Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.2 MEDIUM
CVE-2026-46557 — ImageMagick: Stack overflow in fx operation

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-23, due to a missing depth check a stack overflow can occur in the fx operation b…

imagemagick | Memory Corruption
Jun 10, 2026 Jun 11, 2026
Jun 10, 2026
Jun 11, 2026
5.5 MEDIUM
CVE-2026-46521 — ImageMagick: Heap Buffer Over-Write in MIFF encoder when using LZMA compression

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-23, when using LZMA compression in the MIFF encoder an out of boun…

imagemagick | Memory Corruption
Jun 10, 2026 Jun 11, 2026
Jun 10, 2026
Jun 11, 2026
8.8 HIGH
CVE-2026-44693 — Pi-hole FTL: Unauthenticated Session Hijacking via Race Condition on Global Session Buffer

Pi-hole FTL is the core engine of the Pi-hole network-level advertisement and tracker blocker. Prior to version 6.6.1, Pi-hole FTL contains a race condition vulnerability in the HTTP session manageme…

ftldns | Remote | Race Condition
Jun 10, 2026 Jun 11, 2026
Jun 10, 2026
Jun 11, 2026
4.3 MEDIUM
CVE-2026-42568 — Yamcs Vulnerable to LDAP Injection in LdapAuthModule

Yamcs is a mission control framework. Prior to versions 5.13.0 and 5.12.7, an LDAP injection vulnerability exists in `org.yamcs.security.LdapAuthModule` when constructing search filters. The username…

Remote | Injection
Jun 10, 2026 Jun 11, 2026
Jun 10, 2026
Jun 11, 2026
7.7 HIGH
CVE-2026-42563 — Dulwich Vulnerable to Command Injection via Merge Driver Path

Dulwich is a pure-Python implementation of the Git file formats and protocols. Starting in version 0.24.0 and prior to version 1.2.5, Dulwich's `ProcessMergeDriver` substitutes the file path (from th…

dulwich | Remote | Injection
Jun 10, 2026 Jun 11, 2026
Jun 10, 2026
Jun 11, 2026
7.6 HIGH
CVE-2026-42558 — Xibo Vulnerable to Stored XSS and Iframe Sandbox Escape via Data Connector Script in Data…

Xibo is an open source digital signage platform with a web content management system and Windows display player software. Prior to 4.4.2, a vulnerability chain consisting of Stored XSS and Iframe San…

xibo | Remote | Cross-Site Scripting
Jun 10, 2026 Jun 11, 2026
Jun 10, 2026
Jun 11, 2026
8.8 HIGH
CVE-2026-42305 — Dulwich has an arbitrary file write via NTFS-hostile tree entries on Windows

Dulwich is a pure-Python implementation of the Git file formats and protocols. Versions starting with 0.10.0 and prior to 1.2.5 have an arbitrary file write leading to remote code execution when clon…

dulwich | Remote | Path Traversal
Jun 10, 2026 Jun 11, 2026
Jun 10, 2026
Jun 11, 2026
5.3 MEDIUM
CVE-2024-21944 — Intel Virtualization Technology DIMM SPD Information Disclosure and Memory Corruption

Improper input validation for DIMM serial presence detect (SPD) metadata could allow an attacker with physical access, ring0 access on a system with a non-compliant DIMM, or control over the Root of …

| Memory Corruption
Jun 10, 2026 Jun 11, 2026
Jun 10, 2026
Jun 11, 2026
5.4 MEDIUM
CVE-2026-53742 — Simple Link Directory through 9.0.4 Stored XSS via Embed Shortcode Attributes

Simple Link Directory through 9.0.4 echoes embed shortcode attributes into HTML data attributes without escaping in the embedder template. Attackers with contributor access can craft a shortcode attr…

simple_link_directory | Remote | Cross-Site Scripting
Jun 10, 2026 Jun 11, 2026
Jun 10, 2026
Jun 11, 2026
5.4 MEDIUM
CVE-2026-53741 — Simple Link Directory through 9.0.4 Stored XSS via sld_no_results_found Option

Simple Link Directory through 9.0.4 interpolates the sld_no_results_found option into a JavaScript string literal without encoding. Because sanitize_text_field leaves quotes intact, a stored payload …

simple_link_directory | Remote | Cross-Site Scripting
Jun 10, 2026 Jun 11, 2026
Jun 10, 2026
Jun 11, 2026
5.4 MEDIUM
CVE-2026-53740 — Yoast Duplicate Post through 4.6 Stored Cross-Site Scripting via Scheduled Republish Noti…

