Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

25513
Total
1895
Critical
7789
High
8000
Medium
CVE ID Severity Score Description Published
CVE-2026-10256 MEDIUM 6.3 A vulnerability was identified in itsourcecode Content Management System 1.0. This vulnerability affects unknown code of the file /save_comment.php. The manipulation of the argument Name … Jun 01, 2026
CVE-2026-10255 MEDIUM 5.3 A vulnerability has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. Affected by this vulnerability is the function sell_statement of the file application/controllers/ShowForm.php. … Jun 01, 2026
CVE-2026-10254 MEDIUM 5.3 A flaw has been found in SourceCodester Pet Grooming Management Software 1.0. Affected is an unknown function of the file /admin/. This manipulation causes file … Jun 01, 2026
CVE-2026-10253 HIGH 7.3 A vulnerability was detected in itsourcecode Online House Rental System 1.0. This impacts an unknown function of the file /manage_payment.php. The manipulation of the argument … Jun 01, 2026
CVE-2026-10252 HIGH 7.3 A security vulnerability has been detected in itsourcecode Online House Rental System 1.0. This affects an unknown function of the file /manage_tenant.php. The manipulation of … Jun 01, 2026
CVE-2026-10251 HIGH 7.3 A weakness has been identified in itsourcecode Online House Rental System 1.0. The impacted element is an unknown function of the file /ajax.php?action=login. Executing a … Jun 01, 2026
CVE-2026-49328 MEDIUM 5.3 Server-Side Request Forgery (SSRF) in the UrlImageConverter component of Apache Fesod (Incubating) fesod-sheet before 2.0.2-incubating allows attackers to cause outbound network requests to internal or … Jun 01, 2026
CVE-2026-25600 MEDIUM 6.4 The PDBM application relies on a static, hard‑coded secret embedded in the PDBM.exe executable. This secret is used by the application’s encryption routines, including the … Jun 01, 2026
CVE-2026-25599 MEDIUM 6.3 Missing authentication and clear‑text transmission of data from the heat pumps to the control server, combined with the absence of input validation on aggregated data, … Jun 01, 2026
CVE-2026-10250 HIGH 7.3 A security flaw has been discovered in itsourcecode Online Blood Bank Management System 1.0. The affected element is an unknown function of the file /admin/campsdetails.php. … Jun 01, 2026
CVE-2026-10249 HIGH 7.3 A vulnerability was identified in itsourcecode Online Blood Bank Management System 1.0. Impacted is an unknown function of the file /admin/viewrequest.php. Such manipulation of the … Jun 01, 2026
CVE-2026-10248 MEDIUM 4.7 A vulnerability was determined in SourceCodester Pharmacy Sales and Inventory System up to 1.0. This issue affects the function create_supplier of the file /Export_csv/export of … Jun 01, 2026
CVE-2026-10247 LOW 3.5 A vulnerability was found in SourceCodester Pharmacy Sales and Inventory System 1.0. This vulnerability affects the function create_generic_name of the file /ShowForm/create_generic_name/main. The manipulation of … Jun 01, 2026
CVE-2026-10246 LOW 3.5 A vulnerability has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. This affects the function create_medicine_presentation of the file /ShowForm/create_medicine_presentation/main. The manipulation of … Jun 01, 2026
CVE-2026-10245 LOW 3.5 A flaw has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. Affected by this issue is the function create_supplier of the file /ShowForm/create_supplier/main. … Jun 01, 2026
CVE-2026-10244 LOW 3.5 A vulnerability was detected in SourceCodester Pharmacy Sales and Inventory System 1.0. Affected by this vulnerability is the function create_medicine_name of the file /ShowForm/create_medicine_name/main. Performing … Jun 01, 2026
CVE-2026-9024 HIGH 8.7 A Stored Cross-site Scripting (XSS) vulnerability affecting Process Experience Studio in DELMIA Service Process Engineer from Release 3DEXPERIENCE R2024x through Release 3DEXPERIENCE R2026x could allow … Jun 01, 2026
CVE-2026-8474 MEDIUM 5.3 A vulnerability was discovered on Stormshield Network Security * 4.3.0 to 4.3.41, * 4.8.0 to 4.8.15, * 5.0.0 to 5.0.5 It is possible to execute … Jun 01, 2026
CVE-2026-7858 CRITICAL 9.8 A Deserialization of Untrusted Data vulnerability affecting Teamwork Cloud from No Magic Release 2022x through No Magic Release 2026x and Magic Collaboration Studio from CATIA … Jun 01, 2026
CVE-2026-49361 HIGH 7.5 Apache Fluss versions prior to 0.9.1 configure the Netty LengthFieldBasedFrameDecoder with Integer.MAX_VALUE as the maximum frame length, allowing unauthenticated remote attackers to exhaust JVM heap … Jun 01, 2026
CVE-2026-49298 UNKNOWN A bug in Apache Airflow's KubernetesExecutor caused JWT tokens used by worker pods to authenticate against the Execution API to be passed to the worker … Jun 01, 2026
CVE-2026-49270 MEDIUM 5.9 Exposure of Sensitive Information Through Metadata vulnerability in Apache ActiveMQ Broker, Apache ActiveMQ, Apache ActiveMQ All. Brokers that are configured with a network connector with … Jun 01, 2026
CVE-2026-49267 UNKNOWN Apache Airflow's EmailOperator and the underlying `airflow.utils.email` helpers established SMTP STARTTLS connections without verifying the remote certificate when the deployment used `[email] smtp_starttls=True` without `[email] … Jun 01, 2026
CVE-2026-49157 HIGH 8.8 Incorrect Default Permissions vulnerability in Apache ActiveMQ. This issue affects Apache ActiveMQ: before 5.19.7, from 6.0.0 before 6.2.6. The default Jolokia authorization settings granted non-admin … Jun 01, 2026
CVE-2026-48827 HIGH 7.1 Path traversal vulnerability in Apache MINA SSHD bundle sshd-git. Lack of path validation in git-upload-pack, git-receive-pack, and other git operations allows users authenticated over SSH … Jun 01, 2026