Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.8 CRITICAL
CVE-2026-47065 — Apache MINA: Critical Deserialization Allow-list Bypass via resolveProxyClass - ZDRES-232

ZDRES-232: resolveProxyClass Not Overridden - acceptMatchers Filter Bypass via java.lang.reflect.Proxy Assessment: Fully addressed. When the serialised stream contains a TC_PROXYCLASSDESC (the ma…

mina | Remote | Authentication
Jun 03, 2026 Jun 04, 2026
Jun 03, 2026
Jun 04, 2026
7.5 HIGH
CVE-2026-41032 — Phoenix Contact: Unauthenticated log download vulnerability in the firmware of CHARX SEC-…

It is possible for an unauthenticated adjacent attacker to download log files of the controller, which may disclose some restricted information.

Jun 03, 2026 Jun 04, 2026
Jun 03, 2026
Jun 04, 2026
8.8 HIGH
CVE-2025-15656 — WordPress School Management plugin <= 93.2.0 - Privilege Escalation vulnerability

Incorrect Privilege Assignment vulnerability in Mojoomla School Management allows Privilege Escalation. This issue affects School Management: from n/a through 93.2.0.

Remote | Authorization
Jun 03, 2026 Jun 04, 2026
Jun 03, 2026
Jun 04, 2026
7.6 HIGH
CVE-2025-15655 — WordPress School Management plugin <= 93.2.0 - SQL Injection vulnerability

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mojoomla School Management allows SQL Injection. This issue affects School Management: from n/a …

Remote | Injection
Jun 03, 2026 Jun 04, 2026
Jun 03, 2026
Jun 04, 2026
7.4 HIGH
CVE-2025-14774 — Communication analysis between the Card Reader and TP2CardReaderService daemon

Incorrect Authorization vulnerability in ABB T-MAC Plus. This issue affects T-MAC Plus: 4.0-24.

| Authorization
Jun 03, 2026 Jun 04, 2026
Jun 03, 2026
Jun 04, 2026
8.0 HIGH
CVE-2025-14773 — Stored Cross-Site Scripting in ABB T-MAC Plus web application

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in ABB T-MAC Plus. This issue affects T-MAC Plus: 4.0-24.

Remote | Cross-Site Scripting
Jun 03, 2026 Jun 04, 2026
Jun 03, 2026
Jun 04, 2026
8.8 HIGH
CVE-2025-14772 — Broken Access Control in ABB T-MAC Plus web application

Authorization bypass through User-Controlled key vulnerability in ABB T-MAC Plus. This issue affects T-MAC Plus: 4.0-24.

Remote | Authorization
Jun 03, 2026 Jun 04, 2026
Jun 03, 2026
Jun 04, 2026
9.9 CRITICAL
CVE-2025-14771 — File Disclosure in ABB T-MAC Plus web application and in ABB T-MAC plus Server - Default…

Files or directories accessible to external parties vulnerability in ABB T-MAC Plus. This issue affects T-MAC Plus: 4.0-24.

Remote | Path Traversal
Jun 03, 2026 Jun 04, 2026
Jun 03, 2026
Jun 04, 2026
9.1 CRITICAL
CVE-2026-4035 — Environment Variable Resolution Vulnerability in mlflow/mlflow

A vulnerability in mlflow/mlflow versions prior to 3.11.0 allows for the resolution of environment variables in AI Gateway secrets, which can be exploited to exfiltrate sensitive server-side environm…

mlflow | Remote | Server-Side Request Forgery
Jun 03, 2026 Jun 04, 2026
Jun 03, 2026
Jun 04, 2026
7.1 HIGH
CVE-2025-15654 — WordPress Prague plugin <= 2.2.8 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Fox-themes Prague allows Reflected XSS. This issue affects Prague: from n/a through 2.2.8.

