Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

24801
Total
1759
Critical
7594
High
7792
Medium
CVE ID Severity Score Description Published
CVE-2026-40108 UNKNOWN GLPI is a free asset and IT management software package. In versions 11.0.0 through 11.0.6, a technician can store an XSS payload in a ITIL … Jun 02, 2026
CVE-2026-35482 HIGH 8.0 alf.io is an open source ticket reservation system for conferences, trade shows, workshops, and meetups. Prior to version 2.0-M5-2606, a sandbox escape vulnerability in the … Jun 02, 2026
CVE-2026-32625 CRITICAL 9.6 LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. In versions up to and including 0.8.3, the Model Context Protocol (MCP) server integration … Jun 02, 2026
CVE-2026-31942 HIGH 7.1 LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. In versions up to and including 0.7.6, an Insecure Direct Object Reference (IDOR) vulnerability … Jun 02, 2026
CVE-2026-27145 UNKNOWN (*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, ".") to execute repeatedly on the same … Jun 02, 2026
CVE-2026-25861 MEDIUM 5.9 QloApps through 1.7.0, fixed in commit 64e9722, contains a weak cryptographic algorithm vulnerability that allows attackers to compromise user credentials by exploiting the use of … Jun 02, 2026
CVE-2026-10719 UNKNOWN Out of bounds write in openSeaChest’s --showSupportedFormats in Seagate’s openSeaChest v25.05.3 on all supported platforms allows for writing 1 extra byte outside of allocated memory … Jun 02, 2026
CVE-2026-10718 UNKNOWN Out of bounds write in openSeaChest’s Trim/Unmap operation in Seagate’s openSeaChest v26.03.0 on all supported platforms allows for writing extra memory describing a range of … Jun 02, 2026
CVE-2026-10717 UNKNOWN Out of bounds write and reads in openSeaChest’s --showSCSIDefects in Seagate’s openSeaChest v25.05.3 on all supported platforms allows for writing defect information out of bounds … Jun 02, 2026
CVE-2026-10688 MEDIUM 5.5 A vulnerability was determined in ahujasid blender-mcp up to 7636d13bded82eca58eb93c3f4cd8708dfdfbe8b. The impacted element is the function execute_blender_code of the file /src/blender_mcp/server.py. This manipulation of the … Jun 02, 2026
CVE-2026-10662 MEDIUM 6.3 A vulnerability was found in ahujasid blender-mcp up to 7636d13bded82eca58eb93c3f4cd8708dfdfbe8b. The affected element is the function requests.get of the file src/blender_mcp/server.py of the component ZIP … Jun 02, 2026
CVE-2026-8936 UNKNOWN Fixed a VM panic caused by unbounded recursion in the grpcfuse kernel module when a container created deeply nested directories on a bind-mounted host folder … Jun 02, 2026
CVE-2026-42029 UNKNOWN Rejected reason: This CVE is a duplicate of another CVE. Jun 02, 2026
CVE-2026-35212 UNKNOWN OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Versions prior to 7.260227.0 are vulnerable to XSS in the rendering … Jun 02, 2026
CVE-2026-10661 MEDIUM 4.3 A vulnerability has been found in ahujasid blender-mcp up to 7636d13bded82eca58eb93c3f4cd8708dfdfbe8b. Impacted is the function Open of the file src/blender_mcp/server.py. The manipulation of the argument … Jun 02, 2026
CVE-2026-10650 MEDIUM 5.3 A flaw has been found in warmcat libwebsockets up to 4.5.8. This issue affects the function lws_ssh_parse_plaintext of the file plugins/protocol_lws_ssh_base/sshd.c of the component SSH … Jun 02, 2026
CVE-2025-15653 MEDIUM 6.8 Dräger Zeus Infinity Empowered (Zeus IE) and Zeus RS C500 anesthesia workstations contain a local security vulnerability that allows unauthorized individuals with physical access to … Jun 02, 2026
CVE-2024-14036 HIGH 7.5 Dräger Core 1.0.5 and Dräger M540 Converter Service 1.0.9 contain a denial of service vulnerability that allows network-adjacent attackers to trigger high CPU load by … Jun 02, 2026
CVE-2022-4992 HIGH 8.6 Dräger Infinity Acute Care System and Standalone Infinity M540 patient monitors versions VG4.1.1, VG4.0.3, and lower (with VG4.2 partially affected) contain a network message handling … Jun 02, 2026
CVE-2021-4481 HIGH 8.2 Dräger Protector Software prior to version 6.4.2 contains a local privilege escalation vulnerability due to insecure file system permissions that allows local attackers to execute … Jun 02, 2026
CVE-2021-4480 HIGH 8.2 Dräger Protector Software prior to version 6.4.2 contains a local privilege escalation vulnerability due to insecure file system permissions that allows local attackers to execute … Jun 02, 2026
CVE-2026-49448 CRITICAL 9.8 authentik is an open-source identity provider. Prior to versions 2025.12.6, 2026.2.4, and 2026.5.1, the Source stage can be bypassed by sending an empty POST. This … Jun 02, 2026
CVE-2026-49443 HIGH 8.8 authentik is an open-source identity provider. Prior to versions 2025.12.6, 2026.2.4, and 2026.5.1, an attacker with the ability to change a source connection, and an … Jun 02, 2026
CVE-2026-49144 MEDIUM 6.5 BrowserStack Runner through 0.9.5 contains a path traversal vulnerability in the _default HTTP handler in lib/server.js that allows unauthenticated network-adjacent attackers to read arbitrary files. … Jun 02, 2026
CVE-2026-49143 HIGH 8.8 BrowserStack Runner through 0.9.5 contains a remote code execution vulnerability in the /_log HTTP handler that allows unauthenticated network-adjacent attackers to execute arbitrary code by … Jun 02, 2026