Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

28490
Total
2193
Critical
8546
High
8865
Medium
CVE ID Severity Score Description Published
CVE-2026-9542 MEDIUM 6.3 A weakness has been identified in CodeAstro Leave Management System 1.0. The affected element is an unknown function of the file /admin/add_staff.php. Executing a manipulation … May 26, 2026
CVE-2026-9541 MEDIUM 5.3 A security flaw has been discovered in Squirrel up to 3.2. Impacted is the function ReadObject of the file squirrel/sqobject.cpp of the component Cnut File … May 26, 2026
CVE-2026-9540 MEDIUM 5.3 A vulnerability was identified in vllm-project vllm 0.19.0. This issue affects some unknown processing of the component OpenAI-compatible Serving Path. Such manipulation leads to denial … May 26, 2026
CVE-2026-8479 UNKNOWN IEC 60870-5-104 used in bidirectional mode in RTU500 is vulnerable for a NULL pointer dereferencing, if a specially crafted sequence of messages is sent for … May 26, 2026
CVE-2026-8174 MEDIUM 5.7 Zohocorp Zoho Mail wordpress plugin is vulnerable to Cross-Site request forgery (CSRF). This issue affects Zoho Mail wordpress plugin versions before 1.6.2. May 26, 2026
CVE-2026-7374 CRITICAL 9.9 A flaw was found in KubeVirt's virt-handler component. This vulnerability allows an authenticated OpenShift user with edit permissions in a single namespace to exploit improper … May 26, 2026
CVE-2026-7310 UNKNOWN A heap-based buffer overflow vulnerability exists in XML parser functionality in the HiDraw. An authenticated malicious user with local access can exploit this vulnerability using … May 26, 2026
CVE-2026-48136 MEDIUM 4.1 When Compliance is enabled on Check Point Multi-Domain Management, an authenticated administrator with read-write access to one Management Domain (CMA) can modify stored metadata associated … May 26, 2026
CVE-2026-48135 MEDIUM 5.3 A Check Point HTTP-based service can incorrectly handle malformed HTTP requests. The issue is related to HTTP request parsing and validation. May 26, 2026
CVE-2026-48134 MEDIUM 5.6 When the DLP is active, the UserCheck Web Portal contains an input-handling issue in the UserChoice flow. Under specific conditions, an attacker who can access … May 26, 2026
CVE-2026-48133 HIGH 7.5 When the Identity Awareness blade is enabled with Browser-Based Authentication, an unauthenticated user may be able to read certain internal files on the Security Gateway. May 26, 2026
CVE-2026-48132 HIGH 8.1 The Security Gateway does not correctly validate a length value in certain IKE packets when NAT-T is used (4500/UDP). As a result, a specially crafted … May 26, 2026
CVE-2026-48131 HIGH 8.1 The VPN service may mishandle an unexpected IKE fragment value received on the IKE port 500/UDP during the early stage of a connection attempt. This … May 26, 2026
CVE-2025-11482 HIGH 7.5 An Allocation of Resources Without Limits or Throttling vulnerability in the OPC-UA Server used in PPT30 Operating System versions before 1.8.0 may be used by … May 26, 2026
CVE-2026-44410 LOW 3.8 This vulnerability stems from a business logic flaw.Attackers can exploit legitimate application functions in unintended and abnormal ways, deviating from the designer's expectations, to carry … May 26, 2026
CVE-2026-39661 HIGH 7.5 Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Magentech SW Core allows PHP Local File Inclusion. This … May 26, 2026
CVE-2026-39642 MEDIUM 5.3 Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in SpabRice Nyla allows Code Injection. This issue affects Nyla: from n/a … May 26, 2026
CVE-2026-27427 MEDIUM 6.5 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dylan Kuhn Geo Mashup allows Stored XSS. This issue affects Geo Mashup: from … May 26, 2026
CVE-2026-25713 HIGH 7.8 MediaArea MediaInfoLib ID3v2 parsing heap buffer overflow vulnerability May 26, 2026
CVE-2026-25104 HIGH 7.8 MediaArea MediaInfoLib LXF parsing heap-based buffer overflow vulnerability May 26, 2026
CVE-2026-24638 MEDIUM 4.3 Missing Authorization vulnerability in Webful Creations RepairBuddy allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects RepairBuddy: from n/a through 4.1121. May 26, 2026
CVE-2026-24590 MEDIUM 5.3 Missing Authorization vulnerability in VideoWhisper.Com Paid Videochat Turnkey Site allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Paid Videochat Turnkey Site: from … May 26, 2026
CVE-2026-8047 HIGH 7.5 The affected products perform improper length checking when parsing incoming HTTP requests, resulting in a size-limited out-of-bounds write. An unauthenticated remote attacker can exploit this … May 26, 2026
CVE-2026-8046 HIGH 8.1 The affected products insufficiently verify authorization when deleting user accounts. An authenticated, low-privileged remote user can exploit this vulnerability to delete other users, including those … May 26, 2026
CVE-2026-44469 HIGH 7.8 The affected product extracts installation files to a temporary directory with incorrect default permissions during administrative installation. A low-privileged local attacker can exploit a TOCTOU … May 26, 2026