Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
25513
Total
1895
Critical
7789
High
8000
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-45701 | UNKNOWN | — | Sulu is an open-source PHP content management system based on the Symfony framework. Prior to versions 2.6.23 and 3.0.6, the password reset tokenand API key … | Jun 01, 2026 |
| CVE-2026-45267 | MEDIUM | 6.5 | Nextcloud is an open source content collaboration platform. Prior to version 5.2.6, a missing permissions check allowed users to request reading form submissions of other … | Jun 01, 2026 |
| CVE-2026-45266 | LOW | 3.5 | Nextcloud is an open source content collaboration platform. Prior to versions 21.1.10, 22.0.11, and 23.0.3, a low-privileged user can force other user's microphones to be … | Jun 01, 2026 |
| CVE-2026-45264 | MEDIUM | 4.3 | Nextcloud is an open source content collaboration platform. From versions 17.0.0 to before 17.0.15, 18.0.0 to before 18.1.12, 19.0.0 to before 19.1.16, 20.0.0 to before … | Jun 01, 2026 |
| CVE-2026-45159 | LOW | 3.5 | Nextcloud is an open source content collaboration platform. From versions 1.15.0 to before 1.15.4, 1.16.0 to before 1.16.3, 1.17.0 to before 1.17.1, and 1.18.0 to … | Jun 01, 2026 |
| CVE-2026-45157 | MEDIUM | 6.3 | Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.9, and 33.0.0 to before 33.0.3, when a malicious … | Jun 01, 2026 |
| CVE-2026-45156 | HIGH | 8.1 | Nextcloud is an open source content collaboration platform. From versions 0.3.0 to before 3.1.0, 5.0.0 to before 5.1.0, and 6.0.0 to before 6.4.0, a missing … | Jun 01, 2026 |
| CVE-2026-45155 | LOW | 2.6 | Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.7 and 33.0.0 to before 33.0.1, a missing access … | Jun 01, 2026 |
| CVE-2026-45154 | LOW | 2.6 | Nextcloud is an open source content collaboration platform. From version 2.6.0 to before version 4.3.0, when a previous collective pages was deleted and the collective … | Jun 01, 2026 |
| CVE-2026-45153 | MEDIUM | 4.6 | Nextcloud is an open source content collaboration platform. From version 33.0.0 to before version 33.1.0, after unlocking a locked Android phone the back-button could be … | Jun 01, 2026 |
| CVE-2026-45132 | CRITICAL | 10.0 | CloudPirates Open Source Helm Charts is a collection of Helm charts. Prior to commit fcf9302, a GitHub Actions workflow (generate-schema.yaml) exposes sensitive credentials (Personal Access … | Jun 01, 2026 |
| CVE-2026-45131 | CRITICAL | 10.0 | CloudPirates Open Source Helm Charts is a collection of Helm charts. Prior to commit fcf9302, a GitHub Actions workflow (pull-request.yaml) executes attacker-controlled code from fork … | Jun 01, 2026 |
| CVE-2026-44740 | MEDIUM | 6.5 | Billy is an interface filesystem abstraction for Go. Prior to versions 5.9.0 and 6.0.0-alpha.1, multiple components may improperly handle crafted or malformed input, resulting in … | Jun 01, 2026 |
| CVE-2026-44211 | CRITICAL | 9.6 | Cline is an autonomous coding agent as an SDK, IDE extension, or CLI assistant. In versions 2.13.0 and prior, there is a cross-origin WebSocket hijack … | Jun 01, 2026 |
| CVE-2026-42679 | MEDIUM | 6.5 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Mamunur Rashid Classified Listing allows Path Traversal. This issue affects Classified Listing: … | Jun 01, 2026 |
| CVE-2026-42678 | HIGH | 7.1 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Liquid Web / StellarWP GiveWP allows DOM-Based XSS. This issue affects GiveWP: from … | Jun 01, 2026 |
| CVE-2026-42677 | HIGH | 7.5 | Missing Authorization vulnerability in Ben Balter WP Document Revisions allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP Document Revisions: from n/a … | Jun 01, 2026 |
| CVE-2026-42676 | MEDIUM | 6.5 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in myCred allows Stored XSS. This issue affects myCred: from n/a through 3.0.4. | Jun 01, 2026 |
| CVE-2026-42675 | HIGH | 7.3 | Missing Authorization vulnerability in Themefic Hydra Booking allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Hydra Booking: from n/a through 1.1.41. | Jun 01, 2026 |
| CVE-2026-42674 | HIGH | 7.5 | Authentication Bypass by Spoofing vulnerability in AAM Plugin Advanced Access Manager allows URL Encoding. This issue affects Advanced Access Manager: from n/a through 7.1.0. | Jun 01, 2026 |
| CVE-2026-42673 | HIGH | 7.5 | Insertion of Sensitive Information Into Sent Data vulnerability in Logtivity Activity Logs Activity Logs, User Activity Tracking, Multisite Activity Log from Logtivity allows Retrieve Embedded … | Jun 01, 2026 |
| CVE-2026-42672 | CRITICAL | 9.3 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Wp Directory Kit WP Directory Kit allows Blind SQL Injection. This … | Jun 01, 2026 |
| CVE-2026-42671 | MEDIUM | 6.5 | Missing Authorization vulnerability in Paolo GeoDirectory allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects GeoDirectory: from n/a through 2.8.157. | Jun 01, 2026 |
| CVE-2026-38950 | HIGH | 7.8 | An issue in ESA AnomalyMatch before 1.3.1 allow attackers to execute arbitrary code via crafted model checkpoint files. The affected components load model files from … | Jun 01, 2026 |
| CVE-2026-37227 | HIGH | 7.5 | FlexRIC v2.0.0 contains reachable assert(0) calls in stub message handlers for whitelisted but unimplemented E2AP message types in the near-RT RIC. A remote unauthenticated attacker … | Jun 01, 2026 |