CVE Feed

    Dashboard / CVE

    6.5
    Medium

    CVE-2026-44740

    Last Modified: 1 Jun 2026

    Billy is an interface filesystem abstraction for Go. Prior to versions 5.9.0 and 6.0.0-alpha.1, multiple components may improperly handle crafted or malformed input, resulting in panics, infinite loops, uncontrolled recursion, or excessive resource consumption. These issues arise from insufficient validation and missing safety mechanisms such as cycle detection, recursion limits, or defensive handling of unexpected states when processing untrusted repository data and filesystem structures. This issue has been patched in versions 5.9.0 and 6.0.0-alpha.1.

    Published: 1 Jun 2026
    9.6
    Critical

    CVE-2026-44211

    Last Modified: 3 Jun 2026

    Cline is an autonomous coding agent as an SDK, IDE extension, or CLI assistant. In versions 2.13.0 and prior, there is a cross-origin WebSocket hijack vulnerability in Cline Kanban servers. At time of publication, there are no publicly available patches.

    Published: 1 Jun 2026
    5.5
    Medium

    CVE-2026-10272

    Last Modified: 1 Jun 2026

    A vulnerability has been found in a4m4 Student-Management-System up to f0c5f6842c5e8c431ff02b5260a565ca844df3a0. The impacted element is an unknown function of the file admin/deleteform.php. Such manipulation of the argument sid leads to improper authorization. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used. This product takes the approach of rolling releases to provide continious delivery. Therefore, version details for affected and updated releases are not available. The project was informed of the problem early through an issue report but has not responded yet.

    Published: 1 Jun 2026
    7.4
    High

    CVE-2022-4991

    Last Modified: 2 Jun 2026

    Tychon includes an OpenSSL component that specifies an OPENSSLDIR variable as a subdirectory that may be controllable by an unprivileged user on Windows. Tychon contains a privileged service that uses this OpenSSL component. A user who can place a specially-crafted openssl.cnf file at an appropriate path may be able to achieve arbitrary code execution with SYSTEM privileges.

    Published: 1 Jun 2026
    2.1
    Low

    CVE-2026-10271

    Last Modified: 1 Jun 2026

    A flaw has been found in a4m4 Student-Management-System up to f0c5f6842c5e8c431ff02b5260a565ca844df3a0. The affected element is an unknown function of the file admin/ of the component Admin Endpoint. This manipulation of the argument uid causes execution after redirect. It is possible to initiate the attack remotely. The exploit has been published and may be used. This product is using a rolling release to provide continious delivery. Therefore, no version details for affected nor updated releases are available. Multiple endpoints are affected. The project was informed of the problem early through an issue report but has not responded yet.

    Published: 1 Jun 2026
    7.4
    High

    CVE-2026-10270

    Last Modified: 3 Jun 2026

    A vulnerability was detected in D-Link DI-7001 MINI up to 19.09.19A1. Impacted is the function sprintf of the file /httpd_debug.asp of the component API. The manipulation of the argument Time results in stack-based buffer overflow. The attack may be performed from remote. The exploit is now public and may be used.

    Published: 1 Jun 2026
    6.5
    Medium

    CVE-2026-42671

    Last Modified: 1 Jun 2026

    Missing Authorization vulnerability in Paolo GeoDirectory allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects GeoDirectory: from n/a through 2.8.157.

    Published: 1 Jun 2026
    9.3
    Critical

    CVE-2026-42672

    Last Modified: 2 Jun 2026

    Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Wp Directory Kit WP Directory Kit allows Blind SQL Injection. This issue affects WP Directory Kit: from n/a through 1.5.1.

    Published: 1 Jun 2026
    7.8
    High

    CVE-2026-10118

    Last Modified: 27 Jun 2026

    A flaw was found in Poppler's Splash backend. A remote attacker could exploit this vulnerability by crafting a malicious PDF file that, when rendered, triggers an integer overflow in the `tilingPatternFill` function. This overflow leads to an undersized heap memory allocation, allowing a subsequent out-of-bounds write. Successful exploitation could result in arbitrary code execution, information disclosure, or denial of service within the context of the application processing the PDF.

