Security
CVE Feed
Latest vulnerabilities from the National Vulnerability Database.
26395
Total
1955
Critical
7973
High
8225
Medium
| CVE ID | Severity | Score | Description | Published |
|---|---|---|---|---|
| CVE-2026-41401 | MEDIUM | 6.5 | libyang before 5.2.6 contains a heap use-after-free write vulnerability in lyd_parser_set_data_flags that incorrectly updates metadata list pointers when freeing non-head default metadata entries. Attackers can … | May 26, 2026 |
| CVE-2026-40034 | HIGH | 7.8 | gix-submodule before 0.82.0 incorrectly validates the update field in .gitmodules, allowing attackers to bypass the CommandForbiddenInModulesConfiguration guard when a submodule has been initialized with only … | May 26, 2026 |
| CVE-2026-40033 | HIGH | 8.8 | FreeRDP before 3.26.0 contains a heap-buffer-overflow vulnerability in gdi_CacheToSurface that allows remote attackers to write out-of-bounds heap memory. The vulnerability occurs because rectangle validation clamps … | May 26, 2026 |
| CVE-2026-9544 | HIGH | 7.3 | A vulnerability was found in Shenzhen Sixun Software Sixun Shanghui Group Business Management System 10. Affected by this vulnerability is an unknown functionality of the … | May 26, 2026 |
| CVE-2026-9543 | CRITICAL | 9.8 | A vulnerability has been found in Totolink N300RH 6.1c.1353_B20190305. Affected is the function setPasswordCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Such … | May 26, 2026 |
| CVE-2026-9542 | MEDIUM | 6.3 | A weakness has been identified in CodeAstro Leave Management System 1.0. The affected element is an unknown function of the file /admin/add_staff.php. Executing a manipulation … | May 26, 2026 |
| CVE-2026-9541 | MEDIUM | 5.3 | A security flaw has been discovered in Squirrel up to 3.2. Impacted is the function ReadObject of the file squirrel/sqobject.cpp of the component Cnut File … | May 26, 2026 |
| CVE-2026-9540 | MEDIUM | 5.3 | A vulnerability was identified in vllm-project vllm 0.19.0. This issue affects some unknown processing of the component OpenAI-compatible Serving Path. Such manipulation leads to denial … | May 26, 2026 |
| CVE-2026-8479 | UNKNOWN | — | IEC 60870-5-104 used in bidirectional mode in RTU500 is vulnerable for a NULL pointer dereferencing, if a specially crafted sequence of messages is sent for … | May 26, 2026 |
| CVE-2026-8174 | MEDIUM | 5.7 | Zohocorp Zoho Mail wordpress plugin is vulnerable to Cross-Site request forgery (CSRF). This issue affects Zoho Mail wordpress plugin versions before 1.6.2. | May 26, 2026 |
| CVE-2026-7374 | CRITICAL | 9.9 | A flaw was found in KubeVirt's virt-handler component. This vulnerability allows an authenticated OpenShift user with edit permissions in a single namespace to exploit improper … | May 26, 2026 |
| CVE-2026-7310 | UNKNOWN | — | A heap-based buffer overflow vulnerability exists in XML parser functionality in the HiDraw. An authenticated malicious user with local access can exploit this vulnerability using … | May 26, 2026 |
| CVE-2026-48136 | MEDIUM | 4.1 | When Compliance is enabled on Check Point Multi-Domain Management, an authenticated administrator with read-write access to one Management Domain (CMA) can modify stored metadata associated … | May 26, 2026 |
| CVE-2026-48135 | MEDIUM | 5.3 | A Check Point HTTP-based service can incorrectly handle malformed HTTP requests. The issue is related to HTTP request parsing and validation. | May 26, 2026 |
| CVE-2026-48134 | MEDIUM | 5.6 | When the DLP is active, the UserCheck Web Portal contains an input-handling issue in the UserChoice flow. Under specific conditions, an attacker who can access … | May 26, 2026 |
| CVE-2026-48133 | HIGH | 7.5 | When the Identity Awareness blade is enabled with Browser-Based Authentication, an unauthenticated user may be able to read certain internal files on the Security Gateway. | May 26, 2026 |
| CVE-2026-48132 | HIGH | 8.1 | The Security Gateway does not correctly validate a length value in certain IKE packets when NAT-T is used (4500/UDP). As a result, a specially crafted … | May 26, 2026 |
| CVE-2026-48131 | HIGH | 8.1 | The VPN service may mishandle an unexpected IKE fragment value received on the IKE port 500/UDP during the early stage of a connection attempt. This … | May 26, 2026 |
| CVE-2025-11482 | HIGH | 7.5 | An Allocation of Resources Without Limits or Throttling vulnerability in the OPC-UA Server used in PPT30 Operating System versions before 1.8.0 may be used by … | May 26, 2026 |
| CVE-2026-44410 | LOW | 3.8 | This vulnerability stems from a business logic flaw.Attackers can exploit legitimate application functions in unintended and abnormal ways, deviating from the designer's expectations, to carry … | May 26, 2026 |
| CVE-2026-39661 | HIGH | 7.5 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Magentech SW Core allows PHP Local File Inclusion. This … | May 26, 2026 |
| CVE-2026-39642 | MEDIUM | 5.3 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in SpabRice Nyla allows Code Injection. This issue affects Nyla: from n/a … | May 26, 2026 |
| CVE-2026-27427 | MEDIUM | 6.5 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Dylan Kuhn Geo Mashup allows Stored XSS. This issue affects Geo Mashup: from … | May 26, 2026 |
| CVE-2026-25713 | HIGH | 7.8 | MediaArea MediaInfoLib ID3v2 parsing heap buffer overflow vulnerability | May 26, 2026 |
| CVE-2026-25104 | HIGH | 7.8 | MediaArea MediaInfoLib LXF parsing heap-based buffer overflow vulnerability | May 26, 2026 |