Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

27197
Total
2065
Critical
8240
High
8439
Medium
CVE ID Severity Score Description Published
CVE-2026-45409 UNKNOWN Internationalized Domain Names in Applications (IDNA) for Python provides support for Internationalized Domain Names in Applications (IDNA) and Unicode IDNA Compatibility Processing. In versions prior … Jun 05, 2026
CVE-2026-11431 UNKNOWN A path traversal vulnerability exists in the Projects Service download endpoint shared by Altium Enterprise Server and Altium 365. An authenticated user can supply a … Jun 05, 2026
CVE-2026-11429 UNKNOWN A path traversal vulnerability exists in the Git Service component shared by Altium Enterprise Server and Altium 365. The service accepts a sequence of post-clone … Jun 05, 2026
CVE-2026-11424 UNKNOWN A server-side request forgery (SSRF) vulnerability exists in a GraphQL service component shared by Altium Enterprise Server and Altium 365. An authenticated user can submit … Jun 05, 2026
CVE-2026-11416 HIGH 8.1 MoviePilot contains a path traversal vulnerability in the AliPan, U115, and Rclone cloud storage download handlers where the local destination path is constructed by concatenating … Jun 05, 2026
CVE-2026-36785 UNKNOWN Shenzhen Tenda Technology Co., Ltd Tenda FH451 V1.0.0.9 was discovered to contain a stack overflow in the page parameter of the fromDhcpListClient function. This vulnerability … Jun 05, 2026
CVE-2026-11423 UNKNOWN A path traversal vulnerability exists in the Altium Enterprise Server Collaboration Service due to improper handling of user-supplied filenames in the MCAD and Simulation file … Jun 05, 2026
CVE-2026-11422 HIGH 7.1 Markdown Preview Enhanced 0.8.x with crossnote engine 0.9.28 contains a code injection vulnerability in the WaveDrom rendering pipeline that allows attackers to execute arbitrary JavaScript … Jun 05, 2026
CVE-2026-46493 HIGH 7.5 HAX CMS helps manage microsite universe with PHP or NodeJs backends. Versions prior to 26.0.1 use `uniqid` for generating salts, which is unsuitable. Version 26.0.1 … Jun 05, 2026
CVE-2026-46401 UNKNOWN HAX CMS helps manage microsite universe with PHP or NodeJs backends. Versions prior to 26.0.0 suffer from an improper session termination vulnerability where authentication tokens … Jun 05, 2026
CVE-2026-46400 UNKNOWN HAX CMS helps manage microsite universe with PHP or NodeJs backends. Starting in version 11.0.6 and prior to version 25.0.0, the file upload functionality in … Jun 05, 2026
CVE-2026-46398 UNKNOWN HAX CMS helps manage microsite universe with PHP or NodeJs backends. Starting in version 25.0.0 and prior to version 26.0.0, the haxcms_refresh_token cookie is set … Jun 05, 2026
CVE-2026-46397 MEDIUM 6.5 HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to version 26.0.0, an Authenticated Local File Inclusion (LFI) vulnerability in the HAXCMS … Jun 05, 2026
CVE-2026-46357 MEDIUM 6.5 HAX CMS helps manage microsite universe with PHP or NodeJs backends. Prior to version 26.0.0, the HAX CMS NodeJS application crashes when an authenticated attacker … Jun 05, 2026
CVE-2026-45779 UNKNOWN OpenXDMoD is an open framework for collecting and analyzing HPC metrics. An SQL injection vulnerability exists in Open XDMoD versions prior to 10.0.3 that allows … Jun 05, 2026
CVE-2026-45778 UNKNOWN OpenXDMoD is an open framework for collecting and analyzing HPC metrics. Prior to version 11.0.3, an authenticated attacker can inject malicious JavaScript into their Open … Jun 05, 2026
CVE-2026-45777 UNKNOWN OpenXDMoD is an open framework for collecting and analyzing HPC metrics. Starting in version 9.5.0 and prior to version 11.0.3, an attacker can remotely execute … Jun 05, 2026
CVE-2026-45776 UNKNOWN OpenXDMoD is an open framework for collecting and analyzing HPC metrics. Prior to version 11.0.3, a flaw in Open XDMoD's access control logic allows an … Jun 05, 2026
CVE-2026-45758 CRITICAL 9.6 Guardrails AI is a Python framework that helps build AI applications. On May 11, 2026 at approximately 6:00 PM Pacific, an attacker published a malicious … Jun 05, 2026
CVE-2026-45300 HIGH 7.4 The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Versions on the 2.x branch prior to 2.15.0 … Jun 05, 2026
CVE-2026-25624 MEDIUM 5.7 An administrative cross-site scripting (XSS) vulnerability exists in the web user interface dashboard layout of Arista Edge Threat Management - Arista Next Generation Firewall (NGFW). … Jun 05, 2026
CVE-2026-25623 MEDIUM 6.0 An input validation command execution vulnerability exists in the browser management pipeline of Arista Edge Threat Management - Arista Next Generation Firewall (NGFW). Authenticated administrators … Jun 05, 2026
CVE-2026-25622 MEDIUM 6.0 A Captive Portal Custom Handler command injection vulnerability exists in Arista Edge Threat Management - Arista Next Generation Firewall (NGFW). On affected platforms, an administrative … Jun 05, 2026
CVE-2026-25621 MEDIUM 6.0 A Reports application infrastructure vulnerability exists in Arista Edge Threat Management - Arista Next Generation Firewall (NGFW) due to insecure input validation. This issue uniquely … Jun 05, 2026
CVE-2026-25620 MEDIUM 6.0 An encrypted password command injection vulnerability exists in the Captive Portal application framework of Arista Edge Threat Management - Arista Next Generation Firewall (NGFW). This … Jun 05, 2026