Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
24801
Total
1759
Critical
7594
High
7792
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-42074 | CRITICAL | 9.8 | OpenClaude is an open-source coding-agent command line interface for cloud and local model providers. Prior to version 0.5.1, the dangerouslyDisableSandbox parameter is exposed as part … | Jun 02, 2026 |
| CVE-2026-42073 | MEDIUM | 6.5 | OpenClaude is an open-source coding-agent command line interface for cloud and local model providers. Prior to version 0.5.1, the OpenClaude MCP authentication flow starts a … | Jun 02, 2026 |
| CVE-2026-40715 | HIGH | 7.8 | Dell ThinOS 10, versions prior to ThinOS10 2602_10.0765, contain an Improper Access Control vulnerability. A low privileged attacker with local access could potentially exploit this … | Jun 02, 2026 |
| CVE-2026-40713 | MEDIUM | 6.1 | Dell ThinOS 10, versions prior to ThinOS10 2602_10.0765, contain an Improper Access control vulnerability. An unauthenticated attacker with physical access could potentially exploit this vulnerability, … | Jun 02, 2026 |
| CVE-2026-40571 | UNKNOWN | — | NamelessMC is website software for Minecraft servers. In version 2.2.4, `core/classes/Misc/ProfilePostReactionContext.php` only verifies that the wall post exists and does not enforce blocked/private-profile visibility. This … | Jun 02, 2026 |
| CVE-2026-40314 | UNKNOWN | — | NamelessMC is website software for Minecraft servers. In version 2.2.4,`core/classes/Misc/ProfilePostReactionContext.php` only verifies that the wall post exists and does not enforce blocked/private-profile visibility. `modules/Core/queries/reactions.php` allows … | Jun 02, 2026 |
| CVE-2026-35447 | UNKNOWN | — | NamelessMC is website software for Minecraft servers. In version 2.2.4, the profile page (modules/Core/pages/profile.php) processes wall post submissions and replies before verifying whether the viewer … | Jun 02, 2026 |
| CVE-2026-35443 | UNKNOWN | — | NamelessMC is website software for Minecraft servers. In version 2.2.4, `modules/Forum/classes/ForumPostReactionContext.php` only verifies that the caller can view the forum, but it does not re-enforce … | Jun 02, 2026 |
| CVE-2026-33244 | MEDIUM | 5.4 | React Router is a router for React. In versions 7.5.1 through 7.13.1, when using Framework Mode with pre-rendering enabled, improper neutralization of the HTTP `Location` … | Jun 02, 2026 |
| CVE-2026-24237 | HIGH | 7.8 | NVIDIA NVTabular contains a vulnerability where an attacker could cause improper deserialization of untrusted data. A successful exploit of this vulnerability might lead to code … | Jun 02, 2026 |
| CVE-2026-24221 | HIGH | 7.8 | NVIDIA NVTabular contains a vulnerability where an attacker could cause improper deserialization of untrusted data. A successful exploit of this vulnerability might lead to code … | Jun 02, 2026 |
| CVE-2026-1871 | UNKNOWN | — | TP-Link Tapo C200 v5 contains a stack-based buffer overflow flaw in RTSP authentication handling due to improper validation of Authorization header field lengths, which can … | Jun 02, 2026 |
| CVE-2026-10606 | HIGH | 7.3 | A vulnerability was determined in DedeCMS 5.7.88. The affected element is the function TrimMsg of the file /plus/feedback.php of the component Feedback Handler. Executing a … | Jun 02, 2026 |
| CVE-2026-0611 | CRITICAL | 9.8 | Spacelabs Healthcare Sentinel versions 10.5.x and higher and 11.x.x before 11.6.0 contain an unauthenticated remote code execution vulnerability through a deprecated .NET Remoting HTTP channel … | Jun 02, 2026 |
| CVE-2024-42206 | LOW | 3.1 | HCL iReflection Third party vulnerable and outdated components issue was detected in the web application | Jun 02, 2026 |
| CVE-2026-9590 | MEDIUM | 5.3 | Improper access control in the permission validation component in Devolutions Server 2026.1.19 and earlier allows an authenticated user with entry edit privileges to modify asset … | Jun 02, 2026 |
| CVE-2026-9522 | MEDIUM | 5.4 | Improper access control in the PAM account discovery feature in Devolutions Server 2026.1.19 and earlier allows an authenticated user without administrative privileges to delete network … | Jun 02, 2026 |
| CVE-2026-7299 | MEDIUM | 6.3 | Appsmith’s SQL query editor’s autocomplete functionality fails to sanitize database object names before rendering them in innerHTML, allowing an authenticated Developer to inject persistent XSS … | Jun 02, 2026 |
| CVE-2026-49754 | UNKNOWN | — | Allocation of Resources Without Limits or Throttling vulnerability in elixir-mint Mint allows attacker-controlled HTTP/2 servers to exhaust memory in a Mint client (HTTP/2 CONTINUATION flood). … | Jun 02, 2026 |
| CVE-2026-49753 | UNKNOWN | — | Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in elixir-mint Mint allows attacker-controlled HTTP/1 servers to desynchronise response framing on shared connections. Mint's HTTP/1 … | Jun 02, 2026 |
| CVE-2026-48862 | UNKNOWN | — | Allocation of Resources Without Limits or Throttling vulnerability in elixir-mint Mint allows attacker-controlled HTTP/2 servers to exhaust memory in a Mint client via PUSH_PROMISE flooding. … | Jun 02, 2026 |
| CVE-2026-48861 | UNKNOWN | — | Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability in elixir-mint Mint allows HTTP Request Splitting and HTTP Request Smuggling. In lib/mint/http1/request.ex, the encode_request_line/2 function splices … | Jun 02, 2026 |
| CVE-2026-47117 | CRITICAL | 9.8 | OpenMed before 1.5.2 contains a remote code execution vulnerability in the PII privacy-filter model loading path. The privacy-filter dispatcher used broad substring matching on the … | Jun 02, 2026 |
| CVE-2026-45686 | HIGH | 7.5 | OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. From version 0.7.0 to before version 0.9.0, a remotely reachable integer overflow in OBI's … | Jun 02, 2026 |
| CVE-2026-45685 | HIGH | 7.5 | OpenTelemetry eBPF Instrumentation provides eBPF instrumentation based on the OpenTelemetry standard. From version 0.1.0 to before version 0.9.0, malformed MongoDB wire messages can trigger uncaught … | Jun 02, 2026 |