Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.9 MEDIUM
CVE-2026-35058 — OpenVPN Denial of Service via TLS-Crypt-v2 Assertion Failure

Improper validation of packet length during tls-crypt-v2 key extraction in OpenVPN 2.6.0 through 2.6.19 and 2.7_alpha1 through 2.7.1 allows authenticated attackers to trigger a fatal assertion and ca…

openvpn | Remote | Denial of Service
Jun 08, 2026 Jun 09, 2026
Jun 08, 2026
Jun 09, 2026
6.5 MEDIUM
CVE-2026-11584 — CodeAstro Student Attendance Management System createClass.php edit sql injection

A vulnerability was found in CodeAstro Student Attendance Management System 1.0. This impacts an unknown function of the file /attendance-php/Admin/createClass.php?action=edit. The manipulation of th…

Remote | Injection
Jun 08, 2026 Jun 09, 2026
Jun 08, 2026
Jun 09, 2026
6.5 MEDIUM
CVE-2026-11583 — CodeAstro Student Attendance Management System createClass.php sql injection

A vulnerability has been found in CodeAstro Student Attendance Management System 1.0. This affects an unknown function of the file /attendance-php/Admin/createClass.php. The manipulation of the argum…

Remote | Injection
Jun 08, 2026 Jun 09, 2026
Jun 08, 2026
Jun 09, 2026
7.5 HIGH
CVE-2026-11582 — CodeAstro Student Attendance Management System index.php sql injection

A flaw has been found in CodeAstro Student Attendance Management System 1.0. The impacted element is an unknown function of the file /attendance-php/index.php. Executing a manipulation of the argumen…

Remote | Injection
Jun 08, 2026 Jun 09, 2026
Jun 08, 2026
Jun 09, 2026
9.8 CRITICAL
CVE-2026-52778 — YesWiki has Unsafe eval() in Formula Calculator - Remote Code Execution (RCE) & Denial of…

YesWiki is a wiki system written in PHP. Prior to version 4.6.6, an unsafe execution vulnerability exists in the Bazar form field calculator (CalcField.php) of YesWiki. The application attempts to sa…

yeswiki | Remote | Injection
Jun 08, 2026 Jun 09, 2026
Jun 08, 2026
Jun 09, 2026
8.8 HIGH
CVE-2026-46490 — samlify: XML Injection in AttributeValue Allows Privilege Escalation in Signed SAML Asser…

samlify is a Node.js library for SAML single sign-on. Prior to version 2.13.0, samlify’s template substitution only escapes attribute contexts. Values inserted into element text (e.g., <saml:Attribut…

samlify | Remote | Injection
Jun 08, 2026 Jun 09, 2026
Jun 08, 2026
Jun 09, 2026
5.3 MEDIUM
CVE-2026-46486 — Mobile Verification Toolkit (MVT): Path Traversal via unsanitized File identifiers in iOS…

MVT (Mobile Verification Toolkit) helps with conducting forensics of mobile devices in order to find signs of a potential compromise. Prior to version 2026.5.12, there is a path traversal vulnerabili…

Remote | Path Traversal
Jun 08, 2026 Jun 09, 2026
Jun 08, 2026
Jun 09, 2026
6.5 MEDIUM
CVE-2026-11559 — CodeAstro Payroll System view_account.php sql injection

A vulnerability was detected in CodeAstro Payroll System 1.0. This affects an unknown function of the file /view_account.php. The manipulation of the argument ID results in sql injection. The attack …

payroll_system | Remote | Injection
Jun 08, 2026 Jun 09, 2026
Jun 08, 2026
Jun 09, 2026
6.5 MEDIUM
CVE-2026-11558 — CodeAstro Payroll System home_salary.php sql injection

A security vulnerability has been detected in CodeAstro Payroll System 1.0. The impacted element is an unknown function of the file /home_salary.php. The manipulation of the argument rate/salary_rate…

payroll_system | Remote | Injection
Jun 08, 2026 Jun 09, 2026
Jun 08, 2026
Jun 09, 2026
9.0 HIGH
CVE-2026-11557 — Tenda F451 Web Management Natlimit fromNatlimit stack-based overflow

A weakness has been identified in Tenda F451 1.0.0.7/1.0.0.9. The affected element is the function fromNatlimit of the file /goform/Natlimit of the component Web Management Interface. Executing a man…

f451_firmware f451 | Remote | Memory Corruption
Jun 08, 2026 Jun 09, 2026
Jun 08, 2026
Jun 09, 2026
9.0 CRITICAL
CVE-2026-11393 — Code injection via improper triple-quote escaping in AgentCore CLI Bedrock Agent import