    Published: 1 Jun 2026
    7.5
    High

    CVE-2026-42673

    Last Modified: 2 Jun 2026

    Insertion of Sensitive Information Into Sent Data vulnerability in Logtivity Activity Logs Activity Logs, User Activity Tracking, Multisite Activity Log from Logtivity allows Retrieve Embedded Sensitive Data. This issue affects Activity Logs, User Activity Tracking, Multisite Activity Log from Logtivity: from n/a through 3.3.6.

    Published: 1 Jun 2026
    7.5
    High

    CVE-2026-42674

    Last Modified: 2 Jun 2026

    Authentication Bypass by Spoofing vulnerability in AAM Plugin Advanced Access Manager allows URL Encoding. This issue affects Advanced Access Manager: from n/a through 7.1.0.

    Published: 1 Jun 2026
    7.3
    High

    CVE-2026-42675

    Last Modified: 1 Jun 2026

    Missing Authorization vulnerability in Themefic Hydra Booking allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Hydra Booking: from n/a through 1.1.41.

    Published: 1 Jun 2026
    6.5
    Medium

    CVE-2026-42676

    Last Modified: 1 Jun 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in myCred allows Stored XSS. This issue affects myCred: from n/a through 3.0.4.

    Published: 1 Jun 2026
    7.5
    High

    CVE-2026-42677

    Last Modified: 2 Jun 2026

    Missing Authorization vulnerability in Ben Balter WP Document Revisions allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects WP Document Revisions: from n/a before 4.0.0.

    Published: 1 Jun 2026
    5.3
    Medium

    CVE-2026-10269

    Last Modified: 1 Jun 2026

    A security vulnerability has been detected in decolua 9router up to 0.4.0. This issue affects the function isAuthenticated of the file src/dashboardGuard.js of the component HTTP Header Handler. The manipulation of the argument Host leads to improper authorization. The attack is possible to be carried out remotely. Upgrading to version 0.4.1 is capable of addressing this issue. The identifier of the patch is 428e2c045cb9c0eb8080e8b580471a9c2eaa95ca. Upgrading the affected component is recommended.

    Published: 1 Jun 2026
    7.1
    High

    CVE-2026-42678

    Last Modified: 2 Jun 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Liquid Web / StellarWP GiveWP allows DOM-Based XSS. This issue affects GiveWP: from n/a through 4.14.5.

    Published: 1 Jun 2026
    6.5
    Medium

    CVE-2026-42679

    Last Modified: 2 Jun 2026

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Mamunur Rashid Classified Listing allows Path Traversal. This issue affects Classified Listing: from n/a through 5.3.8.

    Published: 1 Jun 2026
    1.9
    Low

    CVE-2026-10268

    Last Modified: 1 Jun 2026

    A weakness has been identified in janet-lang janet up to 1.41.0. This vulnerability affects the function unmarshal_one_fiber of the file src/core/marsh.c. Executing a manipulation can lead to integer overflow. It is possible to launch the attack on the local host. The exploit has been made available to the public and could be used for attacks. This patch is called d9b1d711ea1fde52ac73a82088b512a3e17bad0d. A patch should be applied to remediate this issue.

    Published: 1 Jun 2026
    9.2
    Critical

    CVE-2026-0826

    Last Modified: 31 Aug 2026

    In certain scenarios when the admin has enabled Interactive Connectivity Establishment (ICE), a buffer overflow could enable remote code execution on Poly Voice products on the Linux platform.

    Published: 1 Jun 2026
    9.8
    Critical

    CVE-2026-42680

    Last Modified: 2 Jun 2026

    Incorrect Privilege Assignment vulnerability in Wasiliy Strecker / ContestGallery developer Contest Gallery Pro allows Privilege Escalation. This issue affects Contest Gallery Pro: from n/a through 29.0.1.

