Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
3.1 LOW
CVE-2026-8404 — Potential exposure of private data via case-sensitive Cache-Control directives in UpdateC…

An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6. `django.middleware.cache.UpdateCacheMiddleware` in Django does not match `Cache-Control` response directives case-insensitive…

django | Remote | Misconfiguration
Jun 03, 2026 Jun 03, 2026
Jun 03, 2026
Jun 03, 2026
3.1 LOW
CVE-2026-7666 — Potential unencrypted email transmission via STARTTLS in the SMTP backend

An issue was discovered in Django 6.0 before 6.0.6 and 5.2 before 5.2.15. `django.core.mail.backends.smtp.EmailBackend` in Django fails to prevent reuse of a partially-initialized connection after a …

django | Remote | Cryptography
Jun 03, 2026 Jun 03, 2026
Jun 03, 2026
Jun 03, 2026
3.1 LOW
CVE-2026-6873 — Signed cookie salt namespace collision in django.http.HttpRequest.get_signed_cookie

An issue was discovered in Django 6.0 before 6.0.6 and 5.2 before 5.2.15. `django.http.HttpRequest.get_signed_cookie` in Django uses a non-injective salt derivation (concatenating the cookie name and…

django | Remote | Cryptography
Jun 03, 2026 Jun 03, 2026
Jun 03, 2026
Jun 03, 2026
8.0 HIGH
CVE-2026-5241 — Policy Bypass in LightGlue Nested Config Resolution in huggingface/transformers

A vulnerability in the LightGlue model loading path of huggingface/transformers version 5.2.0 allows an attacker-controlled model repository to execute arbitrary code during model initialization. The…

transformers | Remote | Supply Chain
Jun 03, 2026 Jun 03, 2026
Jun 03, 2026
Jun 03, 2026
3.1 LOW
CVE-2026-48587 — Potential exposure of private data via whitespace padding in Vary header

An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6. `django.utils.cache.has_vary_header()` in Django does not strip leading or trailing whitespace from `Vary` response header va…

django | Remote | Misconfiguration
Jun 03, 2026 Jun 03, 2026
Jun 03, 2026
Jun 03, 2026
6.9 MEDIUM
CVE-2026-47325 — Weak password policy in ProjectsAndPrograms school-management-system

ProjectsAndPrograms school-management-system uses predictable credentials by generating student's and teacher's passwords solely from the user’s date of birth (e.g., 12072000 for 12 July 2000). The a…

Remote | Authentication
Jun 03, 2026 Jun 03, 2026
Jun 03, 2026
Jun 03, 2026
5.1 MEDIUM
CVE-2026-47324 — Stored XSS in Multiple Points in ProjectsAndPrograms school-management-system

ProjectsAndPrograms school-management-system is vulnerable to Stored Cross‑Site Scripting (XSS) in multiple attributes of students and teachers objects. An authorized attacker (e.g., a teacher or adm…

Remote | Cross-Site Scripting
Jun 03, 2026 Jun 03, 2026
Jun 03, 2026
Jun 03, 2026
3.7 LOW
CVE-2026-44546 — Header injection via WebSocket upgrade parser differential allows ASGI scope header spoof…

daphne before 4.2.2 reconstructs a raw HTTP request from Twisted's parsed headers and feeds it to autobahn for WebSocket handshake processing. Twisted does not treat \x0b, \x0c, \x1c, \x1d, \x1e, or …

Remote | Injection
Jun 03, 2026 Jun 03, 2026
Jun 03, 2026
Jun 03, 2026
5.3 MEDIUM
CVE-2026-44545 — Unbounded WebSocket message and frame sizes can cause unauthenticated remote denial of se…

daphne before 4.2.2 did not pass maxFramePayloadSize or maxMessagePayloadSize to Autobahn's WebSocketServerFactory. Because Autobahn defaults both values to 0 (unlimited), an unauthenticated remote a…

Remote | Denial of Service
Jun 03, 2026 Jun 03, 2026
Jun 03, 2026
Jun 03, 2026
0.0 NA
CVE-2026-37460 — FRRouting BGP UPDATE Denial of Service

Missing input validation in the rfapiRibBi2Ri() function (rfapi_rib.c) of FRRouting (FRR) stable/10.0 to stable/10.6 allows attackers to cause a Denial of Service (DoS) via supplying a crafted BGP UP…

| Denial of Service
Jun 03, 2026 Jun 03, 2026
Jun 03, 2026
Jun 03, 2026
3.1 LOW
CVE-2026-35193 — Potential exposure of private data via missing Vary: Authorization in UpdateCacheMiddlewa…

