Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-12189 — Moovit Bus & Public Transit App com.tranzmate improper authorization in handler for custo…

A flaw has been found in Moovit Bus & Public Transit App 1.18 on Android. This affects an unknown part of the component com.tranzmate. Executing a manipulation can lead to improper authorization in h…

| Authorization
Jun 14, 2026 Jun 14, 2026
Jun 14, 2026
Jun 14, 2026
0.0 NA
CVE-2026-12188 — Grit42 Grit GritEntityController grit_entity_controller.rb sql injection

A vulnerability was detected in Grit42 Grit up to 0.11.0. Affected by this issue is some unknown functionality of the file modules/core/backend/app/controllers/concerns/grit/core/grit_entity_controll…

| Injection
Jun 14, 2026 Jun 14, 2026
Jun 14, 2026
Jun 14, 2026
0.0 NA
CVE-2026-12187 — GL.iNet GL-MT3000 Online Firmware Upgrade one_click_upgrade command injection

A security vulnerability has been detected in GL.iNet GL-MT3000 up to 4.4.5. Affected by this vulnerability is an unknown functionality of the file /usr/bin/one_click_upgrade of the component Online …

| Injection
Jun 14, 2026 Jun 14, 2026
Jun 14, 2026
Jun 14, 2026
9.0 HIGH
CVE-2026-12186 — GL.iNet GL-MT3000 Tor Proxy Service Configuration tor replace_country command injection

A weakness has been identified in GL.iNet GL-MT3000 up to 4.4.5. Affected is the function replace_country in the library /usr/lib/oui-httpd/rpc/tor of the component Tor Proxy Service Configuration Ha…

Remote | Injection
Jun 14, 2026 Jun 14, 2026
Jun 14, 2026
Jun 14, 2026
8.2 HIGH
CVE-2026-54413 — DriftRegion UDS Integer Underflow Out-of-Bounds Read

driftregion iso14229 through 0.9.0 contains an integer underflow and downstream out-of-bounds read in the Handle_0x27_SecurityAccess() function in iso14229.c that allows a remote unauthenticated atta…

Remote | Memory Corruption
Jun 14, 2026 Jun 14, 2026
Jun 14, 2026
Jun 14, 2026
8.2 HIGH
CVE-2026-54412 — MQTT-C Heap Out-of-Bounds Read and Integer Underflow

LiamBindle MQTT-C through version 1.1.6 contains a heap-based out-of-bounds read and integer underflow in the mqtt_unpack_publish_response() function in src/mqtt.c that allows a remote unauthenticate…

Remote | Memory Corruption
Jun 14, 2026 Jun 14, 2026
Jun 14, 2026
Jun 14, 2026
5.9 MEDIUM
CVE-2026-54411 — Linux-PAM pam_userdb Plaintext Password Recovery Timing Vulnerability

Linux-PAM through 1.7.2 contains an observable timing discrepancy (CWE-208) in the pam_userdb module's plaintext-password comparison path in modules/pam_userdb/pam_userdb.c that allows a local or net…

Remote | Information Disclosure
Jun 14, 2026 Jun 14, 2026
Jun 14, 2026
Jun 14, 2026
8.6 HIGH
CVE-2026-54410 — nanoMODBUS TCP Server Off-by-One Buffer Overflow

nanoMODBUS through v1.23.0 contains an off-by-one buffer overflow in the recv_msg_header() function of the Modbus/TCP server that allows remote unauthenticated attackers to write one attacker-control…

Remote | Memory Corruption
Jun 14, 2026 Jun 14, 2026
Jun 14, 2026
Jun 14, 2026
0.0 NA
CVE-2026-11527 — Config::IniFiles versions before 3.001000 for Perl allow OS command injection and file ov…

Config::IniFiles versions before 3.001000 for Perl allow OS command injection and file overwrite via a 2-arg open() of the -file argument in _make_filehandle. Config::IniFiles::_make_filehandle open…

| Injection
Jun 14, 2026 Jun 14, 2026
Jun 14, 2026
Jun 14, 2026
0.0 NA
CVE-2026-11526 — GD versions before 2.86 for Perl allow OS command injection and file overwrite via a 2-ar…

GD versions before 2.86 for Perl allow OS command injection and file overwrite via a 2-arg open() of filename arguments in _make_filehandle. GD::Image::_make_filehandle opens a filename argument wit…

| Injection
Jun 14, 2026 Jun 14, 2026
Jun 14, 2026
Jun 14, 2026
0.0 NA
CVE-2025-15546 — Iptanus File Upload < 5.1.7 - File Overwrite via Race Condition

