CVE Feed

    Dashboard / CVE

    9.8
    Critical

    CVE-2026-11362

    Last Modified: 10 Jun 2026

    DataDog::DogStatsd versions through 0.07 for Perl allow metric injections from event tags. DataDog::DogStatsd does not properly sanitise input, allowing metric injections of data from untrusted sources. The format_event method (used by the event method) does not validate the content of the tags, which may contain commas (allowing tags to be injected) or newlines, pipes and colons that allow metric injections. (There is an ineffective s/|//g to remove pipes, but because the pipe is not escaped, it is interpreted as a regular expression metacharacter and has no effect.)

    Published: 5 Jun 2026
    9.1
    Critical

    CVE-2026-9270

    Last Modified: 10 Jun 2026

    DataDog::DogStatsd versions through 0.07 for Perl allow metric injections. DataDog::DogStatsd does not properly sanitise input, allowing metric injections of data from untrusted sources. The send_stats method does not remove newlines from metric names ($stat variable), allowing attackers to change the metric name prefix. The send_stats method does not validate the content of the value ($delta variable), allowing attackers to inject metrics, especially from methods that do not restrict the data type for the value, such as set, gauge, count and histogram. The send_stats method does not validate the content of the tags, which may contain newlines, pipes and colons that allow metric injections. Note that the SYNOPSIS shows an example of passing a website form "loginName" parameter as a tag, which is unsafe.

    Published: 5 Jun 2026
    9.8
    Critical

    CVE-2026-10879

    Last Modified: 10 Jun 2026

    DBI versions before 1.648 for Perl have a heap overflow when preparsing SQL statements with more than 9 binders. The preparse method expands SQL placeholder characters to numbered binders of the form :pN, but only allocates three characters per binder in the buffer. Placeholders 10-99 require four characters, 100-999 require five characters, et cetera.

    Published: 5 Jun 2026
    2.1
    Low

    CVE-2026-11335

    Last Modified: 5 Jun 2026

    A flaw has been found in tittuvarghese CollegeManagementSystem 3e476335cfbfb9a049e09f474c7ec885f69a9df3/a38852979f7e27ae67b610dce5979500ef8ebe01. This impacts the function session_start of the file /login-form.php. Executing a manipulation of the argument UserAuthData can lead to session fixiation. The attack can be launched remotely. The exploit has been published and may be used. This product does not use versioning. This is why information about affected and unaffected releases are unavailable. The project was informed of the problem early through an issue report but has not responded yet.

    Published: 5 Jun 2026
    Unknown

    CVE-2026-6209

    Last Modified: 7 Jun 2026

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 5 Jun 2026
    Unknown

    CVE-2026-6208

    Last Modified: 7 Jun 2026

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 5 Jun 2026
    5.5
    Medium

    CVE-2026-11334

    Last Modified: 5 Jun 2026

    A vulnerability was detected in tittuvarghese CollegeManagementSystem 3e476335cfbfb9a049e09f474c7ec885f69a9df3/a38852979f7e27ae67b610dce5979500ef8ebe01. This affects an unknown function of the file dashboard_page/forms/fetch.php. Performing a manipulation of the argument department_code results in sql injection. The attack can be initiated remotely. The exploit is now public and may be used. Continious delivery with rolling releases is used by this product. Therefore, no version details of affected nor updated releases are available. The project was informed of the problem early through an issue report but has not responded yet.

    Published: 5 Jun 2026
    8.8
    High

    CVE-2026-48095

    Last Modified: 8 Jun 2026

    7-Zip is a file archiver with a high compression ratio. Versions 26.00 and prior contain a heap buffer overflow vulnerability caused by an under-allocation in the NTFS compressed stream buffer (GetCuSize shift UB), potentially allowing attackers to cause arbitrary code execution or application crashes. CInStream::GetCuSize() in the NTFS handler computes the compression-unit buffer size as (UInt32)1 << (BlockSizeLog + CompressionUnit), and a crafted image with ClusterSizeLog >= 28 and CompressionUnit == 4 drives the exponent to 32, which is undefined behavior and collapses on x86/x64 so _inBuf is allocated as 1 byte. ReadStream_FALSE then writes up to 256 MB of attacker-controlled data into that 1-byte buffer in 64 KB iterations, and because the CInStream object sits only 304 bytes after _inBuf, its vtable pointer is overwritten and the next dispatched call achieves a vtable hijack. On 32-bit builds the overflow is unconditionally reached; on 64-bit it requires the parallel 8 GB _outBuf allocation to succeed, otherwise failing closed to denial of service. The NTFS handler is enabled by default in stock 7z.dll and, via signature-based fallback matching "NTFS " at offset 3, will open a crafted image regardless of file extension during extraction or testing. Version 26.01 fixes the issue.

