Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
27118
Total
2050
Critical
8216
High
8419
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-25559 | HIGH | 8.8 | OpenBullet2 through version 0.3.2 contains a path traversal vulnerability in the wordlist endpoint that allows authenticated attackers to perform arbitrary file read, write, and delete … | Jun 08, 2026 |
| CVE-2026-25555 | CRITICAL | 9.8 | OpenBullet2 through version 0.3.2 contains an authentication bypass vulnerability in the API key authentication middleware that allows unauthenticated attackers to gain admin access by supplying … | Jun 08, 2026 |
| CVE-2026-11611 | MEDIUM | 6.5 | A flaw was found in 389 Directory Server. The Content Synchronization persistent search plugin allows unbounded memory growth when an authenticated client stops reading sync … | Jun 08, 2026 |
| CVE-2026-11534 | LOW | 3.5 | A vulnerability was detected in imvks786 student_management_system up to 9599b560ad3c3b83e75d328b76bedcd489ef1f46. Affected by this issue is some unknown functionality of the file /add.php. The manipulation of … | Jun 08, 2026 |
| CVE-2026-11533 | MEDIUM | 5.4 | A security vulnerability has been detected in imvks786 student_management_system up to 9599b560ad3c3b83e75d328b76bedcd489ef1f46. Affected by this vulnerability is an unknown functionality of the file /see.php of … | Jun 08, 2026 |
| CVE-2026-11532 | MEDIUM | 6.3 | A weakness has been identified in imvks786 student_management_system up to 9599b560ad3c3b83e75d328b76bedcd489ef1f46. Affected is an unknown function of the file /add.php of the component Student Record … | Jun 08, 2026 |
| CVE-2026-11531 | HIGH | 7.3 | A security flaw has been discovered in imvks786 student_management_system up to 9599b560ad3c3b83e75d328b76bedcd489ef1f46. This impacts an unknown function of the file admin/admin_login.php of the component Administrator … | Jun 08, 2026 |
| CVE-2026-11530 | HIGH | 7.3 | A vulnerability was identified in imvks786 student_management_system up to 9599b560ad3c3b83e75d328b76bedcd489ef1f46. This affects an unknown function of the file /index.ph of the component Login. Such manipulation … | Jun 08, 2026 |
| CVE-2026-49975 | UNKNOWN | — | Memory Allocation with Excessive Size Value vulnerability in Apache HTTP Server's mod_http leads to denial of service via malicious HTTP requests. This issue affects Apache … | Jun 08, 2026 |
| CVE-2026-49756 | UNKNOWN | — | Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability in wojtekmach Req allows multipart parameter smuggling via attacker-influenced part metadata. Req.Utils.encode_form_part/2 in lib/req/utils.ex builds the per-part … | Jun 08, 2026 |
| CVE-2026-49755 | UNKNOWN | — | Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in wojtekmach Req allows attacker-controlled HTTP servers to exhaust memory in a Req client via decompression-bomb … | Jun 08, 2026 |
| CVE-2026-48913 | HIGH | 7.3 | Use After Free vulnerability in Apache HTTP Server module mod_http2 when file handles are already exhausted. This issue affects Apache HTTP Server: from 2.4.55 through … | Jun 08, 2026 |
| CVE-2026-48488 | UNKNOWN | — | phpMyFAQ is an open source FAQ web application. Prior to version 4.1.4, attachment passwords are hashed using SHA-1, a cryptographically broken algorithm. SHA-1 has been … | Jun 08, 2026 |
| CVE-2026-46657 | HIGH | 7.1 | Bludit is a content management system. Versions prior to 3.22.0 have a vulnerability in the user management logic that allows deactivated accounts to maintain access … | Jun 08, 2026 |
| CVE-2026-46656 | HIGH | 8.8 | Bludit is a content management system. Versions prior to 3.22.0 have a Broken Access Control flaw where active sessions remain valid even after the corresponding … | Jun 08, 2026 |
| CVE-2026-46480 | UNKNOWN | — | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, evaluator create and update mass-assignment … | Jun 08, 2026 |
| CVE-2026-46479 | UNKNOWN | — | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, evaluation create and update mass-assignment … | Jun 08, 2026 |
| CVE-2026-46478 | UNKNOWN | — | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, DatasetRow create and update mass-assignment … | Jun 08, 2026 |
| CVE-2026-46477 | UNKNOWN | — | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, dataset create and update mass-assignment … | Jun 08, 2026 |
| CVE-2026-46476 | UNKNOWN | — | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, CustomTemplate create and update mass-assignment … | Jun 08, 2026 |
| CVE-2026-46475 | UNKNOWN | — | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, assistant create and update mass-assignment … | Jun 08, 2026 |
| CVE-2026-46444 | UNKNOWN | — | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, all CRUD endpoints for OpenAI … | Jun 08, 2026 |
| CVE-2026-46443 | UNKNOWN | — | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, when credentials are fetched with … | Jun 08, 2026 |
| CVE-2026-46442 | UNKNOWN | — | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, POST /api/v1/node-custom-function lacks route-level authorization, … | Jun 08, 2026 |
| CVE-2026-46441 | UNKNOWN | — | Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, a mass assignment vulnerability exists … | Jun 08, 2026 |