Loading market data...

CVE Feed

Latest vulnerabilities from the National Vulnerability Database.

26395
Total
1955
Critical
7973
High
8225
Medium
CVE ID Severity Score Description Published
CVE-2026-9498 MEDIUM 6.3 A vulnerability has been found in Dromara lamp-cloud up to 5.6.2. Impacted is the function GroovyClassLoader.parseClass of the component Message Template Handler. Such manipulation of … May 25, 2026
CVE-2026-9497 MEDIUM 6.3 A flaw has been found in changmingxie tcc-transaction up to 2.1.0. This issue affects the function Fastjson.parseObject of the component Fastjson AutoType REST API. This … May 25, 2026
CVE-2026-9486 MEDIUM 4.3 A security flaw has been discovered in SourceCodester Student Grades Management System 1.0. This affects an unknown part. The manipulation results in cross-site request forgery. … May 25, 2026
CVE-2026-9485 LOW 3.5 A vulnerability was identified in SourceCodester Student Grades Management System 1.0. Affected by this issue is some unknown functionality of the file students.php. The manipulation … May 25, 2026
CVE-2026-9484 MEDIUM 6.3 A vulnerability was determined in SourceCodester Student Grades Management System 1.0. Affected by this vulnerability is the function getClassroomStudents/removeStudentFromClassroom of the file classroom.php. Executing a … May 25, 2026
CVE-2026-48849 MEDIUM 4.4 In Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1, an unsanitized subject field in the draft restored value could lead to stored XSS/HTML/CSS injection … May 25, 2026
CVE-2026-48848 HIGH 7.2 Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7 has insufficient HTML sanitization that could lead to Cascading Style Sheets (CSS) injection via an SVG … May 25, 2026
CVE-2026-48847 LOW 3.7 Roundcube Webmail 1.6.x before 1.6.16, and 1.7.x before 1.7.1 allows pre-authentication arbitrary file deletion via redis/memcache session poisoning bypass. May 25, 2026
CVE-2026-48846 MEDIUM 6.5 In Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1, the remote image blocking feature can be bypassed via a crafted CSS var() value in … May 25, 2026
CVE-2026-48845 MEDIUM 6.5 In Roundcube Webmail 1.6.x between 1.6.14 and 1.6.16 and 1.7.x before 1.7.1, remote image blocking was not honored for URLs pointing to local/private destinations, which … May 25, 2026
CVE-2026-48844 HIGH 7.5 Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has insecure code evaluation logic in LDAP the autovalues option that could lead to code injection. … May 25, 2026
CVE-2026-48843 HIGH 7.2 Roundcube Webmail 1.6.x between 1.6.14 and 1.6.16,and 1.7.x before 1.7.1 has Insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF … May 25, 2026
CVE-2026-48842 HIGH 8.1 Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has Pre-authentication SQL injection in the virtuser_query plugin via a preg_replace() backslash escape bypass. May 25, 2026
CVE-2026-24546 MEDIUM 5.3 Missing Authorization vulnerability in Ruben Garcia GamiPress allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects GamiPress: from n/a through 7.6.3. May 25, 2026
CVE-2026-9483 MEDIUM 6.3 A vulnerability was found in SourceCodester Student Grades Management System 1.0. Affected is an unknown function of the file grades.php. Performing a manipulation of the … May 25, 2026
CVE-2026-9482 HIGH 8.8 A vulnerability has been found in Edimax EW-7438RPn 1.31. This impacts the function formSDHCP of the file /goform/formSDHCP. Such manipulation of the argument submit-url leads … May 25, 2026
CVE-2026-9481 HIGH 8.8 A flaw has been found in Edimax EW-7438RPn 1.31. This affects the function formStats of the file /goform/formStats. This manipulation of the argument submit-url causes … May 25, 2026
CVE-2026-9480 HIGH 8.8 A vulnerability was detected in Edimax EW-7438RPn 1.31. The impacted element is the function formrefresh of the file /goform/formrefresh. The manipulation of the argument submit-url … May 25, 2026
CVE-2026-9479 HIGH 8.8 A security vulnerability has been detected in Edimax EW-7438RPn 1.31. The affected element is the function formLogout of the file /goform/formLogout. The manipulation of the … May 25, 2026
CVE-2026-9478 CRITICAL 9.8 A weakness has been identified in Totolink A8000RU 7.1cu.643_b20200521. Impacted is the function setParentalRules of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Executing … May 25, 2026
CVE-2026-9477 CRITICAL 9.8 A security flaw has been discovered in Totolink A8000RU 7.1cu.643_b20200521. This issue affects the function setAccessDeviceCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management … May 25, 2026
CVE-2026-9476 CRITICAL 9.8 A vulnerability was identified in Totolink A8000RU 7.1cu.643_b20200521. This vulnerability affects the function setPasswordCfg of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. Such … May 25, 2026
CVE-2026-9475 CRITICAL 9.8 A vulnerability was determined in Totolink A8000RU 7.1cu.643_b20200521. This affects the function setIpQosRules of the file /cgi-bin/cstecgi.cgi of the component Web Management Interface. This manipulation … May 25, 2026
CVE-2026-9474 HIGH 7.3 A vulnerability was found in yashpokharna2555 StudentManagementSystem up to cb2f558ddf8d19396de0f92abf2d224d46a0a203. Affected by this issue is the function confirm_logged_in of the file /studentdel.php. The manipulation of … May 25, 2026
CVE-2026-9473 MEDIUM 6.3 A vulnerability has been found in c-rick jimeng-mcp 1.10.0. Affected by this vulnerability is the function getFileContent/uploadCoverFile/generateImage/generateVideo of the file src/api.ts. The manipulation of the … May 25, 2026