    Published: 1 Jun 2026
    7.1
    High

    CVE-2026-42681

    Last Modified: 2 Jun 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in E2Pdf.Com e2pdf allows Reflected XSS. This issue affects e2pdf: from n/a through 1.32.14.

    Published: 1 Jun 2026
    9.1
    Critical

    CVE-2026-42682

    Last Modified: 1 Jun 2026

    Missing Authorization vulnerability in Tomdever wpForo Forum allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects wpForo Forum: from n/a through 3.0.6.

    Published: 1 Jun 2026
    1.9
    Low

    CVE-2026-10267

    Last Modified: 1 Jun 2026

    A security flaw has been discovered in janet-lang janet up to 1.41.0. This affects the function doframe of the file src/core/debug.c. Performing a manipulation results in out-of-bounds read. Attacking locally is a requirement. The exploit has been released to the public and may be used for attacks. The patch is named ed17dd2c5913a23fb1107251e44a9410a3c30cf5.

    Published: 1 Jun 2026
    7.1
    High

    CVE-2026-42683

    Last Modified: 2 Jun 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in e4jvikwp VikBooking Hotel Booking Engine & PMS allows DOM-Based XSS. This issue affects VikBooking Hotel Booking Engine & PMS: from n/a through 1.8.8.

    Published: 1 Jun 2026
    7.1
    High

    CVE-2026-48839

    Last Modified: 1 Jun 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in VeronaLabs WP Statistics allows DOM-Based XSS. This issue affects WP Statistics: from n/a through 14.16.6.

    Published: 1 Jun 2026
    7.1
    High

    CVE-2026-48865

    Last Modified: 1 Jun 2026

    Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ThimPress LearnPress allows Reflected XSS. This issue affects LearnPress: from n/a through 4.3.6.

    Published: 1 Jun 2026
    9.6
    Critical

    CVE-2026-48866

    Last Modified: 1 Jun 2026

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Rocketgenius Inc. Gravity Forms allows Path Traversal. This issue affects Gravity Forms: from n/a through 2.10.0.1.

    Published: 1 Jun 2026
    9.8
    Critical

    CVE-2026-48879

    Last Modified: 2 Jun 2026

    Incorrect Privilege Assignment vulnerability in Sergey AIWU allows Privilege Escalation. This issue affects AIWU: from n/a through 1.4.17.

    Published: 1 Jun 2026
    9.4
    Critical

    CVE-2026-8931

    Last Modified: 2 Jun 2026

    A critical Remote Code Execution (RCE) vulnerability exists in Disig Web Signer versions 2.0.3 through 2.5.3.

    Published: 1 Jun 2026
    2.1
    Low

    CVE-2026-10265

    Last Modified: 1 Jun 2026

    A vulnerability was identified in itsourcecode Content Management System 1.0. Affected by this issue is some unknown functionality of the file /admin/edit_topic.php. Such manipulation of the argument topic_id leads to sql injection. The attack may be launched remotely. The exploit is publicly available and might be used.

    Published: 1 Jun 2026
    2
    Low

    CVE-2026-10264

    Last Modified: 3 Jun 2026

    A vulnerability was determined in lharries whatsapp-mcp 0.0.1. Affected by this vulnerability is the function SendMessageRequest of the file whatsapp-bridge/main.go of the component Send API Endpoint. This manipulation of the argument mediaPath causes path traversal. The exploit has been publicly disclosed and may be utilized. Patch name: 6657cdceadd361e8fbe824afe9d00b4504009a5d. It is recommended to apply a patch to fix this issue.

    Published: 1 Jun 2026
    5.5
    Medium

    CVE-2026-10263

    Last Modified: 2 Jun 2026

    A vulnerability was found in SourceCodester Computer Repair Shop Management System up to 1.0. Affected is an unknown function of the file /admin/products/manage_product.php. The manipulation of the argument ID results in sql injection. The attack can be launched remotely. The exploit has been made public and could be used.