    Published: 5 Jun 2026
    4.3
    Medium

    CVE-2026-48092

    Last Modified: 8 Jun 2026

    7-Zip is a file archiver with a high compression ratio. Versions 9.34 through 26.00 contain a heap memory disclosure via SquashFS fragment offset integer overflow on 32-bit builds. 32-bit integer overflow in the SquashFS ReadBlock function allows an attacker-controlled node.Offset value to bypass the fragment bounds check, causing memcpy to read heap memory preceding the cache buffer into the extracted file. The vulnerability is exploitable only on 32-bit builds of 7-Zip where size_t is 32 bits, allowing the addition offsetInBlock + blockSize to wrap modulo 2³². On 64-bit builds the addition is promoted to 64 bits and the check correctly rejects the input. Version 26.01 patches the issue.

    Published: 5 Jun 2026
    Unknown

    CVE-2026-6207

    Last Modified: 7 Jun 2026

    This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.

    Published: 5 Jun 2026
    2.1
    Low

    CVE-2026-11333

    Last Modified: 9 Jun 2026

    A security vulnerability has been detected in tittuvarghese CollegeManagementSystem 3e476335cfbfb9a049e09f474c7ec885f69a9df3/a38852979f7e27ae67b610dce5979500ef8ebe01. The impacted element is an unknown function of the file dashboard_page/forms/upload_student_data.php of the component Student Data Upload Endpoint. Such manipulation of the argument Student-Data-CSV leads to unrestricted upload. It is possible to launch the attack remotely. The exploit has been disclosed publicly and may be used. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available. The project was informed of the problem early through an issue report but has not responded yet.

    Published: 5 Jun 2026
    7.1
    High

    CVE-2025-59174

    Last Modified: 8 Jun 2026

    Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain a vulnerability where an attacker sending a large volume of specially crafted messages may cause service degradation.

    Published: 5 Jun 2026
    5.1
    Medium

    CVE-2026-50235

    Last Modified: 7 Jun 2026

    Lyrion Music Server 9.2.0 contains a reflected cross-site scripting vulnerability in advanced search parameters that fail to properly sanitize user input before displaying it in search forms. Attackers can inject malicious scripts through unfiltered search parameters to execute arbitrary JavaScript in users' browsers and steal session information.

    Published: 5 Jun 2026
    8.7
    High

    CVE-2026-50234

    Last Modified: 8 Jun 2026

    Lyrion Music Server 9.2.0 contains a path traversal vulnerability that allows unauthenticated attackers to read arbitrary files by exploiting directory traversal in the web server context. Attackers can manipulate file path parameters to access sensitive files outside the intended directory structure.

    Published: 5 Jun 2026
    6.9
    Medium

    CVE-2026-50233

    Last Modified: 9 Jun 2026

    Lyrion Music Server 9.2.0 contains an arbitrary directory listing vulnerability in its readdirectory query, exposed through both the CLI service (TCP port 9090) and the HTTP JSON-RPC endpoint (/jsonrpc.js). The query accepts a folder parameter and lists its contents with no restriction to the configured media directories and no authentication in the default configuration, allowing a remote, unauthenticated attacker to enumerate arbitrary locations on the host filesystem.

    Published: 5 Jun 2026
    5.1
    Medium

    CVE-2026-50232

    Last Modified: 8 Jun 2026

    Lyrion Music Server 9.2.0 contains a stored cross-site scripting vulnerability that allows attackers to inject malicious scripts through media file metadata tags like GENRE, ARTIST, and ALBUM. Attackers can craft files with XSS payloads in metadata tags that execute in the web interface when users view track information or play files, enabling access to management functions and settings disclosure.

