Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-50883 — matze wastebin HTML Injection

An HTML injection vulnerability in the /src/highlight.rs component of matze wastebin v3.4.1 allows attackers to execute arbitrary scripts via a crafted payload.

| Cross-Site Scripting
Jun 15, 2026 Jun 15, 2026
Jun 15, 2026
Jun 15, 2026
0.0 NA
CVE-2026-50880 — YouTransfer Arbitrary Code Execution

An issue in the sendmail transport integration component of YouTransfer v1.0.6 allows attackers to execute arbitrary code via supplying a crafted request.

| Injection
Jun 15, 2026 Jun 15, 2026
Jun 15, 2026
Jun 15, 2026
0.0 NA
CVE-2026-50878 — Feuerhamster MailForm Denial of Service

An issue in the attachment handling component of Feuerhamster MailForm v1.1.0 allows attackers to cause a Denial of Service (DoS) via a crafted request.

| Denial of Service
Jun 15, 2026 Jun 15, 2026
Jun 15, 2026
Jun 15, 2026
0.0 NA
CVE-2026-50879 — Andrei Marcu linx-server DoS

An issue in the uploadPostHandler component of Andrei Marcu linx-server v2.3.8 allows attackers to cause a Denial of Service (DoS) via a crafted POST request.

| Denial of Service
Jun 15, 2026 Jun 15, 2026
Jun 15, 2026
Jun 15, 2026
0.0 NA
CVE-2026-50877 — Zhoros SuperBin Directory Traversal

An issue in Zhoros SuperBin v1.0.0 allows attackers to execute a directory traversal via supplying files with names containing traversal characters.

| Path Traversal
Jun 15, 2026 Jun 15, 2026
Jun 15, 2026
Jun 15, 2026
0.0 NA
CVE-2026-50876 — Deck9 Input Cross-Site Scripting

A cross-site scripting (XSS) vulnerability in Deck9 Input v2.0.1 allows attackers to execute arbitrary web scripts or HTML via a crafted payload.

| Cross-Site Scripting
Jun 15, 2026 Jun 15, 2026
Jun 15, 2026
Jun 15, 2026
0.0 NA
CVE-2026-50875 — Deck9 Input Webhook Access Control Bypass

Incorrect access control in the /{form}/webhooks/{webhook} endpoint of Deck9 Input v2.0.1 allows authenticated attackers to arbitrarily modify or delete another tenant's webhook via a crafted request.

| Authorization
Jun 15, 2026 Jun 15, 2026
Jun 15, 2026
Jun 15, 2026
0.0 NA
CVE-2026-50873 — Flatnotes Arbitrary Code Execution via File Upload

An arbitrary file upload vulnerability in the attachment handling component of flatnotes v5.5.4 allows attackers to execute arbitrary code via uploading a crafted HTML or SVG file.

| Misconfiguration
Jun 15, 2026 Jun 15, 2026
Jun 15, 2026
Jun 15, 2026
0.0 NA
CVE-2026-50874 — kannishka-linux Reminiscence OS Command Injection

An OS command injection vulnerability in the /manage/features/media component of kanishka-linux Reminiscence v0.3.0 allows attackers to execute arbitrary commands via supplying a crafted input.

| Injection
Jun 15, 2026 Jun 15, 2026
Jun 15, 2026
Jun 15, 2026
0.0 NA
CVE-2026-50872 — fossar selfoss Command Injection

An issue in the loopback request handling component of fossar selfoss v2.20-SNAPSHOT allows attackers to execute arbitrary commands and obtain sensitive information via supplying a crafted HTTP reque…

| Injection
Jun 15, 2026 Jun 15, 2026
Jun 15, 2026
Jun 15, 2026
0.0 NA
CVE-2026-50871 — kanishka-linux Reminiscence OS Command Injection

An OS command injection vulnerability in the media archiving and export pipeline component of kanishka-linux Reminiscence v0.3.0 allows attackers to execute arbitrary commands via supplying a crafted…

| Injection
Jun 15, 2026 Jun 15, 2026
Jun 15, 2026
Jun 15, 2026
0.0 NA
CVE-2026-50870 — Ben Busby whoogle-search Information Disclosure

An information disclosure vulnerability in the configuration endpoint of Ben Busby whoogle-search v1.2.3 allows attackers to obtain sensitive information via a crafted GET request.

| Information Disclosure
Jun 15, 2026 Jun 15, 2026
Jun 15, 2026
Jun 15, 2026
0.0 NA
CVE-2026-50869 — Bludit Directory Traversal

An issue in the api/plugin.php component of Bludit v3.19.0 allows attackers to execute a directory traversal via supplying a crafted request.

| Path Traversal
Jun 15, 2026 Jun 15, 2026
Jun 15, 2026
Jun 15, 2026
0.0 NA
CVE-2026-45390 — ocaml-tar Path Traversal

In OCaml-tar before 3.4.0, a crafted archive with ../ path segments in its name allows escaping the current working directory. This is not desired behavior, and tar(1) rejects such extractions, but o…

| Path Traversal
Jun 15, 2026 Jun 15, 2026
Jun 15, 2026
Jun 15, 2026
0.0 NA
CVE-2026-45389 — OCaml-TLS Client Certificate Impersonation

In OCaml-TLS before 2.1.0, the server implementation does insufficient checks of the certificate provided by the client (when doing client authentication), which allows impersonation with certificate…

| Authentication
Jun 15, 2026 Jun 15, 2026
Jun 15, 2026
Jun 15, 2026
0.0 NA
CVE-2026-45388 — OCaml-TLS Client Certificate Validation Vulnerability

In OCaml-TLS before 2.1.0, the client implementation does insufficient checks of the certificate provided by the server, which allows impersonation with certificates that are not meant for server aut…

| Authentication
Jun 15, 2026 Jun 15, 2026
Jun 15, 2026
Jun 15, 2026
0.0 NA
CVE-2026-39197 — Datadog Vector HTTP Prelude Denial of Service

An issue in the /util/http/prelude.rs endpoint of Datadog, Inc Vector v0.54.0 allows attackers to cause a Denial of Service (DoS) via a crafted request or payload.

| Denial of Service
Jun 15, 2026 Jun 15, 2026
Jun 15, 2026
Jun 15, 2026
0.0 NA
CVE-2026-50891 — Filestash Privilege Escalation

Incorrect access control in the /admin/api/config component of Filestash v0.4.0 allows attackers to escalate privileges via sending a crafted request.

| Authorization
Jun 15, 2026 Jun 15, 2026
Jun 15, 2026
Jun 15, 2026
0.0 NA
CVE-2026-39196 — Datadog Vector SQL Injection

Datadog, Inc Vector v0.54.0 was discovered to contain a SQL injection vulnerability in the set_uri_query parameter in the KeyPartitioner::partition function. This vulnerability allows attackers to ac…

| Injection
Jun 15, 2026 Jun 15, 2026
Jun 15, 2026
Jun 15, 2026
0.0 NA
CVE-2026-50889 — LLDAP HTTP Refresh Token Denial of Service

An input handling flaw in the HTTP refresh token process of LLDAP v0.6.2 allows attackers to cause a Denial of Service (DoS) via sending a crafted refresh-token header.

| Denial of Service
Jun 15, 2026 Jun 15, 2026
Jun 15, 2026
Jun 15, 2026
Showing 20 of 6644 Results