    Published: 1 Jun 2026
    5.5
    Medium

    CVE-2026-10262

    Last Modified: 1 Jun 2026

    A vulnerability has been found in code-projects Real State Services 1.0. This impacts an unknown function of the file /loginuser.php of the component Login. The manipulation of the argument Username leads to sql injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used.

    Published: 1 Jun 2026
    5.5
    Medium

    CVE-2026-10261

    Last Modified: 1 Jun 2026

    A flaw has been found in CodeAstro Online Job Portal 1.0. This affects an unknown function of the file /users/application_status.php. Executing a manipulation of the argument ID can lead to sql injection. It is possible to launch the attack remotely. The exploit has been published and may be used.

    Published: 1 Jun 2026
    8.7
    High

    CVE-2026-42251

    Last Modified: 2 Jun 2026

    Use of hard-coded credentials in KS-SOMED allowed an unauthorized attacker access to FTP server that hosted the application's update packages. The attacker with these credentials could upload a malicious update file, which then may have been distributed and installed on client machines as a legitimate update. This issue affects KS-SOMED with modules: KSPLUPDFTP.exe up to 30.00.00.056 and ANEKSKLIENT.EXE up to 29.00.02.026 Beside removing the hard-coded credentials from the code and changing the update process, access granted by previously exposed credentials was limited to read-only.

    Published: 1 Jun 2026
    5
    Medium

    CVE-2026-10533

    Last Modified: 8 Jun 2026

    A flaw was found in OpenShift Container Platform. Completed pods with restartPolicy: Never do not count toward ResourceQuota pod limits, and Kubernetes events are not quota-scoped. A non-privileged user who can create pods in a namespace can exploit this to generate a large volume of events that accumulate in etcd, causing API server performance degradation across the cluster.

    Published: 1 Jun 2026
    8.6
    High

    CVE-2024-40646

    Last Modified: 8 Jun 2026

    Vertex is a management tool for PT (Private Tracker) users to manage streaming and watching videos. Versions prior to commit fbde301b97986d5913fc4bc95f5445750d282e11 are vulnerable to path traversal. Users should upgrade to a version containing commit fbde301b97986d5913fc4bc95f5445750d282e11 to receive a patch.

    Published: 1 Jun 2026
    5.1
    Medium

    CVE-2026-48559

    Last Modified: 28 Jul 2026

    Lightweight Music Server (LMS) though 3.76.0 contains a stored cross-site scripting vulnerability that allows attackers to execute arbitrary JavaScript by embedding malicious HTML in media file metadata tags such as GENRE, ARTIST, or ALBUM. Attackers can introduce a crafted media file into the victim's library, causing the payload to be saved during library scanning and executed automatically in the web interface due to tag content being rendered using Wt::TextFormat::UnsafeXHTML without sanitization in src/lms/ui/Utils.cpp.

    Published: 1 Jun 2026
    5.5
    Medium

    CVE-2026-10260

    Last Modified: 1 Jun 2026

    A vulnerability was detected in CodeAstro Online Job Portal 1.0. The impacted element is an unknown function of the file /admin/jobs-admins/delete-jobs.php. Performing a manipulation of the argument ID results in sql injection. It is possible to initiate the attack remotely. The exploit is now public and may be used.

    Published: 1 Jun 2026
    7.4
    High

    CVE-2026-10259

    Last Modified: 1 Jun 2026

    A security vulnerability has been detected in H3C Magic B0 up to 100R002. The affected element is the function SetMobileAPInfoById of the file /goform/aspForm. Such manipulation of the argument param leads to stack-based buffer overflow. The attack may be performed from remote. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

    Published: 1 Jun 2026
    2.1
    Low

    CVE-2026-10258

    Last Modified: 3 Jun 2026

    A weakness has been identified in itsourcecode Content Management System 1.0. Impacted is an unknown function of the file /admin/add_sub_topic.php. This manipulation of the argument topic_id causes sql injection. The attack is possible to be carried out remotely. The exploit has been made available to the public and could be used for attacks.