    Published: 5 Jun 2026
    5.1
    Medium

    CVE-2026-50231

    Last Modified: 8 Jun 2026

    Lyrion Music Server 9.2.0 contains an unauthenticated stored cross-site scripting vulnerability in the log viewer that allows attackers to inject malicious scripts by exploiting unescaped template variables. Attackers can inject XSS payloads through search, lines, and path query parameters or by crafting values that get logged such as URLs, User-Agent headers, stream titles, or player names to execute arbitrary scripts in users' browsers.

    Published: 5 Jun 2026
    5.1
    Medium

    CVE-2026-50230

    Last Modified: 7 Jun 2026

    Lyrion Music Server 9.2.0 contains an unauthenticated reflected cross-site scripting vulnerability in the server.log endpoint that allows attackers to inject arbitrary HTML and JavaScript code through the search parameter. Attackers can craft malicious URLs with JavaScript payloads in the search parameter to execute code in users' browsers within the context of the affected application.

    Published: 5 Jun 2026
    2
    Low

    CVE-2026-11330

    Last Modified: 8 Jun 2026

    A weakness has been identified in thedotmack claude-mem up to 11.0.1. The affected element is the function computeObservationContentHash of the file src/services/sqlite/observations/store.ts of the component Observation Content Hash Handler. This manipulation causes use of weak hash. The attack can only be executed locally. The attack's complexity is rated as high. The exploitability is described as difficult. Upgrading to version 12.0.0 is sufficient to fix this issue. Patch name: f32fda8b35e9fe9329f87da65c31149362a03f97. It is suggested to upgrade the affected component.

    Published: 5 Jun 2026
    7.1
    High

    CVE-2026-11369

    Last Modified: 5 Jun 2026

    The Comment API (GET /api/Comment and POST /api/Comment) in the affected application fails to perform authorization checks to verify that the requesting user has access to the object identified by the relatedObjectId. This Insecure Direct Object Reference (IDOR) vulnerability allows any authenticated user to read and write comments on any process across all business units by supplying an arbitrary object GUID.

    Published: 5 Jun 2026
    2
    Low

    CVE-2026-11329

    Last Modified: 8 Jun 2026

    A vulnerability has been found in onnx onnx-mlir up to 0.5.0.0. Affected by this issue is the function generate_hash_key of the file src/Runtime/python/torch_onnxmlir/src/torch_onnxmlir/backend.py of the component Placeholder Node Cache Handler. Such manipulation leads to use of weak hash. An attack has to be approached locally. A high complexity level is associated with this attack. The exploitation is known to be difficult. The name of the patch is 72c5187ff6d13c2c2b3d3789b8f5faf99f08a5b4. Applying a patch is advised to resolve this issue.

    Published: 5 Jun 2026
    5.3
    Medium

    CVE-2026-11346

    Last Modified: 5 Jun 2026

    A Server-Side Request Forgery (SSRF) vulnerability in the custom process creation feature of linqi allows an authenticated attacker to probe internal network components. By crafting a specific process containing an HTTP Request component, an attacker can force the server to send arbitrary HTTP requests. By observing the varying application responses (Success, Failed, or 504 Gateway Time-out), the attacker can determine the status of internal ports, leading to internal network reconnaissance.

    Published: 5 Jun 2026
    6.9
    Medium

    CVE-2026-11345

    Last Modified: 5 Jun 2026

    An Improper Authentication vulnerability in the /api/Cdn/GetFile endpoint of linqi allows unauthenticated, remote attackers to bypass file access controls. The ValidateAnonFileAccess function incorrectly grants access if an 'AnonFile' query parameter containing exactly 256 characters is provided. While this flaw allows bypassing the intended authorization check, the actual security impact is negligible; the exposed resources are strictly limited to minified JavaScript and CSS files that contain no sensitive data and are already publicly accessible via a standard CDN.

    Published: 5 Jun 2026
    7.1
    High

    CVE-2026-25659

    Last Modified: 8 Jun 2026

    Ericsson Packet Core Gateway (PCG) versions prior to 1.30 contain an Improper Handling of Missing Values (CWE-230) vulnerability where an attacker continuously sending a specially crafted message can cause service degradation. The impact continues as long the attack persists but the system recovers from the crashes when the attack stops.

