Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.5 MEDIUM
CVE-2026-36604 — Mercusys AC12G: Host Header Validation Bypass via DNS Rebinding

Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 does not validate the HTTP Host header, enabling DNS rebinding attacks. An external attacker can rebind a domain to the router's intern…

Remote | Misconfiguration
Jun 03, 2026 Jun 04, 2026
Jun 03, 2026
Jun 04, 2026
0.0 NA
CVE-2026-36603 — Mercusys AC12G Router Unauthenticated UPnP Port Mapping Vulnerability

Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 exposes 15 of 18 UPnP IGD actions without authentication on port 1900, including AddPortMapping and GetExternalIPAddress. UPnP is enabl…

| Authentication
Jun 03, 2026 Jun 04, 2026
Jun 03, 2026
Jun 04, 2026
0.0 NA
CVE-2026-36602 — Mercusys AC12G Kernel Memory Disclosure Vulnerability

Mercusys AC12G (EU) V1 router with firmware AC12G(EU)_V1_200909 discloses kernel memory layout via the UPnP GetStatusInfo action. An unauthenticated attacker on the adjacent network can obtain a raw …

| Information Disclosure
Jun 03, 2026 Jun 04, 2026
Jun 03, 2026
Jun 04, 2026
0.0 NA
CVE-2026-36460 — Dovestones ADPhonebook Cross Site Scripting

Dovestones Softwares ADPhonebook before v4.0.1.1 is vulnerable to a Cross Site Scripting vulnerability. The /Admin/Save API allows an authenticated admin user to store malicious JavaScript payloads i…

| Cross-Site Scripting
Jun 03, 2026 Jun 04, 2026
Jun 03, 2026
Jun 04, 2026
6.1 MEDIUM
CVE-2026-20233 — Cisco Webex Meetings Cross-Site Scripting Vulnerability

A vulnerability in the web-based user interface of Cisco Webex Meetings could have allowed an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack. Cisco has addressed this…

webex_meetings webex | Remote | Cross-Site Scripting
Jun 03, 2026 Jun 04, 2026
Jun 03, 2026
Jun 04, 2026
8.6 HIGH
CVE-2026-20230 — Cisco Unified Communications Manager SSRF Vulnerability

A vulnerability in Cisco Unified Communications Manager (Unified CM) and Cisco Unified Communications Manager Session Management Edition (Unified CM SME) could allow an unauthenticated, remote attack…

unified_communications_manager | Remote | Server-Side Request Forgery
Jun 03, 2026 Jun 04, 2026
Jun 03, 2026
Jun 04, 2026
6.1 MEDIUM
CVE-2026-20175 — Cisco Finesse File Inclusion Vulnerability

A vulnerability in Cisco Finesse could allow an unauthenticated, remote attacker to load arbitrary files from remote locations into an active user session on an affected device, possibly leading to b…

finesse | Remote | Path Traversal
Jun 03, 2026 Jun 04, 2026
Jun 03, 2026
Jun 04, 2026
0.0 NA
CVE-2025-71314 — drm/panthor: Recover from panthor_gpu_flush_caches() failures

In the Linux kernel, the following vulnerability has been resolved: drm/panthor: Recover from panthor_gpu_flush_caches() failures We have seen a few cases where the whole memory subsystem is blocke…

linux_kernel | Denial of Service
Jun 03, 2026 Jun 03, 2026
Jun 03, 2026
Jun 03, 2026
0.0 NA
CVE-2025-71313 — PCI: endpoint: Add missing NULL check for alloc_workqueue()

In the Linux kernel, the following vulnerability has been resolved: PCI: endpoint: Add missing NULL check for alloc_workqueue() alloc_workqueue() can return NULL on memory allocation failure. Witho…

linux_kernel | Memory Corruption
Jun 03, 2026 Jun 03, 2026
Jun 03, 2026
Jun 03, 2026
7.1 HIGH
CVE-2019-25720 — Dräger SC Monitoring Devices DoS via Malformed Network Packet

Dräger SC Monitoring devices (SC 6002XL, SC 6802XL, SC 7000, SC 8000, SC 9000 XL) contain a denial-of-service vulnerability in all software versions that allows unauthenticated attackers to reboot th…

| Denial of Service
Jun 03, 2026 Jun 04, 2026
Jun 03, 2026
Jun 04, 2026
6.1 MEDIUM
CVE-2026-6657 — CORS Origin Validation Bypass in jupyter-server

