Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
24801
Total
1759
Critical
7594
High
7792
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-38967 | UNKNOWN | — | CrowCpp Crow through v1.3.1 HTTP is vulnerable to response header injection via unvalidated response header values. | Jun 02, 2026 |
| CVE-2026-35202 | UNKNOWN | — | Pterodactyl is a free, open-source game server management panel. Prior to version 1.12.3, the Pterodactyl Client API has a logic flaw that lets users bypass … | Jun 02, 2026 |
| CVE-2026-35049 | MEDIUM | 6.5 | wire-ios is an iOS client for the Wire secure messaging application. Prior to version 4.16.0, upon receiving a crafted malicious Proteus external message with an … | Jun 02, 2026 |
| CVE-2026-34993 | MEDIUM | 6.4 | AIOHTTP is an asynchronous HTTP client/server framework for asyncio and Python. Prior to version 3.14.0, using ``CookieJar.load()`` with untrusted input may allow arbitrary code execution. … | Jun 02, 2026 |
| CVE-2026-34077 | HIGH | 7.5 | React Router is a router for React. In versions 7.7.0 through 7.13.1, when using React Router's unstable React Server Components (RSC) APIs, there is a … | Jun 02, 2026 |
| CVE-2026-33553 | UNKNOWN | — | Northern.tech CFEngine Enterprise 3.24.3 before 3.24.4 and 3.27.0 before 3.27.1 allows XSS. | Jun 02, 2026 |
| CVE-2026-33245 | HIGH | 8.0 | React Router is a router for React. In versions 7.7.0 through 7.13.1, when using React Router's unstable React Server Components (RSC) APIs, there is a … | Jun 02, 2026 |
| CVE-2026-30586 | UNKNOWN | — | Cross Site Scripting vulnerability in usememos Memos v.0.26.0 allows a remote attacker to obtain sensitive information via the SANITIZE_SCHEMA, Memo Rendering Component, and Public/Private Memo … | Jun 02, 2026 |
| CVE-2026-28299 | HIGH | 8.2 | SolarWinds Web Help Desk is found to be affected by a denial-of-service vulnerability, which when exploited, could cause the Web Help Desk server to crash … | Jun 02, 2026 |
| CVE-2026-1829 | HIGH | 8.8 | The Content Visibility for Divi Builder plugin for WordPress is vulnerable to Remote Code Execution in all versions up to, and including, 4.02 via the … | Jun 02, 2026 |
| CVE-2026-10702 | MEDIUM | 4.3 | JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 151.0.3. | Jun 02, 2026 |
| CVE-2026-10701 | UNKNOWN | — | Incorrect boundary conditions in the Graphics: Text component. This vulnerability was fixed in Firefox 151.0.3. | Jun 02, 2026 |
| CVE-2026-10617 | HIGH | 7.3 | A security vulnerability has been detected in nextlevelbuilder GoClaw up to 3.11.3. This affects the function resolveAuth of the file internal/http/auth.go of the component Webhook … | Jun 02, 2026 |
| CVE-2026-10616 | MEDIUM | 4.3 | A weakness has been identified in nextlevelbuilder GoClaw up to 3.11.3. The impacted element is the function TeamTasksTool.executeComplete of the file internal/tools/team_tasks_lifecycle.go of the component … | Jun 02, 2026 |
| CVE-2026-10608 | HIGH | 7.3 | A security flaw has been discovered in DedeCMS 5.7.88. This affects the function RemoveXSS of the file /plus/carbuyaction.php. The manipulation of the argument postname/des results … | Jun 02, 2026 |
| CVE-2026-10607 | HIGH | 7.3 | A vulnerability was identified in DedeCMS 5.7.88. The impacted element is the function dede_htmlspecialchars of the file /plus/flink.php. The manipulation of the argument msg leads … | Jun 02, 2026 |
| CVE-2026-10584 | MEDIUM | 5.9 | Proxy server in Graph Explorer before 3.0.1 falls back to HTTP when certificate files are missing, which might allow remote threat actors to obtain sensitive … | Jun 02, 2026 |
| CVE-2025-64390 | UNKNOWN | — | A privilege escalation vulnerability exists in PlayStation 4 firmware versions 13.00 through 13.02. The BD-J (Blu-ray Disc Java) sandbox can be escaped through a malformed … | Jun 02, 2026 |
| CVE-2021-4479 | MEDIUM | 4.0 | Dräger Atlan A350 software versions 1.00 through 1.01 contains an improper input handling vulnerability that allows attackers to cause a denial of service by sending … | Jun 02, 2026 |
| CVE-2021-4478 | HIGH | 8.2 | Dräger CC-Vision Basic before 7.5.3 and Dräger CC-Vision E-Cal before 7.2.5.0 contain an out-of-bounds write vulnerability when loading .gdt files. A crafted .gdt file can … | Jun 02, 2026 |
| CVE-2019-25724 | MEDIUM | 6.5 | Dräger Infinity M300 patient worn monitors with software version VG2.x and earlier contain a network-based denial of service vulnerability that allows attackers with access to … | Jun 02, 2026 |
| CVE-2019-25723 | MEDIUM | 4.0 | Dräger Perseus A500 software versions 2.00 through 2.02 contains an improper input handling vulnerability that allows external attackers to cause a denial of service by … | Jun 02, 2026 |
| CVE-2019-25722 | HIGH | 7.6 | Dräger SC Monitoring devices (SC 6002XL, SC 6802XL, SC 7000, SC 8000, SC 9000 XL) contain hard-coded plaintext credentials in source code and a denial-of-service … | Jun 02, 2026 |
| CVE-2019-25721 | MEDIUM | 6.5 | Dräger Infinity M300 patient worn monitors with software version VG2.3.1 and earlier contain a network-based denial of service vulnerability that allows network-adjacent attackers to repeatedly … | Jun 02, 2026 |
| CVE-2026-49943 | MEDIUM | 6.3 | CZ.NIC BIRD Internet Routing Daemon through 2.19.0 contains a stack-based buffer overflow in the BGP AS_PATH mask matching implementation in nest/a-path.c. The as_path_match() function uses … | Jun 02, 2026 |