    Published: 5 Jun 2026
    7.1
    High

    CVE-2026-25658

    Last Modified: 8 Jun 2026

    Ericsson Packet Core Gateway (PCG) versions prior to 1.30 contain an Improper Handling of Missing Values (CWE-230) vulnerability where an attacker continuously sending a specially crafted message can cause service degradation. The impact continues as long the attack persists but the system recovers from the crashes when the attack stops.

    Published: 5 Jun 2026
    7.1
    High

    CVE-2026-25657

    Last Modified: 8 Jun 2026

    Ericsson Packet Core Gateway (PCG) versions prior to 1.30 contain an Improper Handling of Syntactically Invalid Structure (CWE-228) vulnerability where an attacker continuously sending a specially crafted message can cause service degradation. The impact continues as long the attack persists but the system recovers from the crashes when the attack stops.

    Published: 5 Jun 2026
    8.5
    High

    CVE-2026-11347

    Last Modified: 5 Jun 2026

    The linqi application contains hardcoded cryptographic keys. Additionally, the application uses a weak algorithm with a limited ASCII charset to dynamically generate Initialization Vectors (IVs) for AES/CBC encryption, making known-plaintext attacks feasible. An attacker with local access can leverage these vulnerabilities to decrypt sensitive obfuscated strings, including ConnectionString values containing database credentials from appsettings.json.

    Published: 5 Jun 2026
    5.9
    Medium

    CVE-2026-21038

    Last Modified: 13 Aug 2026

    Improper input validation in Samsung Android USB Driver for Windows prior to version 1.9.5.0 allows local attacker to access out-of-bounds memory.

    Published: 5 Jun 2026
    6.9
    Medium

    CVE-2026-21037

    Last Modified: 13 Aug 2026

    Improper input validation in Samsung Members prior to version 5.8.01.5 allows local attackers to access arbitrary URL and launch arbitrary activity with Samsung Members privilege.

    Published: 5 Jun 2026
    6.3
    Medium

    CVE-2026-21036

    Last Modified: 7 Jun 2026

    Improper authorization in Samsung Internet prior to version 30.0.0.39 allows local attackers to access sensitive information.

    Published: 5 Jun 2026
    6.5
    Medium

    CVE-2026-21035

    Last Modified: 13 Aug 2026

    Improper input validation in Samsung Plus TV prior to version 1.0.28.6 allows remote attackers to access sensitive information.

    Published: 5 Jun 2026
    4.8
    Medium

    CVE-2026-21034

    Last Modified: 13 Aug 2026

    Improper export of android application components in Samsung Auto prior to version 3.1.2.61 in Android 15 and 3.2.0.38 in Android 16 allows local attacker to change audio configuration.

    Published: 5 Jun 2026
    6.9
    Medium

    CVE-2026-21033

    Last Modified: 12 Jun 2026

    Improper export of android application components in ExpressHomeWidgetReceiver of Samsung Assistant prior to version 9.3.14 allows local attacker to execute arbitrary script.

    Published: 5 Jun 2026
    6.9
    Medium

    CVE-2026-21032

    Last Modified: 12 Jun 2026

    Improper export of android application components in SmartHomeWidgetReceiver of Samsung Assistant prior to version 9.3.14 allows local attacker to execute arbitrary script.

    Published: 5 Jun 2026
    5.2
    Medium

    CVE-2026-21031

    Last Modified: 6 Jun 2026

    Improper authorization in AppBlock prior to SMR Jun-2026 Release 1 allows local attacker to launch arbitrary activity. User interaction is required for triggering this vulnerability.

    Published: 5 Jun 2026
    6.4
    Medium

    CVE-2026-21030

    Last Modified: 6 Jun 2026

    Improper access control in MediaTek Audio HAL prior to SMR Jun-2026 Release 1 allows local attackers to trigger privileged functions.

    Published: 5 Jun 2026
    6.8
    Medium

    CVE-2026-21029

    Last Modified: 6 Jun 2026

    Improper export of android application components in Galaxy Editing Service prior to SMR Jun-2026 Release 1 allows local attacker to execute privileged operations.