Improper neutralization of triple-quote characters during Python code generation in AgentCore CLI before v0.14.2 might allow an authenticated remote threat actor to execute arbitrary code on AWS Agen…

agentcore_cli | Remote | Injection
Jun 08, 2026 Jun 09, 2026
Jun 08, 2026
Jun 09, 2026
4.3 MEDIUM
CVE-2026-10787 — Devolutions Server: Missing Authorization in Deleted User Groups API

Missing authorization in the deleted user groups API in Devolutions Server allows an authenticated low-privileged user to enumerate metadata of deleted user groups via a crafted API request. This is…

devolutions_server | Remote | Authorization
Jun 08, 2026 Jun 09, 2026
Jun 08, 2026
Jun 09, 2026
6.5 MEDIUM
CVE-2026-10786 — Devolutions Server Improper Access Control Information Disclosure

Improper access control in the ticketing integration settings in Devolutions Server allows an authenticated low-privileged user to obtain cleartext credentials for configured ticketing integrations v…

devolutions_server | Remote | Authorization
Jun 08, 2026 Jun 09, 2026
Jun 08, 2026
Jun 09, 2026
6.5 MEDIUM
CVE-2026-10544 — Devolutions Server PAM Provider Command Injection

Improper neutralization of special elements in the built-in PAM provider password rotation templates in Devolutions Server allows an authenticated user with write access to a vault to execute arbitra…

devolutions_server | Remote | Injection
Jun 08, 2026 Jun 09, 2026
Jun 08, 2026
Jun 09, 2026
8.5 HIGH
CVE-2026-8913 — Command Injection in TP-Link's Archer MR600 WireGuard Client Configuration

A command Injection vulnerability exists in the WireGuard client configuration of Archer MR600 v5 due to improper neutralization of user-controlled input within the web management interface. An authe…

archer_mr600 | Injection
Jun 08, 2026 Jun 09, 2026
Jun 08, 2026
Jun 09, 2026
9.0 HIGH
CVE-2026-11556 — Tenda F451 Web Management WriteFacMac formWriteFacMac os command injection

A security flaw has been discovered in Tenda F451 1.0.0.7/1.0.0.9. Impacted is the function formWriteFacMac of the file /goform/WriteFacMac of the component Web Management Interface. Performing a man…

f451_firmware f451 | Remote | Injection
Jun 08, 2026 Jun 09, 2026
Jun 08, 2026
Jun 09, 2026
7.5 HIGH
CVE-2026-11555 — D-Link DGS-1100-08PD Web boa.conf least privilege violation

A vulnerability was identified in D-Link DGS-1100-08PD 1.00.006. This issue affects some unknown processing of the file /etc/boa.conf of the component Web Interface. Such manipulation leads to least …

dgs-1100-08pd_firmware dgs-1100-08pd | Remote | Path Traversal
Jun 08, 2026 Jun 09, 2026
Jun 08, 2026
Jun 09, 2026
4.3 MEDIUM
CVE-2026-11554 — TOTOLINK CP450 vsftpd vsftpd.conf least privilege violation

A vulnerability was determined in TOTOLINK CP450 4.1.0cu.747. This vulnerability affects unknown code of the file /etc/vsftpd.conf of the component vsftpd. This manipulation causes least privilege vi…

cp450_firmware cp450 | Remote | Misconfiguration
Jun 08, 2026 Jun 09, 2026
Jun 08, 2026
Jun 09, 2026
9.0 HIGH
CVE-2026-11553 — Tenda HG7HG9/HG10 formPPPEdit stack-based overflow

A vulnerability was found in Tenda HG7HG9 and HG10 300001138_en_xpon. This affects the function formPPPEdit of the file /boaform/formPPPEdit. The manipulation of the argument encodename results in st…

hg10_firmware hg10 | Remote | Memory Corruption
Jun 08, 2026 Jun 09, 2026
Jun 08, 2026
Jun 09, 2026
5.5 MEDIUM
CVE-2026-11552 — SourceCodester Onlne Examination & Learning Management System import_users.php hard-coded…

A vulnerability has been found in SourceCodester Onlne Examination & Learning Management System and Syllabus-aligned Learning Management and Examination System 1.0. Affected by this issue is some unk…

Jun 08, 2026 Jun 09, 2026
Jun 08, 2026
Jun 09, 2026
Showing 20 of 7312 Results