Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

27197
Total
2065
Critical
8240
High
8439
Medium
CVE ID Severity Score Description Published
CVE-2026-11528 HIGH 8.8 A vulnerability was found in Tenda AC18 15.03.05.05. The affected element is the function sub_45304 of the file /goform/getRebootStatus of the component Web Management Interface. … Jun 08, 2026
CVE-2026-11524 HIGH 8.8 A vulnerability has been found in Tenda W20E 15.11.0.6. Impacted is the function modifyWifiFilterRules of the file /goform/modifyWifiFilterRules of the component Web Management Interface. The … Jun 08, 2026
CVE-2026-11523 HIGH 8.8 A flaw has been found in Tenda W20E 15.11.0.6. This issue affects the function formPortalAuth of the file /goform/PortalAuth of the component Web Management Interface. … Jun 08, 2026
CVE-2026-11522 HIGH 8.8 A vulnerability was detected in Tenda W20E 15.11.0.6. This vulnerability affects the function formSetPortMirror of the file /goform/setPortMirror. Performing a manipulation of the argument portMirrorMirroredPorts … Jun 08, 2026
CVE-2025-71315 UNKNOWN In the Linux kernel, the following vulnerability has been resolved: drm/vkms: Convert to DRM's vblank timer Replace vkms' vblank timer with the DRM implementation. The … Jun 08, 2026
CVE-2020-37248 MEDIUM 6.5 OfflineIMAP before 8.0.3 trusts the server with their STARTTLS capability prior to authentication, which allows STRIPTLS/man-in-the-middle attacks, taking over the connection and extracting account credentials … Jun 08, 2026
CVE-2026-49235 UNKNOWN When Routinator encounters a file via RRDP using a specifically crafted Document Type Definition, Routinator crashes. Jun 08, 2026
CVE-2026-49234 UNKNOWN When sending a specifically crafted non-UTF-8 string as select-asn query parameter to the /api/v1/origins endpoint, Routinator crashes. This only affects users who allow API access … Jun 08, 2026
CVE-2026-49233 UNKNOWN Routinator does not properly check the module component of rsync URIs, which are used to create the file system paths for the Routinator cache. This … Jun 08, 2026
CVE-2026-49232 UNKNOWN Routinator exits on any error when accepting incoming HTTP or RTR connections, including ones it can recover from such as running out of file descriptors. … Jun 08, 2026
CVE-2026-43974 UNKNOWN Unexpected Status Code or Return Value vulnerability in ninenines gun (gun_http module) allows a malicious HTTP server to force the client into raw protocol mode … Jun 08, 2026
CVE-2026-43973 UNKNOWN Uncontrolled Resource Consumption vulnerability in ninenines gun (gun_http module) allows a malicious server to exhaust client memory via unbounded HTTP/1.1 response buffering. In gun_http:handle/5, three … Jun 08, 2026
CVE-2026-43972 UNKNOWN Origin Validation Error vulnerability in ninenines gun (gun_http2 module) allows cross-origin cookie injection via unvalidated HTTP/2 PUSH_PROMISE authority. In gun_http2:push_promise_frame/7, the :authority pseudo-header from an … Jun 08, 2026
CVE-2026-36789 HIGH 7.5 Shenzhen Tenda Technology Co., Ltd Tenda AC1206 v15.03.06.23 was discovered to contain multiple stack overflows in the fromGstDhcpSetSer function via the username and password parameters. … Jun 08, 2026
CVE-2026-25558 MEDIUM 4.8 QloApps through 1.7.0 contains a stored cross-site scripting vulnerability in the admin file manager that allows authenticated administrators to inject malicious JavaScript by uploading crafted … Jun 08, 2026
CVE-2026-11521 MEDIUM 6.3 A security vulnerability has been detected in Mohammed-eid35 bank-management-system-springboot up to 7b9bcc65ad7df3db29af71aed9bb500e5f24d948. This affects an unknown part of the file src/main/java/com/alien/bank/management/system/controller/TransactionController.java of the component Transaction … Jun 08, 2026
CVE-2026-11520 LOW 3.5 A weakness has been identified in SourceCodester Inventory System 1.0. Affected by this issue is some unknown functionality of the file header.php. This manipulation causes … Jun 08, 2026
CVE-2026-11519 MEDIUM 6.3 A security flaw has been discovered in SourceCodester Inventory System 1.0. Affected by this vulnerability is an unknown functionality of the file /Product_Inventory/api/users_handler.php of the … Jun 08, 2026
CVE-2026-11518 MEDIUM 4.3 A vulnerability was identified in SourceCodester Inventory System 1.0. Affected is an unknown function of the file /users.php of the component User Management Page. The … Jun 08, 2026
CVE-2026-11517 HIGH 8.8 A vulnerability was determined in UTT HiPER 2610G up to 3.0.0-171107. This impacts the function strcpy of the file /goform/formConfigDnsFilterGlobal. Executing a manipulation of the … Jun 08, 2026
CVE-2026-11516 MEDIUM 5.5 A vulnerability was found in UTT HiPER 2610G up to 3.0.0-171107. This affects the function strcpy of the file /goform/formNatStaticMap. Performing a manipulation of the … Jun 08, 2026
CVE-2026-9549 MEDIUM 4.8 Stored cross-site scripting in the service discovery active check output in Checkmk <2.5.0p5, <2.4.0p31, <2.3.0p48, and all 2.2.0 versions allows an administrator who can configure … Jun 08, 2026
CVE-2026-8833 UNKNOWN Improper neutralization of HTML-encoded characters in the URL validation function in Checkmk <2.5.0p5, <2.4.0p31, <2.3.0p48, and all 2.2.0 versions allows an authenticated user to bypass … Jun 08, 2026
CVE-2026-8078 MEDIUM 4.8 Stored cross-site scripting in the global settings change log in Checkmk <2.5.0p5, <2.4.0p31, <2.3.0p48, and all 2.2.0 versions allows an administrator who can change global … Jun 08, 2026
CVE-2026-7765 UNKNOWN Incorrect authorization in the User Messages dashboard widget in Checkmk <2.5.0p5 causes the message-fetching endpoints to return the dashboard creator's messages rather than the viewer's, … Jun 08, 2026