Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

25513
Total
1895
Critical
7789
High
8000
Medium
CVE ID Severity Score Description Published
CVE-2026-45729 MEDIUM 4.3 Thor Vector Graphics (ThorVG) is a production-ready vector graphics engine. Prior to version 1.0.5, a null pointer dereference in SvgLoader::run() allows any caller that passes … Jun 01, 2026
CVE-2026-45727 UNKNOWN CloakBrowser is a tool to bypass bot detection tests. Prior to version 0.3.28, the cloakserve CDP multiplexer uses the user-supplied fingerprint query parameter directly as … Jun 01, 2026
CVE-2026-45722 HIGH 7.1 Nextcloud is an open source content collaboration platform. From versions 0.9.0 to before 0.9.7, and 1.0.0 to before 1.0.2, a missing sanitization in the Tables … Jun 01, 2026
CVE-2026-45691 MEDIUM 5.9 Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.9, and 33.0.0 to before 33.0.3, a pre-2FA session … Jun 01, 2026
CVE-2026-45690 MEDIUM 5.9 Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.9, and 33.0.0 to before 33.0.3, an authentication bypass … Jun 01, 2026
CVE-2026-45545 HIGH 8.2 Nextcloud is an open source content collaboration platform. From versions 0.7.0 to before 0.7.7, 0.8.0 to before 0.8.10, 0.9.0 to before 0.9.8, and 1.0.0 to … Jun 01, 2026
CVE-2026-45544 MEDIUM 4.3 Nextcloud is an open source content collaboration platform. From version 0.8.0 to before version 1.0.4, the view filter criteria is exposed to users with read-only … Jun 01, 2026
CVE-2026-45543 MEDIUM 5.3 Nextcloud is an open source content collaboration platform. From version 4.3.0 to before version 5.2.7, a removed collaborator retains unauthorized read access to uploaded respondent … Jun 01, 2026
CVE-2026-45302 HIGH 8.2 parse-nested-form-data is a tiny node module for parsing FormData by name into objects and arrays. Prior to version 1.0.1, parseFormData() walks bracket and dot-notation FormData … Jun 01, 2026
CVE-2026-45286 MEDIUM 4.3 Nextcloud is an open source content collaboration platform. From versions 5.5.13 to before 5.5.17, and 6.2.0 to before 6.2.3, an authenticated user can enumerate users … Jun 01, 2026
CVE-2026-45285 MEDIUM 6.4 Nextcloud is an open source content collaboration platform. From versions 32.0.0 to before 32.0.9, and 33.0.0 to before 33.0.3, when a user shares a folder … Jun 01, 2026
CVE-2026-45284 MEDIUM 4.6 Nextcloud is an open source content collaboration platform. From version 1.3.6 to before version 8.4.0, an improper check allowed users that where provided by LDAP … Jun 01, 2026
CVE-2026-45283 MEDIUM 6.3 Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.2, and 33.0.0 to before 33.0.1, the files_lock app … Jun 01, 2026
CVE-2026-45282 MEDIUM 6.5 Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.9, and 33.0.0 to before 33.0.3, an authenticated attacker … Jun 01, 2026
CVE-2026-45281 HIGH 8.1 Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.9, and 33.0.0 to before 33.0.3, with the knowledge … Jun 01, 2026
CVE-2026-45279 MEDIUM 4.4 Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 31.0.0 to before 31.0.14, and 32.0.0 to before 32.0.4, if {lang} is … Jun 01, 2026
CVE-2026-45278 LOW 3.3 Nextcloud is an open source content collaboration platform. From version 6.1.0 to before version 8.2.2, an attacker can craft links that would redirect users to … Jun 01, 2026
CVE-2026-45277 LOW 3.3 Nextcloud is an open source content collaboration platform. Prior to version 2.7.2, authenticated users can check if arbitrary files are associated with specific approval workflows … Jun 01, 2026
CVE-2026-45275 MEDIUM 6.5 Nextcloud is an open source content collaboration platform. Prior to version 2.7.2, a privilege escalation vulnerability exists in the Approval app that allows a user … Jun 01, 2026
CVE-2026-43958 HIGH 7.8 A flaw was found in rrdcached, a component of rrdtool. A local attacker with access to a rrdcached socket can exploit a stack-based buffer overflow … Jun 01, 2026
CVE-2026-43625 MEDIUM 5.9 CodexBar prior to 0.32.0 contains a session cookie leakage vulnerability that allows network attackers to intercept imported browser session cookies by exploiting improper redirect handling … Jun 01, 2026
CVE-2026-43624 HIGH 8.2 F5-TTS through version 1.1.20 contains a path traversal vulnerability in the finetune Gradio handlers that allows unauthenticated attackers to write arbitrary files by passing unsanitized … Jun 01, 2026
CVE-2026-43623 HIGH 8.8 microtar through 0.1.0 contains a stack-based buffer overflow vulnerability in the raw_to_header() function in src/microtar.c that allows attackers to corrupt adjacent stack memory by supplying … Jun 01, 2026
CVE-2026-41013 HIGH 8.1 Input validation bypass in SMB volume mount handling in CloudFoundry Foundation diego-release allows low-privileged CF space developer to inject arbitrary kernel CIFS mount options via … Jun 01, 2026
CVE-2026-40990 MEDIUM 5.7 OOM error is possible while attempting to add infinite amount of functions to Function Registry. Affected Spring Products and Versions: Spring Cloud Function 3.2.x: versions … Jun 01, 2026