Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

28489
Total
2193
Critical
8545
High
8865
Medium
CVE ID Severity Score Description Published
CVE-2026-46620 MEDIUM 6.5 e107 is a content management system (CMS). Prior to 2.3.5, e107 CMS does not properly enforce CSRF token validation on comment moderation actions. The problem … May 26, 2026
CVE-2026-43936 MEDIUM 4.3 e107 is a content management system (CMS). Prior to 2.3.4, you can access the local environment by specifying the URL of the local environment from … May 26, 2026
CVE-2026-43935 HIGH 8.1 e107 is a content management system (CMS). Prior to 2.3.4, a Host Header Injection vulnerability in the password reset page allows attackers to manipulate the … May 26, 2026
CVE-2026-43934 MEDIUM 6.5 e107 is a content management system (CMS). Prior to 2.3.4, a Broken Access Control vulnerability exists in the application, allowing an unauthorized authenticated user to … May 26, 2026
CVE-2026-40564 UNKNOWN Files or Directories Accessible to External Parties, Server-Side Request Forgery (SSRF) vulnerability in Apache Flink Kubernetes Operator. The FlinkSessionJob jarURI is currently not validated so … May 26, 2026
CVE-2026-38587 MEDIUM 4.3 An Insecure Direct Object Reference (IDOR) vulnerability was discovered in ONLYOFFICE DocSpace before 3.2.1. The flaw exists in multiple REST API endpoints. This allows authenticated … May 26, 2026
CVE-2026-25112 HIGH 7.8 A high-severity vulnerability in the deployment of Genetec RabbitMQ that allows a privilege escalation attack. May 26, 2026
CVE-2026-9552 HIGH 7.3 A security flaw has been discovered in Das Parking Management System 停车场管理系统 6.2.0. This vulnerability affects unknown code of the component Search API Endpoint. The … May 26, 2026
CVE-2026-9551 HIGH 7.3 A vulnerability was identified in Das Parking Management System 停车场管理系统 6.2.0. This affects the function xp_cmdshell of the file ParkingRecord/ExportParkingRecords of the component API Endpoint. … May 26, 2026
CVE-2026-9550 HIGH 7.3 A vulnerability was determined in Acrel Electrical EEMS Enterprise Power Operation and Maintenance Cloud Platform 1.3.0. Affected by this issue is some unknown functionality of … May 26, 2026
CVE-2026-4480 HIGH 8.5 A flaw was found in the Samba printing subsystem. Samba passes the client-controlled job description string to the command configured with the "print command" setting … May 26, 2026
CVE-2026-46368 HIGH 8.8 luci-app-https-dns-proxy through 2025.12.29-5 — an optional LuCI web UI add-on for the https-dns-proxy package, distributed through the OpenWrt community packages feed and not installed by … May 26, 2026
CVE-2026-45247 CRITICAL 9.8 Mirasvit Full Page Cache Warmer for Magento 2 before version 1.11.12 contains a PHP object injection vulnerability that allows unauthenticated attackers to achieve remote code … May 26, 2026
CVE-2026-45082 HIGH 7.6 Karakeep is a elf-hostable bookmark-everything app. A Server-Side Request Forgery (SSRF) protection bypass vulnerability was identified in versions prior to 0.32.0 affecting redirect-following processing components. … May 26, 2026
CVE-2026-43919 UNKNOWN Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-43918. Reason: This candidate is a duplicate of CVE-2026-43918. Notes: All CVE users … May 26, 2026
CVE-2026-42785 HIGH 7.2 OpenKM 6.3.12 contains a remote code execution vulnerability that allows authenticated administrators to execute arbitrary Java/BeanShell code through the /admin/Scripting endpoint. Attackers can submit malicious … May 26, 2026
CVE-2026-42425 HIGH 7.2 OpenKM 6.3.12 contains an unrestricted SQL execution vulnerability that allows authenticated administrative users to execute arbitrary SQL statements against the application database via the DatabaseQuery … May 26, 2026
CVE-2026-42347 UNKNOWN Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2026-28496. Reason: This candidate is a duplicate of CVE-2026-28496. Notes: All CVE users … May 26, 2026
CVE-2026-41917 MEDIUM 4.9 OpenKM 6.3.12 contains a local file inclusion vulnerability in the administrative scripting interface at /admin/Scripting that allows authenticated administrators to read arbitrary files by supplying … May 26, 2026
CVE-2026-41401 MEDIUM 6.5 libyang before 5.2.6 contains a heap use-after-free write vulnerability in lyd_parser_set_data_flags that incorrectly updates metadata list pointers when freeing non-head default metadata entries. Attackers can … May 26, 2026
CVE-2026-40034 HIGH 7.8 gix-submodule before 0.82.0 incorrectly validates the update field in .gitmodules, allowing attackers to bypass the CommandForbiddenInModulesConfiguration guard when a submodule has been initialized with only … May 26, 2026
CVE-2026-40033 HIGH 8.8 FreeRDP before 3.26.0 contains a heap-buffer-overflow vulnerability in gdi_CacheToSurface that allows remote attackers to write out-of-bounds heap memory. The vulnerability occurs because rectangle validation clamps … May 26, 2026
CVE-2026-9544 HIGH 7.3 A vulnerability was found in Shenzhen Sixun Software Sixun Shanghui Group Business Management System 10. Affected by this vulnerability is an unknown functionality of the … May 26, 2026
CVE-2026-9543 CRITICAL 9.8 A vulnerability has been found in Totolink N300RH 6.1c.1353_B20190305. Affected is the function setPasswordCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Such … May 26, 2026
CVE-2026-9542 MEDIUM 6.3 A weakness has been identified in CodeAstro Leave Management System 1.0. The affected element is an unknown function of the file /admin/add_staff.php. Executing a manipulation … May 26, 2026