Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

25121
Total
1793
Critical
7689
High
7893
Medium
CVE ID Severity Score Description Published
CVE-2026-41860 HIGH 8.8 CWE-326 in BOSH allows a local attacker to steal Basic-auth credentials or redirect UAA token requests via MITM. HttpRequestHelper#create_async_endpoint and #send_http_get_request_synchronous hard-code OpenSSL::SSL::VERIFY_NONE, enabling an … Jun 04, 2026
CVE-2026-41859 HIGH 7.8 A network man-in-the-middle between nats-sync and the BOSH director can steal the director credentials (Basic auth header or UAA client secret) and can tamper with … Jun 04, 2026
CVE-2026-41858 HIGH 7.5 Weak Randomness / Insecure Cryptographic Primitive (CWE-338) in Get-RandomPassword in BOSH-Ecosystem / windows-utilities-release allows a network attacker to estimate VM boot time and reconstruct a … Jun 04, 2026
CVE-2026-41011 HIGH 8.2 PackagePersister.validate_tgz builds "tar -tf #{tgz} 2>&1" where tgz = File.join(release_dir, 'packages', "#{name}.tgz") and name = package_meta['name'] comes directly from release.MF inside the uploaded tarball. The … Jun 04, 2026
CVE-2026-10597 MEDIUM 5.3 OMICARD EDM developed by ITPison has a Insecure Direct Object Reference vulnerability, allowing unauthenticated remote attackers to modify a specific parameter to obtain user's email … Jun 04, 2026
CVE-2026-8653 MEDIUM 6.5 The MasterStudy LMS Pro Plus plugin for WordPress is vulnerable to generic SQL Injection via the 'columns' parameter in all versions up to, and including, … Jun 04, 2026
CVE-2026-7764 MEDIUM 6.8 An out-of-bounds read vulnerability in the morse.ko HaLow Wi-Fi kernel driver in Morse Micro HaLowLink 2 software versions prior to 2.11.12 allows an unauthenticated attacker … Jun 04, 2026
CVE-2026-10737 HIGH 7.5 The SP Project & Document Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the view_file function in … Jun 04, 2026
CVE-2026-8722 MEDIUM 6.5 Net::Async::Statsd::Client versions through 0.005 for Perl allow metric injections. The metric names are not checked for newlines, colons or pipes. Metrics generated from untrusted sources … Jun 04, 2026
CVE-2026-10783 LOW 2.5 A security flaw has been discovered in gradio-app gradio 6.14.0. This affects the function save_audio_to_cache of the component Audio Cache Key Handler. Performing a manipulation … Jun 04, 2026
CVE-2026-2596 UNKNOWN Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. Jun 03, 2026
CVE-2026-10777 HIGH 7.3 A vulnerability was identified in ealpha072 Student-Management-System up to 01451bd7a2f58cdda07bd0b86e3967582e3ecd08. Affected by this issue is some unknown functionality of the file admin/config.php of the component … Jun 03, 2026
CVE-2026-10775 LOW 3.6 A vulnerability was determined in sgl-project SGLang up to 0.5.11. Affected by this vulnerability is the function data_hash of the component Cache Handler. This manipulation … Jun 03, 2026
CVE-2026-46447 MEDIUM 5.8 OpenStack Ironic before 35.0.2 allows Boot Script Injection of an iPXE script if the attacker can set node.driver_info or node.instance_info. Jun 03, 2026
CVE-2026-22055 UNKNOWN Active IQ OneCollect version 2.7.3 contains hard-coded credentials that could allow an authenticated attacker with low privileges to perform unauthorized AutoSupport operations. Jun 03, 2026
CVE-2026-22054 UNKNOWN Active IQ Config Advisor version 6.7.3 contains hard-coded credentials that could allow an authenticated attacker with low privileges to perform unauthorized AutoSupport operations. Jun 03, 2026
CVE-2026-10771 HIGH 7.3 A vulnerability was found in crmeb crmeb_java 1.4. Affected is the function RestTemplate.getForEntity of the file crmeb-common/src/main/java/com/zbkj/common/utils/RestTemplateUtil.java of the component base64 Qrcode Endpoint. The manipulation … Jun 03, 2026
CVE-2026-50033 HIGH 7.3 Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis DeviceLock DLP (Windows) before build 9.0.15051.93227. Jun 03, 2026
CVE-2026-44682 HIGH 7.3 Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis DeviceLock DLP (Windows) before build 9.0.15051.93227. Jun 03, 2026
CVE-2026-44609 HIGH 7.3 Local privilege escalation due to EXE hijacking vulnerability. The following products are affected: Acronis DeviceLock DLP (Windows) before build 9.0.15051.93227. Jun 03, 2026
CVE-2026-43924 UNKNOWN FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, the Redirect module does not validate the URL scheme of administrator-configured … Jun 03, 2026
CVE-2026-42061 HIGH 7.3 Local privilege escalation due to excessive permissions assigned to child processes. The following products are affected: Acronis DeviceLock DLP (Windows) before build 9.0.15051.93227. Jun 03, 2026
CVE-2026-40495 UNKNOWN FOSSBilling is a free, open-source billing and client management system. Versions prior to 0.8.0 leak the exact system version through asset cache buster parameters in … Jun 03, 2026
CVE-2026-37700 UNKNOWN Cross Site Scripting vulnerability in MaxSite CMS v.109.2 allows a remote attacker to obtain sensitive information via the Backend page file upload endpoint used by … Jun 03, 2026
CVE-2026-26825 UNKNOWN A use-of-uninitialized memory vulnerability exists in libxls 1.6.3 when parsing malformed XLS files. The issue is reachable via xls_parseWorkBook() and is triggered by uninitialized heap … Jun 03, 2026