Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-12784 — IM-Magic Partition Resizer Kernel Driver MDA_NTDRV.sys access control

A weakness has been identified in IM-Magic Partition Resizer up to 7.9.0. This affects an unknown function in the library MDA_NTDRV.sys of the component Kernel Driver. This manipulation causes improp…

| Authorization
Jun 21, 2026 Jun 21, 2026
Jun 21, 2026
Jun 21, 2026
0.0 NA
CVE-2026-52911 — ksmbd: scope conn->binding slowpath to bound sessions only

In the Linux kernel, the following vulnerability has been resolved: ksmbd: scope conn->binding slowpath to bound sessions only When the binding SESSION_SETUP sets conn->binding = true, the flag sta…

| Authorization
Jun 21, 2026 Jun 21, 2026
Jun 21, 2026
Jun 21, 2026
0.0 NA
CVE-2026-12782 — EaseUS Partition Master Kernel Driver EUEDKEPM.sys access control

A security flaw has been discovered in EaseUS Partition Master up to 14.5. The impacted element is an unknown function in the library EUEDKEPM.sys of the component Kernel Driver. The manipulation res…

| Authorization
Jun 21, 2026 Jun 21, 2026
Jun 21, 2026
Jun 21, 2026
0.0 NA
CVE-2026-12781 — EaseUS Partition Master Kernel Driver epmntdrv.sys access control

A vulnerability was identified in EaseUS Partition Master up to 14.5. The affected element is an unknown function in the library epmntdrv.sys of the component Kernel Driver. The manipulation leads to…

| Authorization
Jun 21, 2026 Jun 21, 2026
Jun 21, 2026
Jun 21, 2026
0.0 NA
CVE-2026-12780 — AOMEI Backupper Kernel Driver amwrtdrv.sys access control

A vulnerability was determined in AOMEI Backupper up to 8.3.0. Impacted is an unknown function in the library amwrtdrv.sys of the component Kernel Driver. Executing a manipulation can lead to imprope…

| Authorization
Jun 21, 2026 Jun 21, 2026
Jun 21, 2026
Jun 21, 2026
0.0 NA
CVE-2026-12779 — AOMEI Dynamic Disk Manager Kernel Driver ddmdrv.sys access control

A vulnerability was found in AOMEI Dynamic Disk Manager up to 10.10.1. This issue affects some unknown processing in the library ddmdrv.sys of the component Kernel Driver. Performing a manipulation r…

| Authorization
Jun 21, 2026 Jun 21, 2026
Jun 21, 2026
Jun 21, 2026
0.0 NA
CVE-2026-12778 — AOMEI Partition Assistant Kernel Driver ampa10.sys access control

A vulnerability has been found in AOMEI Partition Assistant up to 10.10.1. This vulnerability affects unknown code in the library ampa10.sys of the component Kernel Driver. Such manipulation leads to…

| Authorization
Jun 21, 2026 Jun 21, 2026
Jun 21, 2026
Jun 21, 2026
0.0 NA
CVE-2026-12776 — Montodel House-Rental-Management index.php houses sql injection

A flaw has been found in Montodel House-Rental-Management up to 90010017b81265eb1ef3810268909f7719a33863. This affects an unknown part of the file /index.php?page=houses. This manipulation of the arg…

| Injection
Jun 21, 2026 Jun 21, 2026
Jun 21, 2026
Jun 21, 2026
0.0 NA
CVE-2026-12775 — Montodel House-Rental-Management login.php sql injection

A vulnerability was detected in Montodel House-Rental-Management up to 90010017b81265eb1ef3810268909f7719a33863. Affected by this issue is some unknown functionality of the file /login.php. The manip…

| Injection
Jun 21, 2026 Jun 21, 2026
Jun 21, 2026
Jun 21, 2026
0.0 NA
CVE-2026-12774 — BerriAI litellm MCP Server Connection Testing rest_endpoints.py _execute_with_mcp_client …

A security vulnerability has been detected in BerriAI litellm up to 1.82.2. Affected by this vulnerability is the function _execute_with_mcp_client of the file litellm/proxy/_experimental/mcp_server/…

| Server-Side Request Forgery
Jun 21, 2026 Jun 21, 2026
Jun 21, 2026
Jun 21, 2026
0.0 NA
CVE-2026-12773 — BerriAI litellm MCP Proxy user_api_key_auth_mcp.py UserAPIKeyAuth improper authentication