The Iptanus File Upload WordPress plugin before 5.1.7 does not implement proper file handling when the duplicatepolicy setting is configured to "maintain both." Due to a Time-of-Check to Time-of-Use …

| Race Condition
Jun 14, 2026 Jun 14, 2026
Jun 14, 2026
Jun 14, 2026
6.8 MEDIUM
CVE-2026-54421 — OpenStack Ironic Information Disclosure

In OpenStack Ironic through 35.0.1, when applying a PATCH to update fields in volume properties the user is authorized for, Ironic can return unredacted sensitive information (such as iSCSI credentia…

ironic | Remote | Information Disclosure
Jun 14, 2026 Jun 14, 2026
Jun 14, 2026
Jun 14, 2026
8.5 HIGH
CVE-2026-54420 — LiteSpeed cPanel Plugin Symlink Privilege Escalation

LiteSpeed cPanel plugin before 2.4.8 (as distributed in LiteSpeed WHM PlugIn before 5.3.2.0) mishandles symlinks provided by a user with FTP or web shell access on a shared hosting server running Clo…

Remote | Path Traversal
Jun 14, 2026 Jun 14, 2026
Jun 14, 2026
Jun 14, 2026
5.0 MEDIUM
CVE-2026-12176 — SourceCodester CET Automated Grading System with AI Predictive Analytics index.php cross …

A vulnerability has been found in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. The impacted element is an unknown function of the file /index.php. The manipulation of…

Jun 14, 2026 Jun 14, 2026
Jun 14, 2026
Jun 14, 2026
5.8 MEDIUM
CVE-2026-12175 — CodeAstro Student Attendance Management System createStudents.php sql injection

A vulnerability was detected in CodeAstro Student Attendance Management System 1.0. Impacted is an unknown function of the file /attendance-php/Admin/createStudents.php. Performing a manipulation of …

Remote | Injection
Jun 13, 2026 Jun 13, 2026
Jun 13, 2026
Jun 13, 2026
9.0 HIGH
CVE-2026-12174 — D-Link DCS-935L HTTP rhea snprintf format string

A security vulnerability has been detected in D-Link DCS-935L 1.10.01. This issue affects the function snprintf of the file /web/cgi-bin/greece/rhea of the component HTTP Handler. Such manipulation o…

dcs-935l_firmware | Remote | Injection
Jun 13, 2026 Jun 13, 2026
Jun 13, 2026
Jun 13, 2026
9.8 CRITICAL
CVE-2026-12183 — Nefteprodukttekhnika BUK TS-G Improper Authentication

Nefteprodukttekhnika BUK TS-G Gas Station Automation System 2.9.1 through 2.10.2 on Linux contains an Improper Authentication vulnerability (CWE-287) in the system configuration module. The /php/ajax…

Remote | Authentication
Jun 13, 2026 Jun 13, 2026
Jun 13, 2026
Jun 13, 2026
7.6 HIGH
CVE-2026-6428 — Koha SQL Injection

SQL Injection in reports/catalogue_out.pl in Koha Community Koha through 22.11.37, 23.x, 24.x before 24.11.16, 25.05.x before 25.05.11, 25.11.x before 25.11.05, 26.05.x before 26.05.01, and 26.11.x b…

Remote | Injection
Jun 13, 2026 Jun 13, 2026
Jun 13, 2026
Jun 13, 2026
7.2 HIGH
CVE-2026-5513 — Online Scheduling and Appointment Booking System – Bookly <= 27.2 - Unauthenticated Store…

The Online Scheduling and Appointment Booking System – Bookly plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'bookly-customer-full-name' cookie in versions up to, and inclu…

Remote | Cross-Site Scripting
Jun 13, 2026 Jun 13, 2026
Jun 13, 2026
Jun 13, 2026
4.3 MEDIUM
CVE-2026-1291 — Meow Gallery <= 5.4.4 - Missing Authorization to Authenticated (Author+) Shortcode creati…

The Meow Gallery plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the REST API endpoint /wp-json/meow-gallery/v1/save_shortcode in all vers…

Remote | Authorization
Jun 13, 2026 Jun 13, 2026
Jun 13, 2026
Jun 13, 2026
Showing 20 of 6516 Results