An issue was discovered in Django 5.2 before 5.2.15 and 6.0 before 6.0.6. `django.middleware.cache.UpdateCacheMiddleware` in Django does not add `Authorization` to the `Vary` response header for requ…

django | Remote | Information Disclosure
Jun 03, 2026 Jun 03, 2026
Jun 03, 2026
Jun 03, 2026
1.2 LOW
CVE-2026-10729 — HTML injection in the notification email for "Slow Redirect" and "Cloned Website" Canaryt…

An HTML injection vulnerability in the notification email for "Slow Redirect" and "Cloned Website" Canarytokens exists in Thinkst Applied Research Canarytokens, enabling Interface Manipulation, Cross…

Remote | Cross-Site Scripting
Jun 03, 2026 Jun 03, 2026
Jun 03, 2026
Jun 03, 2026
6.5 MEDIUM
CVE-2025-70101 — lwext4 Out-of-Bounds Read

An out-of-bounds read in the ext4_ext_binsearch_idx function in src/ext4_extent.c of the lwext4 1.0.0 library allows attackers to cause a denial of service by supplying a specially crafted ext4 files…

Remote | Memory Corruption
Jun 03, 2026 Jun 03, 2026
Jun 03, 2026
Jun 03, 2026
5.5 MEDIUM
CVE-2025-70100 — lwext4 Divide By Zero

A divide-by-zero vulnerability in the ext4_block_set_lb_size function in src/ext4_blockdev.c of the lwext4 1.0.0 library allows attackers to cause a denial of service by providing a malformed ext4 fi…

| Denial of Service
Jun 03, 2026 Jun 03, 2026
Jun 03, 2026
Jun 03, 2026
5.0 MEDIUM
CVE-2025-60477 — GPAC MP4Box NULL Pointer Dereference Denial of Service

A NULL pointer dereference in the gf_filter_pid_resolve_file_template_ex function (/filter_core/filter_pid.c) of GPAC Project/MP4Box before 26.02.0 allows attackers to cause a Denial of Service (DoS)…

| Denial of Service
Jun 03, 2026 Jun 03, 2026
Jun 03, 2026
Jun 03, 2026
4.3 MEDIUM
CVE-2024-47273 — Synology Hyper Backup Path Traversal

An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in Backup Task functionality in Synology Hyper Backup before 4.1.2-4036 allows remote authenticated use…

Remote | Path Traversal
Jun 03, 2026 Jun 03, 2026
Jun 03, 2026
Jun 03, 2026
4.1 MEDIUM
CVE-2024-47263 — Synology Hyper Backup Path Traversal

An improper limitation of a pathname to a restricted directory ('Path Traversal') vulnerability in Backup.Repository webapi component in Synology Hyper Backup before 4.1.2-4036 allows remote authenti…

Remote | Path Traversal
Jun 03, 2026 Jun 03, 2026
Jun 03, 2026
Jun 03, 2026
5.9 MEDIUM
CVE-2023-52951 — Synology Note Station Client Cleartext Transmission of Sensitive Information

A cleartext transmission of sensitive information vulnerability in Synology Note Station Client before 2.2.4-703 allows man-in-the-middle attackers to obtain user credential.

Remote | Cryptography
Jun 03, 2026 Jun 03, 2026
Jun 03, 2026
Jun 03, 2026
7.8 HIGH
CVE-2022-49042 — Synology Hyper Backup Explorer: Local Code Execution via Untrusted Control Sphere Inclusi…

An inclusion of functionality from untrusted control sphere vulnerability in MinGW DLL component in Synology Hyper Backup Explorer before 3.0.1-0156 allows local users to execute arbitrary code via u…

| Supply Chain
Jun 03, 2026 Jun 03, 2026
Jun 03, 2026
Jun 03, 2026
7.8 HIGH
CVE-2022-49036 — Synology Active Backup for Business Recovery Media Creator Arbitrary Code Execution

An inclusion of functionality from untrusted control sphere vulnerability in OpenSSL configuration in Synology Active Backup for Business Recovery Media Creator before 2.5.0-2081 allows local users t…

| Misconfiguration
Jun 03, 2026 Jun 03, 2026
Jun 03, 2026
Jun 03, 2026
Showing 20 of 7141 Results