Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

25513
Total
1895
Critical
7789
High
8000
Medium
CVE ID Severity Score Description Published
CVE-2026-45701 UNKNOWN Sulu is an open-source PHP content management system based on the Symfony framework. Prior to versions 2.6.23 and 3.0.6, the password reset tokenand API key … Jun 01, 2026
CVE-2026-45267 MEDIUM 6.5 Nextcloud is an open source content collaboration platform. Prior to version 5.2.6, a missing permissions check allowed users to request reading form submissions of other … Jun 01, 2026
CVE-2026-45266 LOW 3.5 Nextcloud is an open source content collaboration platform. Prior to versions 21.1.10, 22.0.11, and 23.0.3, a low-privileged user can force other user's microphones to be … Jun 01, 2026
CVE-2026-45264 MEDIUM 4.3 Nextcloud is an open source content collaboration platform. From versions 17.0.0 to before 17.0.15, 18.0.0 to before 18.1.12, 19.0.0 to before 19.1.16, 20.0.0 to before … Jun 01, 2026
CVE-2026-45159 LOW 3.5 Nextcloud is an open source content collaboration platform. From versions 1.15.0 to before 1.15.4, 1.16.0 to before 1.16.3, 1.17.0 to before 1.17.1, and 1.18.0 to … Jun 01, 2026
CVE-2026-45157 MEDIUM 6.3 Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.9, and 33.0.0 to before 33.0.3, when a malicious … Jun 01, 2026
CVE-2026-45156 HIGH 8.1 Nextcloud is an open source content collaboration platform. From versions 0.3.0 to before 3.1.0, 5.0.0 to before 5.1.0, and 6.0.0 to before 6.4.0, a missing … Jun 01, 2026
CVE-2026-45155 LOW 2.6 Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 32.0.0 to before 32.0.7 and 33.0.0 to before 33.0.1, a missing access … Jun 01, 2026
CVE-2026-45154 LOW 2.6 Nextcloud is an open source content collaboration platform. From version 2.6.0 to before version 4.3.0, when a previous collective pages was deleted and the collective … Jun 01, 2026
CVE-2026-45153 MEDIUM 4.6 Nextcloud is an open source content collaboration platform. From version 33.0.0 to before version 33.1.0, after unlocking a locked Android phone the back-button could be … Jun 01, 2026
CVE-2026-45132 CRITICAL 10.0 CloudPirates Open Source Helm Charts is a collection of Helm charts. Prior to commit fcf9302, a GitHub Actions workflow (generate-schema.yaml) exposes sensitive credentials (Personal Access … Jun 01, 2026
CVE-2026-45131 CRITICAL 10.0 CloudPirates Open Source Helm Charts is a collection of Helm charts. Prior to commit fcf9302, a GitHub Actions workflow (pull-request.yaml) executes attacker-controlled code from fork … Jun 01, 2026
CVE-2026-44740 MEDIUM 6.5 Billy is an interface filesystem abstraction for Go. Prior to versions 5.9.0 and 6.0.0-alpha.1, multiple components may improperly handle crafted or malformed input, resulting in … Jun 01, 2026
CVE-2026-44211 CRITICAL 9.6 Cline is an autonomous coding agent as an SDK, IDE extension, or CLI assistant. In versions 2.13.0 and prior, there is a cross-origin WebSocket hijack … Jun 01, 2026
CVE-2026-42679 MEDIUM 6.5 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Mamunur Rashid Classified Listing allows Path Traversal. This issue affects Classified Listing: … Jun 01, 2026
CVE-2026-42678 HIGH 7.1 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Liquid Web / StellarWP GiveWP allows DOM-Based XSS. This issue affects GiveWP: from … Jun 01, 2026
CVE-2026-42677 HIGH 7.5 Missing Authorization vulnerability in Ben Balter WP Document Revisions allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP Document Revisions: from n/a … Jun 01, 2026
CVE-2026-42676 MEDIUM 6.5 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in myCred allows Stored XSS. This issue affects myCred: from n/a through 3.0.4. Jun 01, 2026
CVE-2026-42675 HIGH 7.3 Missing Authorization vulnerability in Themefic Hydra Booking allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Hydra Booking: from n/a through 1.1.41. Jun 01, 2026
CVE-2026-42674 HIGH 7.5 Authentication Bypass by Spoofing vulnerability in AAM Plugin Advanced Access Manager allows URL Encoding. This issue affects Advanced Access Manager: from n/a through 7.1.0. Jun 01, 2026
CVE-2026-42673 HIGH 7.5 Insertion of Sensitive Information Into Sent Data vulnerability in Logtivity Activity Logs Activity Logs, User Activity Tracking, Multisite Activity Log from Logtivity allows Retrieve Embedded … Jun 01, 2026
CVE-2026-42672 CRITICAL 9.3 Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Wp Directory Kit WP Directory Kit allows Blind SQL Injection. This … Jun 01, 2026
CVE-2026-42671 MEDIUM 6.5 Missing Authorization vulnerability in Paolo GeoDirectory allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects GeoDirectory: from n/a through 2.8.157. Jun 01, 2026
CVE-2026-38950 HIGH 7.8 An issue in ESA AnomalyMatch before 1.3.1 allow attackers to execute arbitrary code via crafted model checkpoint files. The affected components load model files from … Jun 01, 2026
CVE-2026-37227 HIGH 7.5 FlexRIC v2.0.0 contains reachable assert(0) calls in stub message handlers for whitelisted but unimplemented E2AP message types in the near-RT RIC. A remote unauthenticated attacker … Jun 01, 2026