Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

25513
Total
1895
Critical
7789
High
8000
Medium
CVE ID Severity Score Description Published
CVE-2026-49140 MEDIUM 4.3 Nanobot prior to version 0.2.1 contains a denial of service vulnerability in the Matrix channel media download handler that allows authenticated room members to exhaust … Jun 01, 2026
CVE-2026-49139 UNKNOWN Nanobot prior to version 0.2.1 contains a server-side request forgery vulnerability in the Microsoft Teams channel handler that allows remote attackers to exfiltrate Bot Framework … Jun 01, 2026
CVE-2026-49138 MEDIUM 5.0 Nanobot prior to version 0.2.1 contains a server-side request forgery vulnerability in the web_fetch tool that allows remote attackers to reach internal or private network … Jun 01, 2026
CVE-2026-49136 HIGH 7.5 Banana Slides through 0.4.0, patched in commit e8bc490, contains a path traversal vulnerability in the generate_image() function within the AI service backend that allows unauthenticated … Jun 01, 2026
CVE-2026-49135 HIGH 7.1 CodexBar prior to 0.32.0 contains an insecure temporary file handling vulnerability that allows local attackers to access sensitive credentials or tamper with build artifacts by … Jun 01, 2026
CVE-2026-49134 HIGH 7.1 CodexBar prior to 0.32.0 contains a privilege escalation vulnerability in the CLI installer that allows local attackers to execute arbitrary commands as root by exploiting … Jun 01, 2026
CVE-2026-37234 HIGH 8.2 FlexRIC v2.0.0 allows a single SCTP connection to bind multiple xapp_ids by sending multiple E42_SETUP_REQUESTs. On disconnect, only the first registered xapp_id's resources are cleaned … Jun 01, 2026
CVE-2026-24751 HIGH 8.2 Kiteworks is a private data network (PDN). Prior to version 9.3.0, a reflected XSS vulnerability in Kiteworks Secure Data Forms could allow an external attacker … Jun 01, 2026
CVE-2026-10289 MEDIUM 4.3 A security flaw has been discovered in code-projects Hotel and Tourism Reservation System 1.0. Impacted is an unknown function of the file /ht/tour.php. Performing a … Jun 01, 2026
CVE-2026-10288 HIGH 7.3 A vulnerability was identified in code-projects Hotel and Tourism Reservation System 1.0. This issue affects the function password_verify of the file /admin/login.php of the component … Jun 01, 2026
CVE-2026-10287 HIGH 7.3 A vulnerability was determined in SourceCodester SEO Meta Tag Extractor 1.0. This vulnerability affects the function get_headers of the file /index.php. This manipulation of the … Jun 01, 2026
CVE-2026-10286 MEDIUM 6.3 A vulnerability was found in CodeAstro Payroll System 1.0. This affects an unknown part of the file /home_employee.php. The manipulation of the argument emp_id results … Jun 01, 2026
CVE-2026-10285 MEDIUM 5.4 A vulnerability has been found in DevaslanPHP project-management up to 2.0.0-beta1. Affected by this issue is the function KanbanScrumHelper::recordUpdated of the file app/Helpers/KanbanScrumHelper.php of the … Jun 01, 2026
CVE-2026-10284 MEDIUM 5.4 A flaw has been found in DevaslanPHP project-management up to 2.0.0-beta1. Affected by this vulnerability is the function editComment/doDeleteComment of the file app/Filament/Resources/TicketResource/Pages/ViewTicket.php of the … Jun 01, 2026
CVE-2025-70099 HIGH 7.5 A NULL pointer dereference in the ext4_dir_en_get_name_len function in include/ext4_dir.h of lwext4 1.0.0 allows attackers to cause a denial of service by supplying a specially … Jun 01, 2026
CVE-2021-46747 UNKNOWN Insufficient granularity of access control in ASP (AMD Secure Processor) may allow an attacker with an untrusted user space application to map sensitive SMN (System … Jun 01, 2026
CVE-2026-9614 HIGH 8.8 An Improper Access Control vulnerability in Ivanti Neurons for ITSM (cloud and on-premises) allows a remote authenticated attacker to gain administrative access. Jun 01, 2026
CVE-2026-9330 HIGH 8.5 IBM WebSphere Application Server 9.0, and 8.5 is affected by an improper validation of user-supplied data during deserialization using the SAML Web Single Sign-On component. … Jun 01, 2026
CVE-2026-9319 CRITICAL 9.0 IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to potential remote code execution due to deserialization of untrusted data via JAX-WS endpoints with WS-Security. Jun 01, 2026
CVE-2026-9311 CRITICAL 9.0 IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to remote code execution caused by the bypass of security controls. Jun 01, 2026
CVE-2026-8644 CRITICAL 9.1 IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to identity spoofing. Jun 01, 2026
CVE-2026-7770 HIGH 8.8 IBM i Access Family 1.1.5.0 through 1.1.9.12 IBM i Access Client Solutions (ACS) is vulnerable to remote code execution when configured to listen for requests … Jun 01, 2026
CVE-2026-49121 HIGH 8.1 AI Tensor Engine for ROCm (AITER) through 0.1.14 contains an unauthenticated remote code execution vulnerability in the MessageQueue.recv() function within shm_broadcast.py that allows unauthenticated remote … Jun 01, 2026
CVE-2026-47294 HIGH 8.0 Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. Jun 01, 2026
CVE-2026-45810 MEDIUM 6.8 Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 31.0.0 to before 31.0.12, and 32.0.0 to before 32.0.3, a missing check … Jun 01, 2026