Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
25534
Total
1899
Critical
7798
High
8005
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-10111 | HIGH | 7.3 | A flaw has been found in sambitraj STUDENT-MANAGEMENT-SYSTEM 1.0. This impacts an unknown function of the component Login Page. Executing a manipulation of the argument … | May 30, 2026 |
| CVE-2026-10110 | HIGH | 7.3 | A vulnerability was detected in code-projects Student Details Management System 1.0. This affects an unknown function of the file /index.php. Performing a manipulation of the … | May 30, 2026 |
| CVE-2026-48840 | MEDIUM | 5.3 | Exim 4.88 before 4.99.4, in some proxy configurations, mishandles certain short payloads, leading to disclosure of uninitialized stack memory values to a client. | May 30, 2026 |
| CVE-2026-9831 | MEDIUM | 6.3 | A race condition in the shared Extreme Platform ONE IAM Gateway API-key authentication path could, under specific high-concurrency traffic conditions, intermittently allow requests authenticated with … | May 29, 2026 |
| CVE-2026-4387 | UNKNOWN | — | StrongDM Desktop Application before 23.74.0 (Desktop Client before 53.77.0) on Microsoft Windows stores authentication state, including a JSON Web Token and asymmetric key material, in … | May 29, 2026 |
| CVE-2026-48811 | MEDIUM | 4.3 | FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to 1.8.221, FreeScout allows a non-admin user to permanently delete … | May 29, 2026 |
| CVE-2026-48810 | MEDIUM | 4.3 | FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to 1.8.221, while investigating the ThreadPolicy::delete issue reported previously, the … | May 29, 2026 |
| CVE-2026-48557 | HIGH | 8.8 | Spatie Laravel Media Library before version 11.23.0 contains a file upload restriction bypass in FileAdder::defaultSanitizer(). The sanitizer checks only the final filename suffix, allowing double-extension … | May 29, 2026 |
| CVE-2026-48555 | HIGH | 7.4 | Spatie Laravel Media Library before version 11.23.0 contains a server-side request forgery vulnerability that allows remote attackers to cause the server to issue arbitrary outbound … | May 29, 2026 |
| CVE-2026-47266 | UNKNOWN | — | Formie is a Craft CMS plugin for creating forms. Prior to 2.2.21 and 3.1.26, unauthenticated users could modify existing submissions by posting a known or … | May 29, 2026 |
| CVE-2026-47123 | HIGH | 7.5 | FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to 1.8.220, the email processing pipeline in FreeScout's FetchEmails command … | May 29, 2026 |
| CVE-2026-46599 | UNKNOWN | — | The TIFF decoder does not place a limit on the size of PackBits-compressed data. A maliciously-crafted image can exploit this to cause a small image … | May 29, 2026 |
| CVE-2026-46527 | UNKNOWN | — | cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.44.0, When the server has called Server::set_trusted_proxies() with a non-empty trusted-proxy list, an … | May 29, 2026 |
| CVE-2026-46385 | UNKNOWN | — | iskorotkov/avro is a fast Go Avro codec. Prior to 2.33.0, the Avro array and map decoders looped over an attacker-controlled block-count value without checking the … | May 29, 2026 |
| CVE-2026-46384 | UNKNOWN | — | iskorotkov/avro is a fast Go Avro codec. Prior to 2.33.0, several Avro decoder paths read attacker-controlled 64-bit values from the wire format and either narrowed … | May 29, 2026 |
| CVE-2026-45700 | UNKNOWN | — | FreeRDP is a free implementation of the Remote Desktop Protocol. Prior to 3.26.0, FreeRDP's planar bitmap decoder has an out-of-bounds heap write when decoding RLE … | May 29, 2026 |
| CVE-2026-45697 | CRITICAL | 9.8 | Formie is a Craft CMS plugin for creating forms. Prior to 2.2.20 and 3.1.24, unauthenticated users could submit crafted values into Hidden fields (with Default … | May 29, 2026 |
| CVE-2026-45613 | LOW | 3.3 | Rizin is a UNIX-like reverse engineering framework and command-line toolset. There is a heap-buffer-overflow in librz/bin/format/omf/omf.c. This vulnerability is fixed by commit e6d0937c8a083e23ed76ccfb9f631cdc50c7af47. | May 29, 2026 |
| CVE-2026-45372 | CRITICAL | 9.9 | cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.44.0, when cpp-httplib's server parses an incoming request, it applies percent-decoding to every … | May 29, 2026 |
| CVE-2026-45352 | MEDIUM | 5.3 | cpp-httplib is a C++11 single-file header-only cross platform HTTP/HTTPS library. Prior to 0.43.4, negative chunk-size in chunked Transfer-Encoding causes unbounded memory allocation and process crash. … | May 29, 2026 |
| CVE-2026-45324 | LOW | 3.3 | Rizin is a UNIX-like reverse engineering framework and command-line toolset. There is a double free in librz/core/cmd/cmd_search.c:byte_pattern_search() due wrong pointer ownership declared. This vulnerability is … | May 29, 2026 |
| CVE-2026-45294 | MEDIUM | 5.3 | FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to 1.8.219, the password reset endpoint returns visually distinct responses … | May 29, 2026 |
| CVE-2026-45151 | UNKNOWN | — | NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. In 0.24.8 and earlier, quic_stream_recv can dereference a null substream pointer when a substream is … | May 29, 2026 |
| CVE-2026-45149 | MEDIUM | 6.5 | The brace-expansion library generates arbitrary strings containing a common prefix and suffix. From 5.0.0 to before 5.0.6, the max option was being applied too late. … | May 29, 2026 |
| CVE-2026-44640 | MEDIUM | 4.5 | NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. Prior to 0.24.14, aio->prov_data is stored as nni_quic_conn* during dialing, but read as ex_quic_conn* during … | May 29, 2026 |