Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
28489
Total
2193
Critical
8545
High
8865
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-46620 | MEDIUM | 6.5 | e107 is a content management system (CMS). Prior to 2.3.5, e107 CMS does not properly enforce CSRF token validation on comment moderation actions. The problem … | May 26, 2026 |
| CVE-2026-43936 | MEDIUM | 4.3 | e107 is a content management system (CMS). Prior to 2.3.4, you can access the local environment by specifying the URL of the local environment from … | May 26, 2026 |
| CVE-2026-43935 | HIGH | 8.1 | e107 is a content management system (CMS). Prior to 2.3.4, a Host Header Injection vulnerability in the password reset page allows attackers to manipulate the … | May 26, 2026 |
| CVE-2026-43934 | MEDIUM | 6.5 | e107 is a content management system (CMS). Prior to 2.3.4, a Broken Access Control vulnerability exists in the application, allowing an unauthorized authenticated user to … | May 26, 2026 |
| CVE-2026-40564 | UNKNOWN | — | Files or Directories Accessible to External Parties, Server-Side Request Forgery (SSRF) vulnerability in Apache Flink Kubernetes Operator. The FlinkSessionJob jarURI is currently not validated so … | May 26, 2026 |
| CVE-2026-38587 | MEDIUM | 4.3 | An Insecure Direct Object Reference (IDOR) vulnerability was discovered in ONLYOFFICE DocSpace before 3.2.1. The flaw exists in multiple REST API endpoints. This allows authenticated … | May 26, 2026 |
| CVE-2026-25112 | HIGH | 7.8 | A high-severity vulnerability in the deployment of Genetec RabbitMQ that allows a privilege escalation attack. | May 26, 2026 |
| CVE-2026-9552 | HIGH | 7.3 | A security flaw has been discovered in Das Parking Management System 停车场管理系统 6.2.0. This vulnerability affects unknown code of the component Search API Endpoint. The … | May 26, 2026 |
| CVE-2026-9551 | HIGH | 7.3 | A vulnerability was identified in Das Parking Management System 停车场管理系统 6.2.0. This affects the function xp_cmdshell of the file ParkingRecord/ExportParkingRecords of the component API Endpoint. … | May 26, 2026 |
| CVE-2026-9550 | HIGH | 7.3 | A vulnerability was determined in Acrel Electrical EEMS Enterprise Power Operation and Maintenance Cloud Platform 1.3.0. Affected by this issue is some unknown functionality of … | May 26, 2026 |
| CVE-2026-4480 | HIGH | 8.5 | A flaw was found in the Samba printing subsystem. Samba passes the client-controlled job description string to the command configured with the "print command" setting … | May 26, 2026 |
| CVE-2026-46368 | HIGH | 8.8 | luci-app-https-dns-proxy through 2025.12.29-5 — an optional LuCI web UI add-on for the https-dns-proxy package, distributed through the OpenWrt community packages feed and not installed by … | May 26, 2026 |
| CVE-2026-45247 | CRITICAL | 9.8 | Mirasvit Full Page Cache Warmer for Magento 2 before version 1.11.12 contains a PHP object injection vulnerability that allows unauthenticated attackers to achieve remote code … | May 26, 2026 |
| CVE-2026-45082 | HIGH | 7.6 | Karakeep is a elf-hostable bookmark-everything app. A Server-Side Request Forgery (SSRF) protection bypass vulnerability was identified in versions prior to 0.32.0 affecting redirect-following processing components. … | May 26, 2026 |
| CVE-2026-43919 | UNKNOWN | — | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-43918. Reason: This candidate is a duplicate of CVE-2026-43918. Notes: All CVE users … | May 26, 2026 |
| CVE-2026-42785 | HIGH | 7.2 | OpenKM 6.3.12 contains a remote code execution vulnerability that allows authenticated administrators to execute arbitrary Java/BeanShell code through the /admin/Scripting endpoint. Attackers can submit malicious … | May 26, 2026 |
| CVE-2026-42425 | HIGH | 7.2 | OpenKM 6.3.12 contains an unrestricted SQL execution vulnerability that allows authenticated administrative users to execute arbitrary SQL statements against the application database via the DatabaseQuery … | May 26, 2026 |
| CVE-2026-42347 | UNKNOWN | — | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-28496. Reason: This candidate is a duplicate of CVE-2026-28496. Notes: All CVE users … | May 26, 2026 |
| CVE-2026-41917 | MEDIUM | 4.9 | OpenKM 6.3.12 contains a local file inclusion vulnerability in the administrative scripting interface at /admin/Scripting that allows authenticated administrators to read arbitrary files by supplying … | May 26, 2026 |
| CVE-2026-41401 | MEDIUM | 6.5 | libyang before 5.2.6 contains a heap use-after-free write vulnerability in lyd_parser_set_data_flags that incorrectly updates metadata list pointers when freeing non-head default metadata entries. Attackers can … | May 26, 2026 |
| CVE-2026-40034 | HIGH | 7.8 | gix-submodule before 0.82.0 incorrectly validates the update field in .gitmodules, allowing attackers to bypass the CommandForbiddenInModulesConfiguration guard when a submodule has been initialized with only … | May 26, 2026 |
| CVE-2026-40033 | HIGH | 8.8 | FreeRDP before 3.26.0 contains a heap-buffer-overflow vulnerability in gdi_CacheToSurface that allows remote attackers to write out-of-bounds heap memory. The vulnerability occurs because rectangle validation clamps … | May 26, 2026 |
| CVE-2026-9544 | HIGH | 7.3 | A vulnerability was found in Shenzhen Sixun Software Sixun Shanghui Group Business Management System 10. Affected by this vulnerability is an unknown functionality of the … | May 26, 2026 |
| CVE-2026-9543 | CRITICAL | 9.8 | A vulnerability has been found in Totolink N300RH 6.1c.1353_B20190305. Affected is the function setPasswordCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Such … | May 26, 2026 |
| CVE-2026-9542 | MEDIUM | 6.3 | A weakness has been identified in CodeAstro Leave Management System 1.0. The affected element is an unknown function of the file /admin/add_staff.php. Executing a manipulation … | May 26, 2026 |