Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
25121
Total
1793
Critical
7689
High
7893
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-26824 | MEDIUM | 6.5 | libxls through version 1.6.3 contains a use of uninitialized memory vulnerability in the OLE container parser. Memory allocated for the Master Sector Allocation Table (MSAT) … | Jun 03, 2026 |
| CVE-2026-10766 | LOW | 3.6 | A vulnerability has been found in mlrun up to 1.12.0-rc3. This impacts the function mlrun.utils.helpers.calculate_dataframe_hash of the file mlrun/utils/helpers.py of the component DataFrame Hash Handler. … | Jun 03, 2026 |
| CVE-2026-8889 | UNKNOWN | — | Version 3.0.7 of the Securly Chrome Extension uses deprecated SHA-1 hashing for IWF CSAM URL matching (25,020 hashes) and CIPA blocklist matching (12,352 hashes). | Jun 03, 2026 |
| CVE-2026-8888 | UNKNOWN | — | Version 3.0.7 of the Securly Chrome Extension downloads config.json over HTTP and compiles server-provided patterns as JavaScript regular expressions via new RegExp() without complexity validation. … | Jun 03, 2026 |
| CVE-2026-8881 | UNKNOWN | — | Version 3.0.7 of the Securly Chrome Extension uses EVP_BytesToKey key derivation with MD5 and a single iteration for AES encryption. MD5 has been broken since … | Jun 03, 2026 |
| CVE-2026-8879 | HIGH | 7.5 | Version 3.0.7 of the Securly Chrome Extension dynamically registers content13.min.js as a content script via chrome.scripting.registerContentScripts() at runtime. This script is NOT declared in manifest.json … | Jun 03, 2026 |
| CVE-2026-8878 | HIGH | 7.5 | Version 3.0.7 of the Securly Chrome Extension exposes multiple publicly accessible endpoints that allow unauthenticated access to sensitive data. The exposed information consists of SHA-1 … | Jun 03, 2026 |
| CVE-2026-8876 | HIGH | 7.3 | Version 3.0.7 of the Securly Chrome Extension contains hardcoded, plaintext AES passphrases in securly.min.js. These keys decrypt crisis alert keyword data and intervention site data. | Jun 03, 2026 |
| CVE-2026-8874 | HIGH | 7.1 | Version 3.0.7 of the Securly Chrome Extension downloads JSON files containing crisis alert keywords and filtering rules over unencrypted HTTP via the Fetch API. Other … | Jun 03, 2026 |
| CVE-2026-7888 | UNKNOWN | — | Concrete CMS below 9.5.2 is vulnerable to PHP Object Injection via unserialize() calls in the Workflow, Form block, and File/Set components that lack the allowed_classes … | Jun 03, 2026 |
| CVE-2026-45702 | MEDIUM | 4.4 | OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. Starting … | Jun 03, 2026 |
| CVE-2026-45614 | MEDIUM | 4.7 | OP-TEE is a Trusted Execution Environment (TEE) designed as companion to a non-secure Linux kernel running on Arm; Cortex-A cores using the TrustZone technology. Prior … | Jun 03, 2026 |
| CVE-2026-42840 | UNKNOWN | — | An authenticated user can persist arbitrary HTML/JavaScript in the email_id or mobile_no fields of a Customer record and trigger unescaped rendering in the Point of … | Jun 03, 2026 |
| CVE-2026-42839 | UNKNOWN | — | An authenticated ERPNext user with Item record edit permissions can persist arbitrary HTML/JavaScript in the item_name, description, or image fields of an Item and trigger … | Jun 03, 2026 |
| CVE-2026-26379 | MEDIUM | 6.5 | An issue in Koha v.25.11 and before allows a remote attacker to execute arbitrary code via the Z39.50 configuration module | Jun 03, 2026 |
| CVE-2026-26378 | MEDIUM | 5.4 | Cross Site Scripting vulnerability in Koha 25.11 and before allows a remote attacker to execute arbitrary code via file upload function in Invoice features | Jun 03, 2026 |
| CVE-2026-46273 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: ibmveth: Disable GSO for packets with small MSS Some physical adapters on Power systems do … | Jun 03, 2026 |
| CVE-2026-46272 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: coresight: tmc-etr: Fix race condition between sysfs and perf mode When trying to run perf … | Jun 03, 2026 |
| CVE-2026-46271 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: wifi: ath12k: do WoW offloads only on primary link In case of multi-link connection, WCN7850 … | Jun 03, 2026 |
| CVE-2026-46270 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: power: supply: rt9455: Fix use-after-free in power_supply_changed() Using the `devm_` variant for requesting IRQ _before_ … | Jun 03, 2026 |
| CVE-2026-46269 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: pinctrl: canaan: k230: Fix NULL pointer dereference when parsing devicetree When probing the k230 pinctrl … | Jun 03, 2026 |
| CVE-2026-46268 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: PCI/P2PDMA: Fix p2pmem_alloc_mmap() warning condition Commit b7e282378773 has already changed the initial page refcount of … | Jun 03, 2026 |
| CVE-2026-46267 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: nfc: hci: shdlc: Stop timers and work before freeing context llc_shdlc_deinit() purges SHDLC skb queues … | Jun 03, 2026 |
| CVE-2026-46266 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: inet: RAW sockets using IPPROTO_RAW MUST drop incoming ICMP Yizhou Zhao reported that simply having … | Jun 03, 2026 |
| CVE-2026-46265 | UNKNOWN | — | In the Linux kernel, the following vulnerability has been resolved: RDMA/hns: Fix WQ_MEM_RECLAIM warning When sunrpc is used, if a reset triggered, our wq may … | Jun 03, 2026 |