Remote | Cross-Site Scripting
Jun 03, 2026 Jun 04, 2026
Jun 03, 2026
Jun 04, 2026
5.3 MEDIUM
CVE-2026-5078 — morgan vulnerable to Log Forging via unneutralized control characters in :remote-user

Impact: The morgan logging middleware's :remote-user token extracts the Basic auth username from the Authorization request header and writes it to the log stream without neutralizing control characte…

morgan | Remote | Information Disclosure
Jun 03, 2026 Jun 04, 2026
Jun 03, 2026
Jun 04, 2026
2.3 LOW
CVE-2026-50052 — Varnish Cache HTTP/2 Request Smuggling

In Vinyl Cache before 9.0.1 and Varnish Cache before 9.0.3, a deficiency in HTTP/2 request parsing can be exploited to launch a backend request desync attack (request smuggling), which in turn can be…

Remote | Injection
Jun 03, 2026 Jun 04, 2026
Jun 03, 2026
Jun 04, 2026
7.5 HIGH
CVE-2026-50031 — FreeIPMI ipmi-oem Buffer Overflow

ipmi-oem in FreeIPMI before 1.6.18 has exploitable buffer overflows on response messages. The Intelligent Platform Management Interface (IPMI) specification defines a set of interfaces for platform m…

Remote | Memory Corruption
Jun 03, 2026 Jun 04, 2026
Jun 03, 2026
Jun 04, 2026
3.1 LOW
CVE-2026-10705 — dask HLL hyperloglog.py nunique_approx resource consumption

A flaw has been found in dask up to 3.0. Affected by this issue is the function nunique_approx of the file dask/dataframe/hyperloglog.py of the component HLL Handler. This manipulation causes resourc…

dask | Remote | Denial of Service
Jun 03, 2026 Jun 04, 2026
Jun 03, 2026
Jun 04, 2026
7.5 HIGH
CVE-2026-10704 — SourceCodester Pizzafy E-Commerce System Administrative Control Panel admin_class_novo.ph…

A vulnerability was detected in SourceCodester Pizzafy E-Commerce System 1.0. Affected by this vulnerability is the function Login of the file /admin/admin_class_novo.php of the component Administrat…

pizzafy_e-commerce_system | Remote | Injection
Jun 03, 2026 Jun 04, 2026
Jun 03, 2026
Jun 04, 2026
6.5 MEDIUM
CVE-2026-10703 — EIPStackGroup OpENer SendRRData cipmessagerouter.c CreateMessageRouterRequestStructure us…

A security vulnerability has been detected in EIPStackGroup OpENer up to 2.3.0. Affected is the function CreateMessageRouterRequestStructure of the file cipmessagerouter.c of the component SendRRData…

opener | Remote | Memory Corruption
Jun 03, 2026 Jun 04, 2026
Jun 03, 2026
Jun 04, 2026
7.5 HIGH
CVE-2026-9516 — Cpanel::JSON::XS versions before 4.41 for Perl allow denial of service via UTF-8 BOM pref…

Cpanel::JSON::XS versions before 4.41 for Perl allow denial of service via UTF-8 BOM prefixed input when a decode filter callback throws. To skip a leading 3-byte UTF-8 BOM, decode_json() advances t…

Remote | Denial of Service
Jun 03, 2026 Jun 04, 2026
Jun 03, 2026
Jun 04, 2026
7.3 HIGH
CVE-2026-9334 — Cpanel::JSON::XS versions before 4.41 for Perl allow type confusion via duplicate object …

Cpanel::JSON::XS versions before 4.41 for Perl allow type confusion via duplicate object keys when dupkeys_as_arrayref is enabled. decode_hv() collapses duplicate object keys into an array reference…

Remote | Memory Corruption
Jun 03, 2026 Jun 04, 2026
Jun 03, 2026
Jun 04, 2026
7.5 HIGH
CVE-2026-10694 — SourceCodester Online Food Ordering System index.php include file inclusion

A vulnerability was detected in SourceCodester Online Food Ordering System 2.0. Affected by this issue is the function include of the file /index.php. The manipulation of the argument page results in…

online_food_ordering_system | Remote | Path Traversal
Jun 03, 2026 Jun 04, 2026
Jun 03, 2026
Jun 04, 2026
6.5 MEDIUM
CVE-2026-10693 — SourceCodester Online Boat Reservation System Administrative Endpoint improper authorizat…

A security vulnerability has been detected in SourceCodester Online Boat Reservation System 1.0. Affected by this vulnerability is an unknown functionality of the component Administrative Endpoint. T…

online_boat_reservation_system | Remote | Authorization
Jun 03, 2026 Jun 04, 2026
Jun 03, 2026
Jun 04, 2026
Showing 20 of 7127 Results