Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
25301
Total
1888
Critical
7733
High
7926
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-3871 | MEDIUM | 6.5 | A buffer overflow vulnerability in the UPnP DeletePortMapping() command in Zyxel VMG4005-B50B firmware versions through 5.13(ABRL.5.4)C0 could allow an adjacent attacker to trigger a temporary … | Jun 02, 2026 |
| CVE-2026-3870 | MEDIUM | 6.5 | A buffer overflow vulnerability in the UPnP AddPortMapping() command in Zyxel VMG4005-B50B firmware versions through 5.13(ABRL.5.4)C0 could allow an adjacent attacker to trigger a temporary … | Jun 02, 2026 |
| CVE-2026-3722 | MEDIUM | 6.4 | The Auto Image Attributes From Filename With Bulk Updater (Add Alt Text, Image Title For Image SEO) plugin for WordPress is vulnerable to Stored Cross-Site … | Jun 02, 2026 |
| CVE-2026-10568 | MEDIUM | 6.3 | A vulnerability was detected in itsourcecode Fees Management System 1.0. Affected is an unknown function of the file /manage_payment.php. The manipulation of the argument ID … | Jun 02, 2026 |
| CVE-2026-10567 | LOW | 3.5 | A security vulnerability has been detected in 1Panel-dev CordysCRM up to 1.4.1. This impacts the function Save of the file src/main/java/cn/cordys/crm/system/service/ModuleFormService.java of the component ModuleFormController. … | Jun 02, 2026 |
| CVE-2026-10566 | MEDIUM | 5.3 | A weakness has been identified in FoundationAgents MetaGPT up to 0.8.2. This affects the function Message.check_instruct_content of the file metagpt/schema.py. Executing a manipulation of the … | Jun 02, 2026 |
| CVE-2026-10565 | LOW | 3.1 | A security flaw has been discovered in Open5GS up to 2.7.6. The impacted element is the function gmm_state_security_mode of the file src/amf/gmm-sm.c of the component … | Jun 02, 2026 |
| CVE-2026-10510 | MEDIUM | 6.1 | Cross-Site Scripting (XSS) in GeniexWebView component in Transsion AI Assistant Lifestyle application (com.transsion.aiassistantlifestyle) all versions on Android allows remote attacker to execute arbitrary JavaScript in … | Jun 02, 2026 |
| CVE-2026-10100 | MEDIUM | 4.4 | The Simple Custom Login Page plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the color settings fields (Page Background, Form Background, Text Color, … | Jun 02, 2026 |
| CVE-2026-10559 | MEDIUM | 6.3 | A flaw has been found in SourceCodester Pizzafy Ecommerce System 1.0. The affected element is an unknown function of the file /index.php. Executing a manipulation … | Jun 02, 2026 |
| CVE-2026-10558 | MEDIUM | 6.3 | A vulnerability was detected in SourceCodester Pizzafy Ecommerce System 1.0. Impacted is an unknown function of the file /admin/index.php. Performing a manipulation of the argument … | Jun 02, 2026 |
| CVE-2026-10550 | MEDIUM | 6.3 | A weakness has been identified in elunez eladmin up to 2.7. This vulnerability affects unknown code of the file App.java of the component Application Deployment … | Jun 02, 2026 |
| CVE-2026-10548 | MEDIUM | 5.3 | A security flaw has been discovered in NousResearch hermes-agent up to 2026.4.23. This affects the function _sync_anthropic_entry_from_credentials_file of the file agent/credential_pool.py of the component Credential … | Jun 02, 2026 |
| CVE-2026-10529 | LOW | 2.4 | A weakness has been identified in westboy CicadasCMS up to 2431154dac8d0735e04f1fd2a3c3556668fc8dab. Impacted is an unknown function of the file src/main/java/com/zhiliao/module/web/system/ScheduleJobController.java of the component Task Scheduling … | Jun 02, 2026 |
| CVE-2026-9050 | MEDIUM | 4.3 | The Slider Revolution plugin for WordPress in versions 6.0.0-6.7.55 and 7.0.0-7.0.14 is vulnerable to unauthorized modification of data. This is due to the plugin not … | Jun 02, 2026 |
| CVE-2026-9048 | MEDIUM | 4.3 | The Slider Revolution plugin for WordPress is vulnerable to Sensitive Information Exposure in versions 7.0.0 - 7.0.14, via the 'slider.get.full' AJAX Action. This makes it … | Jun 02, 2026 |
| CVE-2026-10528 | LOW | 3.3 | A security flaw has been discovered in Orthanc DICOM Server up to 1.12.11. This issue affects the function DcmItem::read of the file OrthancFramework/Sources/DicomParsing/FromDcmtkBridge.cpp of the … | Jun 02, 2026 |
| CVE-2026-10514 | LOW | 2.4 | A vulnerability has been found in 1Panel-dev CordysCRM up to 1.6.2. This affects an unknown function of the file backend/framework/src/main/java/cn/cordys/config/RequestParamTrimConfig.java. The manipulation leads to cross … | Jun 02, 2026 |
| CVE-2026-10302 | MEDIUM | 6.3 | A flaw has been found in itsourcecode Fees Management System 1.0. The impacted element is an unknown function of the file /manage_fee.php. Executing a manipulation … | Jun 02, 2026 |
| CVE-2026-10301 | MEDIUM | 4.3 | A vulnerability was detected in itsourcecode Fees Management System 1.0. The affected element is an unknown function of the file index.php. Performing a manipulation of … | Jun 02, 2026 |
| CVE-2026-28511 | MEDIUM | 4.3 | eLabFTW is an open source electronic lab notebook. Prior to version 5.4.2, in certain cases, an authenticated user performing a numeric reference/search can return results … | Jun 01, 2026 |
| CVE-2026-25879 | CRITICAL | 9.8 | Langroid is a framework for building large-language-model-powered applications. Prior to version 0.63.0, SQLChatAgent executes SQL produced by an LLM, which is influenceable by prompt injection. … | Jun 01, 2026 |
| CVE-2026-25277 | HIGH | 8.8 | Memory corruption while using Strongbox due to buffer overflow. | Jun 01, 2026 |
| CVE-2026-25276 | HIGH | 8.8 | Memory corruption while using Strongbox due to missing bounds check. | Jun 01, 2026 |
| CVE-2026-25260 | HIGH | 7.8 | Memory Corruption when accessing shared buffers without validation of concurrent user-mode input modifications. | Jun 01, 2026 |