SSH client & server library. Prior to version 0.60.3, CryptoVec used unchecked capacity growth, unchecked length arithmetic, and unsafe allocation/locking paths. … | Jun 10, 2026 |
| CVE-2026-46669 | UNKNOWN | — | OpenVM is a performant and modular zkVM framework built for customization and extensibility. Prior to version 1.6.0, the openvm-pairing guest library's try_honest_pairing_check function invokes Theorem … | Jun 10, 2026 |
| CVE-2026-46668 | UNKNOWN | — | SpiceDB is an open source database system for creating and managing security-critical application permissions. From version 1.15.0 to before version 1.52.0, caveat structures with nested … | Jun 10, 2026 |
| CVE-2026-46654 | UNKNOWN | — | Plonky3 is a toolkit for polynomial IOPs (PIOPs). Prior to versions 0.4.3 and 0.5.3, an attacker controlling prover-side observations can craft distinct transcripts that produce … | Jun 10, 2026 |
| CVE-2026-46625 | HIGH | 7.5 | JavaScript Cookie is a JavaScript API for handling cookies, client-side. Prior to version 3.0.7, js-cookie's internal assign() helper copies properties with for...in + plain assignment. … | Jun 10, 2026 |
| CVE-2026-46523 | MEDIUM | 6.2 | ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2.23 and 6.9.13-48, a crafted MSL image can trigger … | Jun 10, 2026 |