Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

27274
Total
2073
Critical
8258
High
8462
Medium
CVE ID Severity Score Description Published
CVE-2026-45749 HIGH 8.1 Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. The `POST /users/totp/disable` and `POST /users/totp/backup-codes` endpoints in Termix prior … Jun 05, 2026
CVE-2026-45748 CRITICAL 9.8 Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. The `POST /ssh/tunnel/connect` endpoint in Termix prior to version 2.3.2 … Jun 05, 2026
CVE-2026-45746 CRITICAL 9.0 Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to version 2.3.2, the File Manager functionality in Termix … Jun 05, 2026
CVE-2026-45745 HIGH 8.0 Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Starting in version 1.7.0, Termix Desktop (Electron) disables TLS certificate … Jun 05, 2026
CVE-2026-45744 CRITICAL 9.9 Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to version 2.3.2, the GET /ssh/file_manager/ssh/resolvePath endpoint in Termix … Jun 05, 2026
CVE-2026-45743 HIGH 8.1 Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. 16 file-manager endpoints in Termix prior to version 2.3.2 do … Jun 05, 2026
CVE-2026-45327 HIGH 8.2 TinyIce is a streaming server for audio and video. In versions 0.8.95 through 2.4.1, missing authentication on WebRTC ingest endpoint allows unauthenticated stream injection. Version … Jun 05, 2026
CVE-2026-45291 HIGH 7.5 Cloudburst Network provides network components used within Cloudburst projects. A vulnerability in versions prior to `1.0.0.CR3-20260418.124334-32` impacts publicly accessible software depending on the affected versions … Jun 05, 2026
CVE-2026-45290 HIGH 7.5 Cloudburst Network provides network components used within Cloudburst projects. A vulnerability in versions prior to `1.0.0.CR3-20260417.085727-30` impacts publicly accessible software depending on the affected versions … Jun 05, 2026
CVE-2026-36501 UNKNOWN An issue in the Externalizable.readExternal() component of Controller v12.0.5 allows attackers to cause a Denial of Service (DoS) via a crafted input. Jun 05, 2026
CVE-2026-36500 UNKNOWN An issue in the cluster-admin:backup-datastore component of Controller v12.0.5 allows attackers to execute a directory traversal via a crafted request. Jun 05, 2026
CVE-2026-2379 MEDIUM 5.9 On affected platforms with hardware IPSec support running Arista EOS with certain IPsec features enabled, EOS may exhibit unexpected behavior in specific cases. Physical interface … Jun 05, 2026
CVE-2026-11344 HIGH 7.3 A vulnerability was found in code-projects Vehicle Management System 1.0. This impacts an unknown function of the file newdriver.php of the component New Driver Registration … Jun 05, 2026
CVE-2026-11342 HIGH 7.3 A vulnerability has been found in code-projects Hotel and Tourism Reservation System 1.0. This affects an unknown function of the file /details.php. Such manipulation of … Jun 05, 2026
CVE-2026-11341 MEDIUM 6.3 A flaw has been found in D-Link DWR-M920 up to 1.1.50. The impacted element is the function sub_412DA0 of the file /boafrm/formIMEISetup. This manipulation of … Jun 05, 2026
CVE-2025-71318 CRITICAL 9.8 NetMan 204 fails to enforce authentication on its administrative pages and command endpoints. A remote, unauthenticated attacker can directly request administrative pages (such as administration.html, … Jun 05, 2026
CVE-2025-71317 CRITICAL 9.8 NetMan 204 contains a hard-coded backdoor account with the username and password 'eurek' that grants administrative access. A remote, unauthenticated attacker can authenticate through the … Jun 05, 2026
CVE-2026-8714 UNKNOWN A denial-of-service vulnerability exists in the RTSP server component of TP-Link Tapo C520WS v2 due to improper handling of syntactically invalid input. Crafted inputs can … Jun 05, 2026
CVE-2026-7473 MEDIUM 5.8 On affected platforms running Arista EOS where a tunnel decapsulation configuration—such as VXLAN (Virtual Extensible LAN), decap-groups, or a GRE (Generic Routing Encapsulation) tunnel interface—is … Jun 05, 2026
CVE-2026-48112 MEDIUM 6.5 7-Zip is a file archiver with a high compression ratio. Versions 9.18 through 26.00 contain a heap out-of-bounds read in 7-Zip Ar handler BSD SYMDEF … Jun 05, 2026
CVE-2026-48111 MEDIUM 4.3 7-Zip is a file archiver with a high compression ratio. Versions 9.21 through 26.00 contain an off-by-one out-of-bounds read vulnerability in the ParseDepedencyExpression function of … Jun 05, 2026
CVE-2026-48104 MEDIUM 4.2 7-Zip is a file archiver with a high compression ratio. Versions 9.18 through 26.00 contain an uninitialized heap read in the SquashFS archive handler caused … Jun 05, 2026
CVE-2026-48103 MEDIUM 4.3 7-Zip is a file archiver with a high compression ratio. Versions 9.34 through 26.00 contain an off-by-one heap out-of-bounds read in the WIM (Windows Imaging) … Jun 05, 2026
CVE-2026-11339 MEDIUM 6.3 A vulnerability was detected in D-Link DWR-M920 up to 1.1.50. The affected element is the function sub_41CF20 of the file /boafrm/formUSSDSetup. The manipulation of the … Jun 05, 2026
CVE-2026-11338 LOW 2.4 A security vulnerability has been detected in SourceCodester Ship Ferry Ticket Reservation System 1.0. Impacted is an unknown function of the file /admin/?page=user/manage_user. The manipulation … Jun 05, 2026