A vulnerability in jupyter-server versions 1.12.0 through 2.17.0 allows an attacker to bypass CORS origin validation when the `allow_origin_pat` configuration is used. The issue arises from the use o…

jupyter_server | Remote | Misconfiguration
Jun 03, 2026 Jun 04, 2026
Jun 03, 2026
Jun 04, 2026
7.0 HIGH
CVE-2026-44281 — GLPI vulnerable to unauthorized reading of a specific asset object

GLPI is a free asset and IT management software package. Starting in version 0.78 and prior to versions 10.0.25 and 11.0.7, an authenticated user with config READ permission can read a specific asset…

glpi | Remote | Authorization
Jun 03, 2026 Jun 04, 2026
Jun 03, 2026
Jun 04, 2026
8.4 HIGH
CVE-2026-42321 — GLPI has stored XSS in asset locks

GLPI is a free asset and IT management software package. Starting in version 10.0.4 and prior to version 10.0.25, a technician can store an XSS payload in the asset locked tab. Upgrade to 10.0.25 or …

glpi | Remote | Cross-Site Scripting
Jun 03, 2026 Jun 04, 2026
Jun 03, 2026
Jun 04, 2026
5.9 MEDIUM
CVE-2026-42320 — GLPI vulnerable to arbitrary file access

GLPI is a free asset and IT management software package. Starting in version 0.50 and prior to versions 10.0.25 and 11.0.7, a technician can read arbitrary files inside the GLPI_DOC_DIR. Upgrade to 1…

glpi | Remote | Path Traversal
Jun 03, 2026 Jun 04, 2026
Jun 03, 2026
Jun 04, 2026
7.0 HIGH
CVE-2026-42318 — GLPI Vulnerable to Arbitrary Item Deletion via Planning Endpoint

GLPI is a free asset and IT management software package. Starting in version 9.5.0 and prior to versions 10.0.25 and 11.0.7, low privilege users with access to planning can delete any object in GLPI.…

glpi | Remote | Authorization
Jun 03, 2026 Jun 04, 2026
Jun 03, 2026
Jun 04, 2026
7.0 HIGH
CVE-2026-42317 — GLPI vulnerable to arbitrary files deletion by technician

GLPI is a free asset and IT management software package. Starting in version 0.78 and prior to versions 10.0.25 and 11.0.7, a technician can delete arbitrary files from the filesystem as long as the …

glpi | Remote | Path Traversal
Jun 03, 2026 Jun 04, 2026
Jun 03, 2026
Jun 04, 2026
6.3 MEDIUM
CVE-2026-3276 — Potential DoS via quadratic complexity in unicodedata.normalize()

unicodedata.normalize() can take excessive CPU time when processing specially crafted Unicode input containing long runs of combining characters with alternating Canonical Combining Class values. Thi…

python cpython cpython | Remote | Denial of Service
Jun 03, 2026 Jun 04, 2026
Jun 03, 2026
Jun 04, 2026
7.5 HIGH
CVE-2026-37462 — gobgp: BGPUpdate.DecodeFromBytes Integer Underflow Denial of Service

An integer underflow in the BGPUpdate.DecodeFromBytes function (/bgp/bgp.go) of gobgp v4.3.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted BGP UPDATE message.

Remote | Denial of Service
Jun 03, 2026 Jun 04, 2026
Jun 03, 2026
Jun 04, 2026
9.0 CRITICAL
CVE-2026-36748 — RockRMS Cross-Site Scripting

RockRMS v16.13 and before v.17.7.0 is vulnerable to Cross Site Scripting (XSS) via Social Media links in user profile.

Remote | Cross-Site Scripting
Jun 03, 2026 Jun 04, 2026
Jun 03, 2026
Jun 04, 2026
9.8 CRITICAL
CVE-2026-36576 — openlabs docker-wkhtmltopdf-aas OS Command Injection

An OS command injection vulnerability in the app.py component of openlabs docker-wkhtmltopdf-aas up to commit 9f50579 allows attackers to execute arbitrary commands via a crafted POST request.

Remote | Injection
Jun 03, 2026 Jun 04, 2026
Jun 03, 2026
Jun 04, 2026
Showing 20 of 7151 Results