Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

26391
Total
1955
Critical
7971
High
8223
Medium
CVE ID Severity Score Description Published
CVE-2026-48999 MEDIUM 5.7 Attackers carefully craft malicious scripts, such as JavaScript, and inject them into target systems; when other users access pages containing such malicious content, the scripts … May 27, 2026
CVE-2026-48962 HIGH 7.3 IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob. _parseOutputGlob() wraps the caller-supplied output glob string in … May 27, 2026
CVE-2026-48961 UNKNOWN IO::Compress versions from 2.207 before 2.220 for Perl ship a zipdetails CLI tool that crashes with undefined subroutine on Info-ZIP Unix Extra Field with 8-byte … May 27, 2026
CVE-2026-48959 UNKNOWN IO::Uncompress::Unzip versions before 2.220 for Perl allow CPU exhaustion via per-byte read loop in fastForward. fastForward() compares length $offset (the digit count of the offset, … May 27, 2026
CVE-2026-2255 MEDIUM 4.3 Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.6 and 11.0.0.0, including 9.3.x and 8.3.x, expose Hadoop cluster credentials in plain text through the … May 27, 2026
CVE-2026-2254 MEDIUM 6.3 Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.6 and 11.0.0.0, including 9.3.x and 8.3.x, does not apply ACLs on certain API endpoints related … May 27, 2026
CVE-2026-2253 HIGH 7.7 Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.7 and 11.0.0.0, including 9.3.x and 8.3.x, does not prevent certain XML parsers from resolving external … May 27, 2026
CVE-2025-15649 UNKNOWN IO::Uncompress::Unzip versions before 2.215 for Perl propagate uncaught exception when parsing zip header with malformed DOS date. _dosToUnixTime() decodes the local-file-header last-modification date field and … May 27, 2026
CVE-2026-9632 HIGH 8.8 A flaw has been found in UTT HiPER 1250GW up to 3.2.7-210907-180535. Affected by this issue is the function strcpy of the file /goform/formGroupConfig of … May 27, 2026
CVE-2026-9631 HIGH 8.8 A vulnerability was detected in UTT HiPER 1250GW up to 3.2.7-210907-180535. Affected by this vulnerability is the function strcpy of the file /goform/formConfigFastDirectionW of the … May 27, 2026
CVE-2026-9628 HIGH 8.8 A weakness has been identified in UTT HiPER 1200GW up to 2.5.3-170306. Affected is an unknown function of the file /goform/formPptpClientConfig of the component Web … May 27, 2026
CVE-2026-9627 HIGH 8.8 A security flaw has been discovered in UTT HiPER 1200GW up to 2.5.3-170306. This impacts the function strcpy of the file /goform/setSysAdm of the component … May 27, 2026
CVE-2026-9609 MEDIUM 4.7 A vulnerability was identified in QianFox FoxCMS up to 1.2.6. This affects the function Edit of the file Admin.php. The manipulation leads to weak password … May 27, 2026
CVE-2026-9608 LOW 2.4 A vulnerability was determined in QianFox FoxCMS up to 1.2.6. The impacted element is an unknown function of the file /Tag/edit of the component Administrator … May 27, 2026
CVE-2026-9207 HIGH 8.8 Tanium addressed an unauthorized code execution vulnerability in Connect. May 27, 2026
CVE-2026-9156 MEDIUM 6.5 Tanium addressed a denial of service vulnerability in Tanium Server. May 27, 2026
CVE-2026-7493 MEDIUM 5.3 The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to denial of service in all versions up to, and … May 27, 2026
CVE-2026-6565 MEDIUM 6.4 The Style Kits – Advanced Theme Styles for Elementor, Elementor Kits & Elementor Patterns plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the … May 27, 2026
CVE-2026-49017 UNKNOWN In OpenStack Swift before 2.36.2 and 2.37.2, s3api middleware enters an infinite loop when processing a truncated aws-chunked PUT request body. The StreamingInput class repeatedly … May 27, 2026
CVE-2026-49014 HIGH 7.4 In GDAL 3.1.0 through 3.13.0, scanForGeometryContainers in the netCDF driver allows code execution via a stack-based buffer overflow. It reads a geometry attribute into a … May 27, 2026
CVE-2026-9607 MEDIUM 6.3 A vulnerability was found in itsourcecode Courier Management System 1.0. The affected element is an unknown function of the file /parcel_list.php. Performing a manipulation of … May 27, 2026
CVE-2026-9606 HIGH 7.3 A vulnerability has been found in itsourcecode Courier Management System 1.0. Impacted is an unknown function of the file /manage_user.php. Such manipulation of the argument … May 27, 2026
CVE-2026-9605 HIGH 7.3 A flaw has been found in GNU libredwg up to 0.13.4.8160. This issue affects the function bit_read_RC of the file bits.c of the component Dwgbmp … May 27, 2026
CVE-2026-9312 UNKNOWN A server-side request forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to send crafted requests to internal services by … May 27, 2026
CVE-2026-8606 UNKNOWN A Server-Side Request Forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an attacker to cause the server to issue HTTP requests to … May 27, 2026