Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

24801
Total
1759
Critical
7594
High
7792
Medium
CVE ID Severity Score Description Published
CVE-2026-42074 CRITICAL 9.8 OpenClaude is an open-source coding-agent command line interface for cloud and local model providers. Prior to version 0.5.1, the dangerouslyDisableSandbox parameter is exposed as part … Jun 02, 2026
CVE-2026-42073 MEDIUM 6.5 OpenClaude is an open-source coding-agent command line interface for cloud and local model providers. Prior to version 0.5.1, the OpenClaude MCP authentication flow starts a … Jun 02, 2026
CVE-2026-40715 HIGH 7.8 Dell ThinOS 10, versions prior to ThinOS10 2602_10.0765, contain an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this … Jun 02, 2026
CVE-2026-40713 MEDIUM 6.1 Dell ThinOS 10, versions prior to ThinOS10 2602_10.0765, contain an Improper Access control vulnerability. An unauthenticated attacker with physical access could potentially exploit this vulnerability, … Jun 02, 2026
CVE-2026-40571 UNKNOWN NamelessMC is website software for Minecraft servers. In version 2.2.4, `core/classes/Misc/ProfilePostReactionContext.php` only verifies that the wall post exists and does not enforce blocked/private-profile visibility. This … Jun 02, 2026
CVE-2026-40314 UNKNOWN NamelessMC is website software for Minecraft servers. In version 2.2.4,`core/classes/Misc/ProfilePostReactionContext.php` only verifies that the wall post exists and does not enforce blocked/private-profile visibility. `modules/Core/queries/reactions.php` allows … Jun 02, 2026
CVE-2026-35447 UNKNOWN NamelessMC is website software for Minecraft servers. In version 2.2.4, the profile page (modules/Core/pages/profile.php) processes wall post submissions and replies before verifying whether the viewer … Jun 02, 2026
CVE-2026-35443 UNKNOWN NamelessMC is website software for Minecraft servers. In version 2.2.4, `modules/Forum/classes/ForumPostReactionContext.php` only verifies that the caller can view the forum, but it does not re-enforce … Jun 02, 2026
CVE-2026-33244 MEDIUM 5.4 React Router is a router for React. In versions 7.5.1 through 7.13.1, when using Framework Mode with pre-rendering enabled, improper neutralization of the HTTP `Location` … Jun 02, 2026
CVE-2026-24237 HIGH 7.8 NVIDIA NVTabular contains a vulnerability where an attacker could cause improper deserialization of untrusted data. A successful exploit of this vulnerability might lead to code … Jun 02, 2026
CVE-2026-24221 HIGH 7.8 NVIDIA NVTabular contains a vulnerability where an attacker could cause improper deserialization of untrusted data. A successful exploit of this vulnerability might lead to code … Jun 02, 2026
CVE-2026-1871 UNKNOWN TP-Link Tapo C200 v5 contains a stack-based buffer overflow flaw in RTSP authentication handling due to improper validation of Authorization header field lengths, which can … Jun 02, 2026
CVE-2026-10606 HIGH 7.3 A vulnerability was determined in DedeCMS 5.7.88. The affected element is the function TrimMsg of the file /plus/feedback.php of the component Feedback Handler. Executing a … Jun 02, 2026
CVE-2026-0611 CRITICAL 9.8 Spacelabs Healthcare Sentinel versions 10.5.x and higher and 11.x.x before 11.6.0 contain an unauthenticated remote code execution vulnerability through a deprecated .NET Remoting HTTP channel … Jun 02, 2026
CVE-2024-42206 LOW 3.1 HCL iReflection Third party vulnerable and outdated components issue was detected in the web application Jun 02, 2026
CVE-2026-9590 MEDIUM 5.3 Improper access control in the permission validation component in Devolutions Server 2026.1.19 and earlier allows an authenticated user with entry edit privileges to modify asset … Jun 02, 2026
CVE-2026-9522 MEDIUM 5.4 Improper access control in the PAM account discovery feature in Devolutions Server 2026.1.19 and earlier allows an authenticated user without administrative privileges to delete network … Jun 02, 2026
CVE-2026-7299 MEDIUM 6.3 Appsmith’s SQL query editor’s autocomplete functionality fails to sanitize database object names before rendering them in innerHTML, allowing an authenticated Developer to inject persistent XSS … Jun 02, 2026
CVE-2026-49754 UNKNOWN Allocation of Resources Without Limits or Throttling vulnerability in elixir-mint Mint allows attacker-controlled HTTP/2 servers to exhaust memory in a Mint client (HTTP/2 CONTINUATION flood). … Jun 02, 2026
CVE-2026-49753 UNKNOWN Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in elixir-mint Mint allows attacker-controlled HTTP/1 servers to desynchronise response framing on shared connections. Mint's HTTP/1 … Jun 02, 2026
CVE-2026-48862 UNKNOWN Allocation of Resources Without Limits or Throttling vulnerability in elixir-mint Mint allows attacker-controlled HTTP/2 servers to exhaust memory in a Mint client via PUSH_PROMISE flooding. … Jun 02, 2026
CVE-2026-48861 UNKNOWN Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability in elixir-mint Mint allows HTTP Request Splitting and HTTP Request Smuggling. In lib/mint/http1/request.ex, the encode_request_line/2 function splices … Jun 02, 2026
CVE-2026-47117 CRITICAL 9.8 OpenMed before 1.5.2 contains a remote code execution vulnerability in the PII privacy-filter model loading path. The privacy-filter dispatcher used broad substring matching on the … Jun 02, 2026
CVE-2026-45686 HIGH 7.5 OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. From version 0.7.0 to before version 0.9.0, a remotely reachable integer overflow in OBI's … Jun 02, 2026
CVE-2026-45685 HIGH 7.5 OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. From version 0.1.0 to before version 0.9.0, malformed MongoDB wire messages can trigger uncaught … Jun 02, 2026