Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

27118
Total
2050
Critical
8216
High
8419
Medium
CVE ID Severity Score Description Published
CVE-2026-46440 HIGH 7.5 Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, the checkBasicAuth endpoint validates credentials … Jun 08, 2026
CVE-2026-46275 UNKNOWN In the Linux kernel, the following vulnerability has been resolved: Bluetooth: hci_uart: fix UAFs and race conditions in close and init paths Vulnerabilities leading to … Jun 08, 2026
CVE-2026-46274 UNKNOWN In the Linux kernel, the following vulnerability has been resolved: io-wq: check that the predecessor is hashed in io_wq_remove_pending() io_wq_remove_pending() needs to fix up wq->hash_tail[] … Jun 08, 2026
CVE-2026-44631 CRITICAL 9.8 Buffer Underwrite vulnerability in Apache HTTP Server on crafted regular expressions in the configuration. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users … Jun 08, 2026
CVE-2026-44186 UNKNOWN Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in the mod_proxy_ftp module in Apache HTTP Server with an attacker controlled backend FTP server. This issue … Jun 08, 2026
CVE-2026-44185 HIGH 7.3 Buffer Over-read vulnerability in Apache HTTP Server via outbound OCSP requests to an attacker controlled OCSP server This issue affects Apache HTTP Server: from 2.4.0 … Jun 08, 2026
CVE-2026-44119 UNKNOWN Improper Privilege Management vulnerability in Apache HTTP Server 2.4.67 and earlier allows local .htaccess authors to read files with the privileges of the httpd user. … Jun 08, 2026
CVE-2026-43951 MEDIUM 6.5 Out-of-bounds Read vulnerability in Apache HTTP Server with mod_headers and mod_mime and multiple response languages. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Jun 08, 2026
CVE-2026-42863 UNKNOWN Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, a mass assignment vulnerability exists … Jun 08, 2026
CVE-2026-42862 UNKNOWN Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, a mass assignment vulnerability exists … Jun 08, 2026
CVE-2026-42861 UNKNOWN Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, a mass assignment vulnerability exists … Jun 08, 2026
CVE-2026-42536 HIGH 7.5 Heap-based Buffer Overflow vulnerability in Apache HTTP Server with mod_xml2enc, xml2StartParse, and untrusted content This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users … Jun 08, 2026
CVE-2026-42535 UNKNOWN A path handling issue in mod_dav_fs in Apache 2.4.67 and earlier allows a WebDAV content author to directly manipulate trusted DAV property databases, potentially causing … Jun 08, 2026
CVE-2026-36786 HIGH 7.5 Shenzhen Tenda Technology Co., Ltd Tenda FH451 V1.0.0.9 was discovered to contain a stack overflow in the list1 parameter of the fromDhcpListClient function. This vulnerability … Jun 08, 2026
CVE-2026-34356 HIGH 7.5 Heap-based Buffer Overflow vulnerability in Apache HTTP Server with malicious backend servers and ProxyPassReverseCookie* This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users … Jun 08, 2026
CVE-2026-34355 HIGH 7.5 A buffer overflow in mod_proxy_html in Apache HTTP Server 2.4.67 and earlier allows an attack by an untrusted backend. Users are recommended to upgrade to … Jun 08, 2026
CVE-2026-34194 HIGH 7.1 Software installed and run as a non-privileged user may conduct improper GPU system calls to cause mismanagement of a mapping state maintained for a sparse … Jun 08, 2026
CVE-2026-29170 MEDIUM 6.1 A cross-site scripting vulnerability exists in mod_proxy_ftp's HTML directory list generation in Apache HTTP Server 2.4.67 and earlier when listing FTP directory contents either via … Jun 08, 2026
CVE-2026-29167 UNKNOWN Use After Free vulnerability in Apache HTTP Server with mod_ldap in per-directory configuration This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67. Users are … Jun 08, 2026
CVE-2026-22164 HIGH 7.5 Software installed and run as a non-privileged user may conduct improper GPU system calls to corrupt kernel heap memory. By creating resources of certain types … Jun 08, 2026
CVE-2026-11529 MEDIUM 6.3 A vulnerability was determined in designcomputer mysql-mcp-server up to 0.2.2. The impacted element is the function read_resource of the file src/mysql_mcp_server/server.py of the component mysql … Jun 08, 2026
CVE-2026-11528 HIGH 8.8 A vulnerability was found in Tenda AC18 15.03.05.05. The affected element is the function sub_45304 of the file /goform/getRebootStatus of the component Web Management Interface. … Jun 08, 2026
CVE-2026-11524 HIGH 8.8 A vulnerability has been found in Tenda W20E 15.11.0.6. Impacted is the function modifyWifiFilterRules of the file /goform/modifyWifiFilterRules of the component Web Management Interface. The … Jun 08, 2026
CVE-2026-11523 HIGH 8.8 A flaw has been found in Tenda W20E 15.11.0.6. This issue affects the function formPortalAuth of the file /goform/PortalAuth of the component Web Management Interface. … Jun 08, 2026
CVE-2026-11522 HIGH 8.8 A vulnerability was detected in Tenda W20E 15.11.0.6. This vulnerability affects the function formSetPortMirror of the file /goform/setPortMirror. Performing a manipulation of the argument portMirrorMirroredPorts … Jun 08, 2026