    Published: 1 Jun 2026
    2.1
    Low

    CVE-2026-10257

    Last Modified: 2 Jun 2026

    A security flaw has been discovered in itsourcecode Content Management System 1.0. This issue affects some unknown processing of the file /admin/update_ss_img.php. The manipulation of the argument topic_id results in sql injection. The attack can be executed remotely. The exploit has been released to the public and may be used for attacks.

    Published: 1 Jun 2026
    2.1
    Low

    CVE-2026-10256

    Last Modified: 1 Jun 2026

    A vulnerability was identified in itsourcecode Content Management System 1.0. This vulnerability affects unknown code of the file /save_comment.php. The manipulation of the argument Name leads to sql injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.

    Published: 1 Jun 2026
    5.5
    Medium

    CVE-2026-10255

    Last Modified: 1 Jun 2026

    A vulnerability has been found in SourceCodester Pharmacy Sales and Inventory System 1.0. Affected by this vulnerability is the function sell_statement of the file application/controllers/ShowForm.php. Such manipulation leads to improper access controls. The attack can be launched remotely. The exploit has been disclosed to the public and may be used.

    Published: 1 Jun 2026
    5.5
    Medium

    CVE-2026-10254

    Last Modified: 1 Jun 2026

    A flaw has been found in SourceCodester Pet Grooming Management Software 1.0. Affected is an unknown function of the file /admin/. This manipulation causes file and directory information exposure. The attack can be initiated remotely. The exploit has been published and may be used.

    Published: 1 Jun 2026
    2.9
    Low

    CVE-2026-10532

    Last Modified: 2 Jun 2026

    Deserialization of untrusted data vulnerability in QOS.CH Sarl logback logback-core (HardenedObjectInputStream (logback-core) modules) allows Object Injection, albeit heavily restricted. More precisely, an attacker able to influence serialized data sent to SimpleSocketServer or SimpleSSLSocketServer can instantiate Proxy objects. Although deserialization is heavily restricted by HardenedObjectInputStream and no practical way to achieve remote code execution or significant privilege escalation has been identified, this issue constitutes a bypass of the intended security restrictions. This issue affects logback: through 1.5.33 inclusive.

    Published: 1 Jun 2026
    5.5
    Medium

    CVE-2026-10253

    Last Modified: 1 Jun 2026

    A vulnerability was detected in itsourcecode Online House Rental System 1.0. This impacts an unknown function of the file /manage_payment.php. The manipulation of the argument ID results in sql injection. It is possible to launch the attack remotely. The exploit is now public and may be used.

    Published: 1 Jun 2026
    5.4
    Medium

    CVE-2026-9309

    Last Modified: 3 Jun 2026

    Firefox for iOS Reader View did not properly escape HTML tags in JSON-LD metadata. A malicious page could inject markup that changed Reader View behavior and leaked sensitive URL parameters. These parameters could then be used to access internal pages, potentially resulting in arbitrary JavaScript execution in an internal origin. This vulnerability was fixed in Firefox for iOS 151.2.

    Published: 1 Jun 2026
    5.4
    Medium

    CVE-2026-9308

    Last Modified: 3 Jun 2026

    Firefox for iOS Reader View replaced page content in its HTML template before replacing other internal placeholders. A malicious page could include a placeholder string that was later substituted with JSON-LD data, potentially resulting in arbitrary JavaScript execution. This vulnerability was fixed in Firefox for iOS 151.2.

    Published: 1 Jun 2026
    5.5
    Medium

    CVE-2026-10252

    Last Modified: 3 Jun 2026

    A security vulnerability has been detected in itsourcecode Online House Rental System 1.0. This affects an unknown function of the file /manage_tenant.php. The manipulation of the argument ID leads to sql injection. It is possible to initiate the attack remotely. The exploit has been disclosed publicly and may be used.

    Published: 1 Jun 2026