    Published: 5 Jun 2026
    5.1
    Medium

    CVE-2026-21028

    Last Modified: 6 Jun 2026

    Improper access control in AuditLogService prior to SMR Jun-2026 Release 1 allows local attackers to access sensitive information.

    Published: 5 Jun 2026
    4.8
    Medium

    CVE-2026-21027

    Last Modified: 6 Jun 2026

    Improper export of android application components in ImsSettings prior to SMR Jun-2026 Release 1 allows local attackers to trigger logging function.

    Published: 5 Jun 2026
    6.4
    Medium

    CVE-2026-21026

    Last Modified: 6 Jun 2026

    Improper export of android application components in SpriteWallpaper prior to SMR Jun-2026 Release 1 allows local attackers to access to sensitive information.

    Published: 5 Jun 2026
    6.9
    Medium

    CVE-2026-21025

    Last Modified: 6 Jun 2026

    Incorrect privilege assignment in Telephony prior to SMR Jun-2026 Release 1 allows local attackers to access sensitive information.

    Published: 5 Jun 2026
    4.6
    Medium

    CVE-2026-21017

    Last Modified: 6 Jun 2026

    Improper handling of insufficient privileges in SecTelephonyProvider prior to SMR Jun-2026 Release 1 allows local attackers to access privileged files.

    Published: 5 Jun 2026
    8.4
    High

    CVE-2026-8914

    Last Modified: 7 Jun 2026

    In Teltonika Networks RUTOS devices, running versions 7.22 through 7.23.2 and TSWOS devices running versions 1.09 through 1.09.1, due to unsafe calls to an eval function in rpc-profile, a vulnerability exists where a lower privileged user could perform command injection as the root user.

    Published: 5 Jun 2026
    9.8
    Critical

    CVE-2026-6274

    Last Modified: 8 Jun 2026

    Improper Authentication, Missing authentication for critical function, Weak Authentication vulnerability in DTS Electronics Industry and Trade Ltd. Co. Redline WR3200 allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Redline WR3200: from 7.1.3 before 7.1.8.

    Published: 5 Jun 2026
    10
    Critical

    CVE-2026-49777

    Last Modified: 8 Jun 2026

    Improper Validation of Specified Quantity in Input vulnerability in ShapedPlugin, LLC Product Slider Pro for WooCommerce allows Malicious Software Implanted. This issue affects Product Slider Pro for WooCommerce: from n/a before 3.5.4.

    Published: 5 Jun 2026
    2.7
    Low

    CVE-2026-9088

    Last Modified: 26 Jun 2026

    A flaw was found in org.keycloak.services. An administrator with delegated access to read group memberships and users can bypass user profile permissions by accessing the group members endpoint. This allows the administrator to view user attributes that are explicitly configured to be denied, leading to information disclosure.

    Published: 5 Jun 2026
    10
    Critical

    CVE-2026-48907

    Last Modified: 16 Jun 2026

    A vulnerability in the JCE editor extension for Joomla allows the creation of new editor profiles for unauthenticated users, ultimately resulting in PHP code upload and execution.

    Published: 5 Jun 2026
    7.8
    High

    CVE-2026-11332

    Last Modified: 9 Sept 2026

    A flaw was found in ansible-core. The ansible-galaxy role install command processes dependency specifications from a role's meta/requirements.yml file. Due to improper neutralization of argument delimiters, a malicious role author can inject arbitrary git configuration flags through the src field. This allows arbitrary code execution on the machine of a user who installs the role via ansible-galaxy role install.

    Published: 5 Jun 2026
    6.1
    Medium

    CVE-2026-21825

    Last Modified: 10 Jun 2026

    HCL Digital Experience Compose is affected by a reflected cross-site scripting (XSS) vulnerability in the search center.  An attacker could execute arbitrary JavaScript in the victim's browser.

    Published: 5 Jun 2026
    6.1
    Medium

    CVE-2026-21826

    Last Modified: 10 Jun 2026

    HCL Digital Experience and HCL Digital Experience Compose could be susceptible to Host header injection.  An attacker can manipulate the Host header and cause the application to behave in unexpected ways.

    Published: 5 Jun 2026