Yoast Duplicate Post through 4.6 inserts an unescaped post title and permalink into the Classic Editor scheduled republish notice. Attackers can schedule a republish copy with a crafted title to exec…

duplicate_post | Remote | Cross-Site Scripting
Jun 10, 2026 Jun 11, 2026
Jun 10, 2026
Jun 11, 2026
5.1 MEDIUM
CVE-2026-53739 — Yoast Duplicate Post through 4.6 Cross-Site Request Forgery via duplicate_post_dismiss_no…

Yoast Duplicate Post through 4.6 contains a cross-site request forgery vulnerability in the duplicate_post_dismiss_notice handler, which verifies no nonce or capability. Attackers can trick any authe…

duplicate_post | Remote | Cross-Site Request Forgery
Jun 10, 2026 Jun 11, 2026
Jun 10, 2026
Jun 11, 2026
8.1 HIGH
CVE-2026-53738 — Copy & Delete Posts through 1.5.4 Privilege Escalation via cdp_action_handling Handler

Copy & Delete Posts through 1.5.4 lets any plugin-enabled non-admin role invoke every operation in the cdp_action_handling AJAX handler. Attackers with an enabled role can delete posts or overwrite p…

duplicate_post | Remote | Authorization
Jun 10, 2026 Jun 11, 2026
Jun 10, 2026
Jun 11, 2026
6.1 MEDIUM
CVE-2026-53737 — Juicer through 1.12.18 Stored Cross-Site Scripting via Unescaped API Response

Juicer through 1.12.18 fails to escape remote feed API response fields before rendering them on the admin settings page. Attackers controlling the connected feed data can inject script that executes …

juicer | Remote | Cross-Site Scripting
Jun 10, 2026 Jun 11, 2026
Jun 10, 2026
Jun 11, 2026
5.1 MEDIUM
CVE-2026-53736 — Easy Twitter Feeds before 1.2.13 Cross-Site Request Forgery via duplicate_post Action

Easy Twitter Feeds before 1.2.13 contains a cross-site request forgery vulnerability in the duplicate_post action handler that lacks nonce verification. Attackers can trick an authenticated user into…

easy_twitter_feed | Remote | Cross-Site Request Forgery
Jun 10, 2026 Jun 11, 2026
Jun 10, 2026
Jun 11, 2026
4.3 MEDIUM
CVE-2026-53634 — Sharp: Missing Authorization Check in Quick Creation Command Endpoints

Sharp is a content management framework built for Laravel as a package. From version 9.0.0 to before version 9.22.3, the create and store endpoints of the Quick Creation Command feature did not enfor…

sharp | Remote | Authorization
Jun 10, 2026 Jun 11, 2026
Jun 10, 2026
Jun 11, 2026
8.6 HIGH
CVE-2026-50131 — Fedify has an incomplete SSRF mitigation after GHSA-p9cg-vqcc-grcx: validatePublicUrl all…

Fedify is a TypeScript library for building federated server apps powered by ActivityPub. Fedify previously addressed SSRF/internal network access in GHSA-p9cg-vqcc-grcx by adding public URL validati…

Remote | Server-Side Request Forgery
Jun 10, 2026 Jun 11, 2026
Jun 10, 2026
Jun 11, 2026
7.5 HIGH
CVE-2026-48110 — Russh: SSH message fields were decoded through allocation-first parsers before field-spec…

Russh is a Rust SSH client & server library. From version 0.34.0 to before version 0.61.0, several russh client and server message handlers decoded attacker-controlled SSH strings, name-lists, and by…

russh | Remote | Information Disclosure
Jun 10, 2026 Jun 11, 2026
Jun 10, 2026
Jun 11, 2026
5.3 MEDIUM
CVE-2026-48108 — Russh: SSH identification parsing accepted non-canonical client banners and did not bound…

Russh is a Rust SSH client & server library. From version 0.34.0-beta.1 to before version 0.61.0, russh did not enforce the SSH identification-string rules as deliberately as OpenSSH. In particular, …

russh | Remote | Misconfiguration
Jun 10, 2026 Jun 11, 2026
Jun 10, 2026
Jun 11, 2026
6.5 MEDIUM
CVE-2026-48107 — Russh: Unchecked keyboard-interactive prompt count in client auth path

Russh is a Rust SSH client & server library. From version 0.37.0 to before version 0.61.0, in the russh client keyboard-interactive authentication path, a malicious SSH server could send a USERAUTH_I…

russh | Remote | Authentication
Jun 10, 2026 Jun 11, 2026
Jun 10, 2026
Jun 11, 2026
Showing 20 of 7142 Results