Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
26391
Total
1955
Critical
7971
High
8223
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-48999 | MEDIUM | 5.7 | Attackers carefully craft malicious scripts, such as JavaScript, and inject them into target systems; when other users access pages containing such malicious content, the scripts … | May 27, 2026 |
| CVE-2026-48962 | HIGH | 7.3 | IO::Compress versions before 2.220 for Perl can execute arbitrary code in File::GlobMapper via an attacker-controlled output glob. _parseOutputGlob() wraps the caller-supplied output glob string in … | May 27, 2026 |
| CVE-2026-48961 | UNKNOWN | — | IO::Compress versions from 2.207 before 2.220 for Perl ship a zipdetails CLI tool that crashes with undefined subroutine on Info-ZIP Unix Extra Field with 8-byte … | May 27, 2026 |
| CVE-2026-48959 | UNKNOWN | — | IO::Uncompress::Unzip versions before 2.220 for Perl allow CPU exhaustion via per-byte read loop in fastForward. fastForward() compares length $offset (the digit count of the offset, … | May 27, 2026 |
| CVE-2026-2255 | MEDIUM | 4.3 | Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.6 and 11.0.0.0, including 9.3.x and 8.3.x, expose Hadoop cluster credentials in plain text through the … | May 27, 2026 |
| CVE-2026-2254 | MEDIUM | 6.3 | Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.6 and 11.0.0.0, including 9.3.x and 8.3.x, does not apply ACLs on certain API endpoints related … | May 27, 2026 |
| CVE-2026-2253 | HIGH | 7.7 | Hitachi Vantara Pentaho Data Integration & Analytics versions before 10.2.0.7 and 11.0.0.0, including 9.3.x and 8.3.x, does not prevent certain XML parsers from resolving external … | May 27, 2026 |
| CVE-2025-15649 | UNKNOWN | — | IO::Uncompress::Unzip versions before 2.215 for Perl propagate uncaught exception when parsing zip header with malformed DOS date. _dosToUnixTime() decodes the local-file-header last-modification date field and … | May 27, 2026 |
| CVE-2026-9632 | HIGH | 8.8 | A flaw has been found in UTT HiPER 1250GW up to 3.2.7-210907-180535. Affected by this issue is the function strcpy of the file /goform/formGroupConfig of … | May 27, 2026 |
| CVE-2026-9631 | HIGH | 8.8 | A vulnerability was detected in UTT HiPER 1250GW up to 3.2.7-210907-180535. Affected by this vulnerability is the function strcpy of the file /goform/formConfigFastDirectionW of the … | May 27, 2026 |
| CVE-2026-9628 | HIGH | 8.8 | A weakness has been identified in UTT HiPER 1200GW up to 2.5.3-170306. Affected is an unknown function of the file /goform/formPptpClientConfig of the component Web … | May 27, 2026 |
| CVE-2026-9627 | HIGH | 8.8 | A security flaw has been discovered in UTT HiPER 1200GW up to 2.5.3-170306. This impacts the function strcpy of the file /goform/setSysAdm of the component … | May 27, 2026 |
| CVE-2026-9609 | MEDIUM | 4.7 | A vulnerability was identified in QianFox FoxCMS up to 1.2.6. This affects the function Edit of the file Admin.php. The manipulation leads to weak password … | May 27, 2026 |
| CVE-2026-9608 | LOW | 2.4 | A vulnerability was determined in QianFox FoxCMS up to 1.2.6. The impacted element is an unknown function of the file /Tag/edit of the component Administrator … | May 27, 2026 |
| CVE-2026-9207 | HIGH | 8.8 | Tanium addressed an unauthorized code execution vulnerability in Connect. | May 27, 2026 |
| CVE-2026-9156 | MEDIUM | 6.5 | Tanium addressed a denial of service vulnerability in Tanium Server. | May 27, 2026 |
| CVE-2026-7493 | MEDIUM | 5.3 | The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to denial of service in all versions up to, and … | May 27, 2026 |
| CVE-2026-6565 | MEDIUM | 6.4 | The Style Kits – Advanced Theme Styles for Elementor, Elementor Kits & Elementor Patterns plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the … | May 27, 2026 |
| CVE-2026-49017 | UNKNOWN | — | In OpenStack Swift before 2.36.2 and 2.37.2, s3api middleware enters an infinite loop when processing a truncated aws-chunked PUT request body. The StreamingInput class repeatedly … | May 27, 2026 |
| CVE-2026-49014 | HIGH | 7.4 | In GDAL 3.1.0 through 3.13.0, scanForGeometryContainers in the netCDF driver allows code execution via a stack-based buffer overflow. It reads a geometry attribute into a … | May 27, 2026 |
| CVE-2026-9607 | MEDIUM | 6.3 | A vulnerability was found in itsourcecode Courier Management System 1.0. The affected element is an unknown function of the file /parcel_list.php. Performing a manipulation of … | May 27, 2026 |
| CVE-2026-9606 | HIGH | 7.3 | A vulnerability has been found in itsourcecode Courier Management System 1.0. Impacted is an unknown function of the file /manage_user.php. Such manipulation of the argument … | May 27, 2026 |
| CVE-2026-9605 | HIGH | 7.3 | A flaw has been found in GNU libredwg up to 0.13.4.8160. This issue affects the function bit_read_RC of the file bits.c of the component Dwgbmp … | May 27, 2026 |
| CVE-2026-9312 | UNKNOWN | — | A server-side request forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to send crafted requests to internal services by … | May 27, 2026 |
| CVE-2026-8606 | UNKNOWN | — | A Server-Side Request Forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an attacker to cause the server to issue HTTP requests to … | May 27, 2026 |