Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

27118
Total
2050
Critical
8216
High
8419
Medium
CVE ID Severity Score Description Published
CVE-2026-11513 MEDIUM 6.3 A vulnerability was detected in itsourcecode Hospital Management System 1.0. Impacted is an unknown function of the file /adminaccount.php. The manipulation of the argument Date … Jun 08, 2026
CVE-2026-11512 MEDIUM 4.3 A security vulnerability has been detected in itsourcecode Hospital Management System 1.0. This issue affects some unknown processing of the file /billing.php. The manipulation of … Jun 08, 2026
CVE-2026-11511 LOW 3.5 A weakness has been identified in Bolt CMS up to 3.7.5. This vulnerability affects unknown code of the file src/Storage/Field/Type/TextType.php of the component HTML Attribute … Jun 08, 2026
CVE-2026-50752 HIGH 7.4 A weakness in the certificate validation logic of the deprecated IKEv1 key exchange may allow an unauthenticated attacker positioned as a man-in-the-middle to bypass certificate … Jun 08, 2026
CVE-2026-50751 CRITICAL 9.3 A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows an unauthenticated remote attacker to bypass user … Jun 08, 2026
CVE-2026-47430 UNKNOWN ## Summary The iOS implementation of `cordova-plugin-inappbrowser` passes the `id` field from a `WKScriptMessage` body to `commandDelegate sendPluginResult:callbackId:` with no format validation (`CDVWKInAppBrowser.m:560–574`). Any web … Jun 08, 2026
CVE-2026-3011 MEDIUM 6.4 The Recipe Card Blocks Lite plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the recipe block's 'summary' and 'notes' attributes in all versions … Jun 08, 2026
CVE-2026-11569 MEDIUM 5.4 A flaw was found in Quay. The filedrop endpoint accepts any mime type without validation, allowing an authenticated user with repository write access to upload … Jun 08, 2026
CVE-2026-11510 MEDIUM 6.3 A security flaw has been discovered in CodeAstro Leave Management System 1.0. This affects an unknown part of the file /admin/add_leave.php. Performing a manipulation of … Jun 08, 2026
CVE-2026-11509 MEDIUM 6.3 A vulnerability was identified in CodeAstro Leave Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/search_staff_for_updation.php. Such manipulation of … Jun 08, 2026
CVE-2026-11508 MEDIUM 6.3 A vulnerability was determined in CodeAstro Leave Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/search_staff_to_assign_pc.php. This manipulation of … Jun 08, 2026
CVE-2026-11507 MEDIUM 6.3 A vulnerability was found in CodeAstro Leave Management System 1.0. Affected is an unknown function of the file /admin/delete_leave_type.php. The manipulation of the argument leave_type … Jun 08, 2026
CVE-2026-11506 MEDIUM 6.3 A vulnerability has been found in CodeAstro Leave Management System 1.0. This impacts an unknown function of the file /admin/search_staff_for_deletion.php. The manipulation of the argument … Jun 08, 2026
CVE-2026-11505 MEDIUM 5.0 A flaw has been found in GL.iNet A1300, AX1800, AXT1800, MT2500, MT3000, MT6000, X3000 and XE3000 4.8.x. This affects an unknown function of the component … Jun 08, 2026
CVE-2026-11504 HIGH 8.8 A vulnerability was detected in Tenda CX12L 16.03.53.12. The impacted element is the function setSchedWifi of the file /goform/openSchedWifi of the component Wi-Fi Schedule Configuration … Jun 08, 2026
CVE-2026-9506 UNKNOWN This vulnerability exists in Bagisto due to improper validation of user-supplied input in the ImageCacheController component. An unauthenticated remote attacker could exploit this vulnerability by … Jun 08, 2026
CVE-2026-11503 HIGH 8.8 A security vulnerability has been detected in Tenda CX12L 16.03.53.12. The affected element is the function form_fast_setting_wifi_set of the file /goform/fast_setting_wifi_set of the component Wi-Fi … Jun 08, 2026
CVE-2026-11502 LOW 3.1 A weakness has been identified in JeecgBoot up to 3.9.2. Impacted is the function HttpServletResponse.sendRedirect of the file jeecg-module-system/jeecg-system-biz/src/main/java/org/jeecg/modules/system/controller/ThirdLoginController.java of the component Third-Party Login. This … Jun 08, 2026
CVE-2026-11501 HIGH 7.3 A security flaw has been discovered in SourceCodester Hospitals Patient Records Management System 1.0. This issue affects some unknown processing of the file /classes/Master.php?f=save_patient. The … Jun 08, 2026
CVE-2026-11500 MEDIUM 5.0 A vulnerability was identified in Weaviate up to 1.37.7. This vulnerability affects the function validateConfig of the file usecases/auth/authentication/apikey/client.go of the component Static API Key … Jun 08, 2026
CVE-2024-56123 UNKNOWN Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Jun 08, 2026
CVE-2024-56122 UNKNOWN Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Jun 08, 2026
CVE-2024-56121 UNKNOWN Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Jun 08, 2026
CVE-2024-56120 UNKNOWN Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Jun 08, 2026
CVE-2026-41724 HIGH 8.0 VMware Cloud Foundation Operations contains multiple stored cross-site scripting vulnerabilities.A malicious actor with privileges to create policies, views or text-widgets may be able to inject … Jun 08, 2026