Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

24621
Total
1725
Critical
7573
High
7749
Medium
CVE ID Severity Score Description Published
CVE-2026-10620 HIGH 7.3 A flaw has been found in code-projects Student Admission System 1.0. Affected is an unknown function of the file /index.php. This manipulation of the argument … Jun 02, 2026
CVE-2026-10619 HIGH 7.3 A vulnerability was detected in sayan365 student-management-system up to 7f3c9ce7d410332335c2affac93a385485051800. This impacts an unknown function. The manipulation results in improper authentication. The attack can be … Jun 02, 2026
CVE-2026-8036 HIGH 7.1 Improper input validation in NI-PAL may allow a local authenticated user to access arbitrary system memory, potentially leading to privilege escalation. This vulnerability affects NI-PAL … Jun 02, 2026
CVE-2026-8035 HIGH 7.1 Improper input validation in the NI-PAL kernel driver may allow a local authenticated user to cause a denial of service by triggering a crash due … Jun 02, 2026
CVE-2026-5385 UNKNOWN An unauthenticated user with write access to the knowledge base can store an XSS payload in a knowledge base item. This issue affects glpi: before … Jun 02, 2026
CVE-2026-5076 CRITICAL 9.8 The ARMember Premium plugin for WordPress is vulnerable to an insecure password reset mechanism in all versions up to, and including, 7.3.1. The plugin stores … Jun 02, 2026
CVE-2026-5074 MEDIUM 6.5 The ARMember Premium plugin for WordPress is vulnerable to SQL Injection via the 'sSortDir_0' parameter of the `get_private_content_data` AJAX action in all versions up to, … Jun 02, 2026
CVE-2026-5073 HIGH 7.5 The ARMember Premium plugin for WordPress is vulnerable to SQL Injection via the 'order' parameter of the 'arm_directory_paging_action' AJAX action in all versions up to, … Jun 02, 2026
CVE-2026-49120 HIGH 8.5 Medplum before 5.1.14 contains a server-side request forgery vulnerability in the subscription worker that allows authenticated users to perform unauthorized internal network requests by creating … Jun 02, 2026
CVE-2026-48682 UNKNOWN FastNetMon Community Edition through 1.2.9 contains an out-of-bounds read in the IPv4 packet parser. In src/simple_packet_parser_ng.cpp, after validating that the packet contains at least sizeof(ipv4_header_t) … Jun 02, 2026
CVE-2026-48598 UNKNOWN Improper Encoding or Escaping of Output vulnerability in elixir-tesla tesla allows multipart part header injection via unescaped Content-Disposition parameter values. Tesla.Multipart.part_headers_for_disposition/1 interpolates each disposition parameter … Jun 02, 2026
CVE-2026-48597 UNKNOWN Allocation of Resources Without Limits or Throttling vulnerability in elixir-tesla tesla allows denial of service via atom table exhaustion in Tesla.Adapter.Mint. Tesla.Adapter.Mint.open_conn/2 converts the URL … Jun 02, 2026
CVE-2026-48596 UNKNOWN Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Request/Response Splitting') vulnerability in elixir-tesla tesla allows HTTP header injection via Tesla.Multipart.add_content_type_param/2. Tesla.Multipart.add_content_type_param/2 appends caller-supplied strings … Jun 02, 2026
CVE-2026-48595 UNKNOWN Improper Handling of Case Sensitivity vulnerability in elixir-tesla tesla allows credential leakage to a third-party origin on cross-origin redirects. Tesla.Middleware.FollowRedirects strips security-sensitive headers on cross-origin … Jun 02, 2026
CVE-2026-48594 UNKNOWN Improper Handling of Highly Compressed Data (Data Amplification) vulnerability in elixir-tesla tesla allows a denial of service via decompression bomb in HTTP response bodies. When … Jun 02, 2026
CVE-2026-47265 UNKNOWN AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.14.0, cookies set with the `cookies` parameter on requests are sent … Jun 02, 2026
CVE-2026-42342 HIGH 7.5 React Router is a router for React. In versions 7.0.0 through 7.14.x of react-router and versions 2.10.0 through 2.17.4 of @remix-run/server-runtime, certain crafted requests can … Jun 02, 2026
CVE-2026-42211 HIGH 8.1 React Router is a router for React. In versions 7.0.0 through 7.14.1, when using Framework Mode, a combination of steps could potentially allow unauthorized remote … Jun 02, 2026
CVE-2026-41577 UNKNOWN authentik is an open-source identity provider. Prior to versions 2025.12.5 and 2026.2.3, the SAML source response processor (ResponseProcessor.parse()) does not validate the Conditions element on … Jun 02, 2026
CVE-2026-40181 UNKNOWN React Router is a router for React. In versions 7.0.0 through 7.14.0 and 6.7.0 through 6.30.3, certain URLs passed to the redirect function can trigger … Jun 02, 2026
CVE-2026-38967 UNKNOWN CrowCpp Crow through v1.3.1 HTTP is vulnerable to response header injection via unvalidated response header values. Jun 02, 2026
CVE-2026-35202 UNKNOWN Pterodactyl is a free, open-source game server management panel. Prior to version 1.12.3, the Pterodactyl Client API has a logic flaw that lets users bypass … Jun 02, 2026
CVE-2026-35049 MEDIUM 6.5 wire-ios is an iOS client for the Wire secure messaging application. Prior to version 4.16.0, upon receiving a crafted malicious Proteus external message with an … Jun 02, 2026
CVE-2026-34993 MEDIUM 6.4 AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.14.0, using ``CookieJar.load()`` with untrusted input may allow arbitrary code execution. … Jun 02, 2026
CVE-2026-34077 HIGH 7.5 React Router is a router for React. In versions 7.7.0 through 7.13.1, when using React Router's unstable React Server Components (RSC) APIs, there is a … Jun 02, 2026