Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
25513
Total
1895
Critical
7789
High
8000
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-10256 | MEDIUM | 6.3 | A vulnerability was identified in itsourcecode Content Management System 1.0. This vulnerability affects unknown code of the file /save_comment.php. The manipulation of the argument Name … | Jun 01, 2026 |
| CVE-2026-10255 | MEDIUM | 5.3 | A vulnerability has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. Affected by this vulnerability is the function sell_statement of the file application/controllers/ShowForm.php. … | Jun 01, 2026 |
| CVE-2026-10254 | MEDIUM | 5.3 | A flaw has been found in SourceCodester Pet Grooming Management Software 1.0. Affected is an unknown function of the file /admin/. This manipulation causes file … | Jun 01, 2026 |
| CVE-2026-10253 | HIGH | 7.3 | A vulnerability was detected in itsourcecode Online House Rental System 1.0. This impacts an unknown function of the file /manage_payment.php. The manipulation of the argument … | Jun 01, 2026 |
| CVE-2026-10252 | HIGH | 7.3 | A security vulnerability has been detected in itsourcecode Online House Rental System 1.0. This affects an unknown function of the file /manage_tenant.php. The manipulation of … | Jun 01, 2026 |
| CVE-2026-10251 | HIGH | 7.3 | A weakness has been identified in itsourcecode Online House Rental System 1.0. The impacted element is an unknown function of the file /ajax.php?action=login. Executing a … | Jun 01, 2026 |
| CVE-2026-49328 | MEDIUM | 5.3 | Server-Side Request Forgery (SSRF) in the UrlImageConverter component of Apache Fesod (Incubating) fesod-sheet before 2.0.2-incubating allows attackers to cause outbound network requests to internal or … | Jun 01, 2026 |
| CVE-2026-25600 | MEDIUM | 6.4 | The PDBM application relies on a static, hard‑coded secret embedded in the PDBM.exe executable. This secret is used by the application’s encryption routines, including the … | Jun 01, 2026 |
| CVE-2026-25599 | MEDIUM | 6.3 | Missing authentication and clear‑text transmission of data from the heat pumps to the control server, combined with the absence of input validation on aggregated data, … | Jun 01, 2026 |
| CVE-2026-10250 | HIGH | 7.3 | A security flaw has been discovered in itsourcecode Online Blood Bank Management System 1.0. The affected element is an unknown function of the file /admin/campsdetails.php. … | Jun 01, 2026 |
| CVE-2026-10249 | HIGH | 7.3 | A vulnerability was identified in itsourcecode Online Blood Bank Management System 1.0. Impacted is an unknown function of the file /admin/viewrequest.php. Such manipulation of the … | Jun 01, 2026 |
| CVE-2026-10248 | MEDIUM | 4.7 | A vulnerability was determined in SourceCodester Pharmacy Sales and Inventory System up to 1.0. This issue affects the function create_supplier of the file /Export_csv/export of … | Jun 01, 2026 |
| CVE-2026-10247 | LOW | 3.5 | A vulnerability was found in SourceCodester Pharmacy Sales and Inventory System 1.0. This vulnerability affects the function create_generic_name of the file /ShowForm/create_generic_name/main. The manipulation of … | Jun 01, 2026 |
| CVE-2026-10246 | LOW | 3.5 | A vulnerability has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. This affects the function create_medicine_presentation of the file /ShowForm/create_medicine_presentation/main. The manipulation of … | Jun 01, 2026 |
| CVE-2026-10245 | LOW | 3.5 | A flaw has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. Affected by this issue is the function create_supplier of the file /ShowForm/create_supplier/main. … | Jun 01, 2026 |
| CVE-2026-10244 | LOW | 3.5 | A vulnerability was detected in SourceCodester Pharmacy Sales and Inventory System 1.0. Affected by this vulnerability is the function create_medicine_name of the file /ShowForm/create_medicine_name/main. Performing … | Jun 01, 2026 |
| CVE-2026-9024 | HIGH | 8.7 | A Stored Cross-site Scripting (XSS) vulnerability affecting Process Experience Studio in DELMIA Service Process Engineer from Release 3DEXPERIENCE R2024x through Release 3DEXPERIENCE R2026x could allow … | Jun 01, 2026 |
| CVE-2026-8474 | MEDIUM | 5.3 | A vulnerability was discovered on Stormshield Network Security * 4.3.0 to 4.3.41, * 4.8.0 to 4.8.15, * 5.0.0 to 5.0.5 It is possible to execute … | Jun 01, 2026 |
| CVE-2026-7858 | CRITICAL | 9.8 | A Deserialization of Untrusted Data vulnerability affecting Teamwork Cloud from No Magic Release 2022x through No Magic Release 2026x and Magic Collaboration Studio from CATIA … | Jun 01, 2026 |
| CVE-2026-49361 | HIGH | 7.5 | Apache Fluss versions prior to 0.9.1 configure the Netty LengthFieldBasedFrameDecoder with Integer.MAX_VALUE as the maximum frame length, allowing unauthenticated remote attackers to exhaust JVM heap … | Jun 01, 2026 |
| CVE-2026-49298 | UNKNOWN | — | A bug in Apache Airflow's KubernetesExecutor caused JWT tokens used by worker pods to authenticate against the Execution API to be passed to the worker … | Jun 01, 2026 |
| CVE-2026-49270 | MEDIUM | 5.9 | Exposure of Sensitive Information Through Metadata vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All. Brokers that are configured with a network connector with … | Jun 01, 2026 |
| CVE-2026-49267 | UNKNOWN | — | Apache Airflow's EmailOperator and the underlying `airflow.utils.email` helpers established SMTP STARTTLS connections without verifying the remote certificate when the deployment used `[email] smtp_starttls=True` without `[email] … | Jun 01, 2026 |
| CVE-2026-49157 | HIGH | 8.8 | Incorrect Default Permissions vulnerability in Apache ActiveMQ. This issue affects Apache ActiveMQ: before 5.19.7, from 6.0.0 before 6.2.6. The default Jolokia authorization settings granted non-admin … | Jun 01, 2026 |
| CVE-2026-48827 | HIGH | 7.1 | Path traversal vulnerability in Apache MINA SSHD bundle sshd-git. Lack of path validation in git-upload-pack, git-receive-pack, and other git operations allows users authenticated over SSH … | Jun 01, 2026 |