A weakness has been identified in BerriAI litellm up to 1.59.8. Affected is the function UserAPIKeyAuth of the file litellm/proxy/_experimental/mcp_server/auth/user_api_key_auth_mcp.py of the compone…

| Authentication
Jun 21, 2026 Jun 21, 2026
Jun 21, 2026
Jun 21, 2026
0.0 NA
CVE-2026-12772 — BerriAI litellm PROXY_ADMIN database API Key Generator login_utils.py authenticate_user s…

A security flaw has been discovered in BerriAI litellm up to 1.82.2. This impacts the function authenticate_user of the file litellm/proxy/auth/login_utils.py of the component PROXY_ADMIN database AP…

| Authentication
Jun 21, 2026 Jun 21, 2026
Jun 21, 2026
Jun 21, 2026
0.0 NA
CVE-2026-12771 — BerriAI litellm M2M JWT user_api_key_auth.py improper authorization

A vulnerability was identified in BerriAI litellm up to 1.82.2. This affects an unknown function of the file litellm/proxy/auth/user_api_key_auth.py of the component M2M JWT Handler. Such manipulatio…

| Authorization
Jun 21, 2026 Jun 21, 2026
Jun 21, 2026
Jun 21, 2026
0.0 NA
CVE-2026-12770 — BerriAI litellm Admin Key key_management_endpoints.py improper authorization

A vulnerability was determined in BerriAI litellm up to 1.63.1. The impacted element is an unknown function of the file litellm/proxy/management_endpoints/key_management_endpoints.py of the component…

| Authorization
Jun 21, 2026 Jun 21, 2026
Jun 21, 2026
Jun 21, 2026
3.7 LOW
CVE-2026-56355 — GNU Savannah Savane Authorization Bypass

GNU Savannah Administration Savane through 3.17 uses untrusted data as part of authorization.

savane | Remote | Authorization
Jun 20, 2026 Jun 20, 2026
Jun 20, 2026
Jun 20, 2026
6.1 MEDIUM
CVE-2026-56347 — AVideo TopMenu Plugin - Stored Cross-Site Scripting via Unescaped Menu Item Fields

AVideo TopMenu plugin through version 26.0 contains a stored cross-site scripting vulnerability in menu item rendering due to missing output encoding of icon classes, URLs, and text labels. Attackers…

avideo | Remote | Cross-Site Scripting
Jun 20, 2026 Jun 20, 2026
Jun 20, 2026
Jun 20, 2026
6.9 MEDIUM
CVE-2026-56346 — AVideo - Unauthenticated PGP Message Decryption via decryptMessage.json.php Endpoint

AVideo through version 25.0 contains an authentication bypass vulnerability in the decryptMessage.json.php endpoint that allows unauthenticated users to decrypt PGP messages. Remote attackers can sub…

Remote | Authentication
Jun 20, 2026 Jun 20, 2026
Jun 20, 2026
Jun 20, 2026
9.2 CRITICAL
CVE-2026-56345 — AVideo - Arbitrary User Session Hijacking via Meet Plugin uploadRecordedVideo Endpoint

AVideo through 29.0 contains an authorization bypass vulnerability in the Meet plugin's uploadRecordedVideo.json.php endpoint that derives the target users_id from the uploaded filename without verif…

Remote | Authorization
Jun 20, 2026 Jun 20, 2026
Jun 20, 2026
Jun 20, 2026
6.8 MEDIUM
CVE-2026-56342 — AVideo - Server-Side Request Forgery in Live/test.php via statsURL Parameter

AVideo through version 27.0 contains a server-side request forgery vulnerability in plugin/Live/test.php that allows authenticated administrators to read arbitrary URLs via the statsURL parameter, wh…

Remote | Server-Side Request Forgery
Jun 20, 2026 Jun 20, 2026
Jun 20, 2026
Jun 20, 2026
8.7 HIGH
CVE-2026-56341 — AVideo - Unauthenticated Access to Payment Log DataTables Endpoints via list.json.php

AVideo through version 26.0 contains multiple unauthenticated list.json.php endpoints in payment plugins lacking authorization checks, exposing PayPal tokens, Authorize.Net webhooks, and Bitcoin tran…

Remote | Authorization
Jun 20, 2026 Jun 20, 2026
Jun 20, 2026
Jun 20, 2026
Showing 20 of 7423 Results