Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-39197 — Datadog Vector HTTP Prelude Denial of Service

An issue in the /util/http/prelude.rs endpoint of Datadog, Inc Vector v0.54.0 allows attackers to cause a Denial of Service (DoS) via a crafted request or payload.

| Denial of Service
Jun 15, 2026 Jun 15, 2026
Jun 15, 2026
Jun 15, 2026
0.0 NA
CVE-2026-39196 — Datadog Vector SQL Injection

Datadog, Inc Vector v0.54.0 was discovered to contain a SQL injection vulnerability in the set_uri_query parameter in the KeyPartitioner::partition function. This vulnerability allows attackers to ac…

| Injection
Jun 15, 2026 Jun 15, 2026
Jun 15, 2026
Jun 15, 2026
0.0 NA
CVE-2026-39118 — Kandji Agent Privilege Escalation

An issue in Iru, Inc Kandji Agent before v.4.7.5(5374) allows a local attacker to escalate privileges via a client validation gap to invoke restricted agent functionality.

| Authorization
Jun 15, 2026 Jun 15, 2026
Jun 15, 2026
Jun 15, 2026
0.0 NA
CVE-2026-39007 — Observeinc Observe CSV Log Export Information Disclosure

An issue in Observeinc's Observe v.2026-01-28 and before allows a remote attacker to obtain sensitive information via the CSV Log export component.

| Information Disclosure
Jun 15, 2026 Jun 15, 2026
Jun 15, 2026
Jun 15, 2026
0.0 NA
CVE-2026-39006 — SNMP4J-Agent Arbitrary Code Execution

An issue in SNMP4J-Agent 3.8.3 allows a remote attacker to execute arbitrary code via the snmp4jCfgStoragePath component.

| Information Disclosure
Jun 15, 2026 Jun 15, 2026
Jun 15, 2026
Jun 15, 2026
0.0 NA
CVE-2026-38812 — RuoYi SQL Injection

RuoYi v4.8.2 is vulnerable to SQL Injection via the /tool/gen/createTable endpoint. The issue affects the code generation module and may allow an authenticated attacker with administrative privileges…

| Injection
Jun 15, 2026 Jun 15, 2026
Jun 15, 2026
Jun 15, 2026
0.0 NA
CVE-2026-38329 — Bludit CMS API Plugin Remote Code Execution

Bludit CMS before version 3.18.4 allows Remote Code Execution (RCE) via the API Plugin. The POST /api/files/{key} endpoint in bl-plugins/api/plugin.php fails to perform authorization checks and lacks…

| Authorization
Jun 15, 2026 Jun 15, 2026
Jun 15, 2026
Jun 15, 2026
0.0 NA
CVE-2026-38065 — Tenda Command Injection

Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_ims_on_with_apn via the ims_apn parameter.

| Injection
Jun 15, 2026 Jun 15, 2026
Jun 15, 2026
Jun 15, 2026
0.0 NA
CVE-2026-38064 — Tenda Command Injection

Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_dial_call via the dialNumber parameter.

| Injection
Jun 15, 2026 Jun 15, 2026
Jun 15, 2026
Jun 15, 2026
0.0 NA
CVE-2026-38063 — Tenda Command Injection

Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_radio_on_with_ia_apn via the ia parameter.

| Injection
Jun 15, 2026 Jun 15, 2026
Jun 15, 2026
Jun 15, 2026
0.0 NA
CVE-2026-38062 — Tenda Command Injection

Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_set_rat_mode via the ratMode parameter.

| Injection
Jun 15, 2026 Jun 15, 2026
Jun 15, 2026
Jun 15, 2026
0.0 NA
CVE-2026-38061 — Tenda Command Injection

Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_set_volume via the volume parameter.

| Injection
Jun 15, 2026 Jun 15, 2026
Jun 15, 2026
Jun 15, 2026
0.0 NA
CVE-2026-38060 — Tenda Command Injection

Tenda 5G03 V05.03.02.04 (Version 1.0) is vulnerable to Command injection in the function action_unlock_sim via the pin parameter.

| Injection
Jun 15, 2026 Jun 15, 2026
Jun 15, 2026
Jun 15, 2026
0.0 NA
CVE-2026-37216 — Ruoyi Cross-Site Scripting

Ruoyi 4.8.2 is vulnerable to Cross Site Scripting (XSS) at the interface /system/notice/add.

| Cross-Site Scripting
Jun 15, 2026 Jun 15, 2026
Jun 15, 2026
Jun 15, 2026
0.0 NA
CVE-2026-36933 — Boyleep K11 Factory Test Command Injection

An issue in Boyleep K11, y108 firmware v.2.3.0.11291 allows a physically proximate attacker to execute arbitrary code via the factory test feature.

| Authentication
Jun 15, 2026 Jun 15, 2026
Jun 15, 2026
Jun 15, 2026
0.0 NA
CVE-2026-36670 — OpenSIPS Control Panel Time-Based Blind SQL Injection

A Time-Based Blind SQL Injection vulnerability in the alias_management module of OpenSIPS Control Panel (opensips-cp) prior to version 9.3.3 allows authenticated attackers to execute arbitrary SQL co…

| Injection
Jun 15, 2026 Jun 15, 2026
Jun 15, 2026
Jun 15, 2026
0.0 NA
CVE-2026-36537 — ThingsBoard Authentication Bypass via OAuth Code Exchange

ThingsBoard v4.3.0.1 is vulnerable to an authentication bypass during the OAuth authorization code exchange. The application improperly trusts user-supplied identity data within the user parameter of…

| Authentication
Jun 15, 2026 Jun 15, 2026
Jun 15, 2026
Jun 15, 2026
0.0 NA
CVE-2026-36521 — PublicCMS Cross-Site Scripting

PublicCMS V5.202506.d has a Cross Site Scripting (XSS) vulnerability in the site configuration management module.

| Cross-Site Scripting
Jun 15, 2026 Jun 15, 2026
Jun 15, 2026
Jun 15, 2026
0.0 NA
CVE-2026-36213 — Microvirt MEmu Privilege Escalation

An issue in Microvirt MEmu Android Emulator 9.2.7.0 allows a local attacker to escalate privileges via the MemuService.exe component.

| Authorization
Jun 15, 2026 Jun 15, 2026
Jun 15, 2026
Jun 15, 2026
0.0 NA
CVE-2026-30121 — remotion-dev Arbitrary File Write

remotion-dev remotion v4.0.409 was discovered to contain an arbitrary file write vulnerability.

| Path Traversal
Jun 15, 2026 Jun 15, 2026
Jun 15, 2026
Jun 15, 2026
Showing 20 of 6862 Results