Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
25513
Total
1895
Critical
7789
High
8000
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-49140 | MEDIUM | 4.3 | Nanobot prior to version 0.2.1 contains a denial of service vulnerability in the Matrix channel media download handler that allows authenticated room members to exhaust … | Jun 01, 2026 |
| CVE-2026-49139 | UNKNOWN | — | Nanobot prior to version 0.2.1 contains a server-side request forgery vulnerability in the Microsoft Teams channel handler that allows remote attackers to exfiltrate Bot Framework … | Jun 01, 2026 |
| CVE-2026-49138 | MEDIUM | 5.0 | Nanobot prior to version 0.2.1 contains a server-side request forgery vulnerability in the web_fetch tool that allows remote attackers to reach internal or private network … | Jun 01, 2026 |
| CVE-2026-49136 | HIGH | 7.5 | Banana Slides through 0.4.0, patched in commit e8bc490, contains a path traversal vulnerability in the generate_image() function within the AI service backend that allows unauthenticated … | Jun 01, 2026 |
| CVE-2026-49135 | HIGH | 7.1 | CodexBar prior to 0.32.0 contains an insecure temporary file handling vulnerability that allows local attackers to access sensitive credentials or tamper with build artifacts by … | Jun 01, 2026 |
| CVE-2026-49134 | HIGH | 7.1 | CodexBar prior to 0.32.0 contains a privilege escalation vulnerability in the CLI installer that allows local attackers to execute arbitrary commands as root by exploiting … | Jun 01, 2026 |
| CVE-2026-37234 | HIGH | 8.2 | FlexRIC v2.0.0 allows a single SCTP connection to bind multiple xapp_ids by sending multiple E42_SETUP_REQUESTs. On disconnect, only the first registered xapp_id's resources are cleaned … | Jun 01, 2026 |
| CVE-2026-24751 | HIGH | 8.2 | Kiteworks is a private data network (PDN). Prior to version 9.3.0, a reflected XSS vulnerability in Kiteworks Secure Data Forms could allow an external attacker … | Jun 01, 2026 |
| CVE-2026-10289 | MEDIUM | 4.3 | A security flaw has been discovered in code-projects Hotel and Tourism Reservation System 1.0. Impacted is an unknown function of the file /ht/tour.php. Performing a … | Jun 01, 2026 |
| CVE-2026-10288 | HIGH | 7.3 | A vulnerability was identified in code-projects Hotel and Tourism Reservation System 1.0. This issue affects the function password_verify of the file /admin/login.php of the component … | Jun 01, 2026 |
| CVE-2026-10287 | HIGH | 7.3 | A vulnerability was determined in SourceCodester SEO Meta Tag Extractor 1.0. This vulnerability affects the function get_headers of the file /index.php. This manipulation of the … | Jun 01, 2026 |
| CVE-2026-10286 | MEDIUM | 6.3 | A vulnerability was found in CodeAstro Payroll System 1.0. This affects an unknown part of the file /home_employee.php. The manipulation of the argument emp_id results … | Jun 01, 2026 |
| CVE-2026-10285 | MEDIUM | 5.4 | A vulnerability has been found in DevaslanPHP project-management up to 2.0.0-beta1. Affected by this issue is the function KanbanScrumHelper::recordUpdated of the file app/Helpers/KanbanScrumHelper.php of the … | Jun 01, 2026 |
| CVE-2026-10284 | MEDIUM | 5.4 | A flaw has been found in DevaslanPHP project-management up to 2.0.0-beta1. Affected by this vulnerability is the function editComment/doDeleteComment of the file app/Filament/Resources/TicketResource/Pages/ViewTicket.php of the … | Jun 01, 2026 |
| CVE-2025-70099 | HIGH | 7.5 | A NULL pointer dereference in the ext4_dir_en_get_name_len function in include/ext4_dir.h of lwext4 1.0.0 allows attackers to cause a denial of service by supplying a specially … | Jun 01, 2026 |
| CVE-2021-46747 | UNKNOWN | — | Insufficient granularity of access control in ASP (AMD Secure Processor) may allow an attacker with an untrusted user space application to map sensitive SMN (System … | Jun 01, 2026 |
| CVE-2026-9614 | HIGH | 8.8 | An Improper Access Control vulnerability in Ivanti Neurons for ITSM (cloud and on-premises) allows a remote authenticated attacker to gain administrative access. | Jun 01, 2026 |
| CVE-2026-9330 | HIGH | 8.5 | IBM WebSphere Application Server 9.0, and 8.5 is affected by an improper validation of user-supplied data during deserialization using the SAML Web Single Sign-On component. … | Jun 01, 2026 |
| CVE-2026-9319 | CRITICAL | 9.0 | IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to potential remote code execution due to deserialization of untrusted data via JAX-WS endpoints with WS-Security. | Jun 01, 2026 |
| CVE-2026-9311 | CRITICAL | 9.0 | IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to remote code execution caused by the bypass of security controls. | Jun 01, 2026 |
| CVE-2026-8644 | CRITICAL | 9.1 | IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to identity spoofing. | Jun 01, 2026 |
| CVE-2026-7770 | HIGH | 8.8 | IBM i Access Family 1.1.5.0 through 1.1.9.12 IBM i Access Client Solutions (ACS) is vulnerable to remote code execution when configured to listen for requests … | Jun 01, 2026 |
| CVE-2026-49121 | HIGH | 8.1 | AI Tensor Engine for ROCm (AITER) through 0.1.14 contains an unauthenticated remote code execution vulnerability in the MessageQueue.recv() function within shm_broadcast.py that allows unauthenticated remote … | Jun 01, 2026 |
| CVE-2026-47294 | HIGH | 8.0 | Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network. | Jun 01, 2026 |
| CVE-2026-45810 | MEDIUM | 6.8 | Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 31.0.0 to before 31.0.12, and 32.0.0 to before 32.0.3, a missing check … | Jun 01, 2026 |