Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.7 HIGH
CVE-2026-49494 — Xcitium Client Security / Comodo Internet Security Remote Denial of Service

Comodo Internet Security's firewall driver Inspect.sys contains an integer underflow in its IPv6 packet parser. The parser decrements an unsigned 64-bit payload-length value (taken from the IPv6 fixe…

internet_security | Remote | Memory Corruption
Jun 07, 2026 Jun 08, 2026
Jun 07, 2026
Jun 08, 2026
3.3 LOW
CVE-2026-11459 — SecureAge CatchPulse IOCTL saappctl.sys information disclosure

A security vulnerability has been detected in SecureAge CatchPulse up to 10.9.3. Impacted is an unknown function in the library saappctl.sys of the component IOCTL Handler. The manipulation leads to …

catchpulse | Information Disclosure
Jun 07, 2026 Jun 12, 2026
Jun 07, 2026
Jun 12, 2026
5.5 MEDIUM
CVE-2026-11458 — erzhongxmu JeeWMS Boot Actuator Endpoint actuator information disclosure

A weakness has been identified in erzhongxmu JeeWMS up to 141740afb2ba14d441c82a833d0a418d07ca2d69. This issue affects some unknown processing of the file /base-boot/actuator of the component Boot Ac…

jeewms | Remote | Information Disclosure
Jun 07, 2026 Jun 08, 2026
Jun 07, 2026
Jun 08, 2026
7.5 HIGH
CVE-2026-11457 — erzhongxmu JeeWMS JimuReport test-connection Endpoint testConnection injection

A security flaw has been discovered in erzhongxmu JeeWMS up to 141740afb2ba14d441c82a833d0a418d07ca2d69. This vulnerability affects unknown code of the file /base-boot/jmreport/testConnection of the …

jeewms | Remote | Injection
Jun 07, 2026 Jun 08, 2026
Jun 07, 2026
Jun 08, 2026
7.5 HIGH
CVE-2026-11456 — Chanjet CRM HTTP GET Request jxf_dump_systable.php sql injection

A vulnerability was identified in Chanjet CRM 1.0. This affects an unknown part of the file /tools/jxf_dump_systable.php of the component HTTP GET Request Handler. Such manipulation of the argument g…

crm | Remote | Injection
Jun 07, 2026 Jun 08, 2026
Jun 07, 2026
Jun 08, 2026
5.0 MEDIUM
CVE-2026-11455 — FoundationAgents MetaGPT common.py check_cmd_exists command injection

A vulnerability was determined in FoundationAgents MetaGPT up to 0.8.2. Affected by this issue is the function check_cmd_exists of the file metagpt/utils/common.py. This manipulation of the argument …

metagpt | Remote | Injection
Jun 07, 2026 Jun 08, 2026
Jun 07, 2026
Jun 08, 2026
6.5 MEDIUM
CVE-2026-11453 — Tiobon Employee Self-Service System Login Endpoint BlogSearch.aspx sql injection

A vulnerability was found in Tiobon Employee Self-Service System up to 7.2. Affected by this vulnerability is an unknown functionality of the file /Blog/BlogSearch.aspx of the component Login Endpoin…

employee_self-service_system | Remote | Injection
Jun 07, 2026 Jun 08, 2026
Jun 07, 2026
Jun 08, 2026
7.5 HIGH
CVE-2026-11452 — GL.iNet GL-MT3000 SET_USER_PWD glc FUN_0042e200 command injection

A vulnerability has been found in GL.iNet GL-MT3000 up to 4.4.5. Affected is the function FUN_0042e200 of the file /cgi-bin/glc of the component SET_USER_PWD Handler. The manipulation of the argument…

gl-mt3000_firmware | Remote | Injection
Jun 07, 2026 Jun 08, 2026
Jun 07, 2026
Jun 08, 2026
7.5 HIGH
CVE-2026-11451 — GL.iNet GL-MT3000 FTP Protocol glc snprintf command injection

A flaw has been found in GL.iNet GL-MT3000 4.4.5. This impacts the function snprintf of the file /cgi-bin/glc of the component FTP Protocol Handler. Executing a manipulation of the argument media_dir…

gl-mt3000_firmware | Remote | Injection
Jun 07, 2026 Jun 08, 2026
Jun 07, 2026
Jun 08, 2026
7.5 HIGH
CVE-2026-11450 — GL.iNet GL-MT3000 Path Normalization dlopen command injection

A vulnerability was detected in GL.iNet GL-MT3000 4.4.5. This affects the function dlopen in the library /usr/lib/oui-httpd/rpc/ of the component Path Normalization Handler. Performing a manipulation…

gl-mt3000_firmware | Remote | Injection
Jun 07, 2026 Jun 08, 2026
Jun 07, 2026
Jun 08, 2026
6.5 MEDIUM
CVE-2026-11449 — GL.iNet GL-MT3000 LuCI JSON-RPC rpc rpc_sys command injection

A security vulnerability has been detected in GL.iNet GL-MT3000 4.4.5. The impacted element is the function rpc_sys of the file /cgi-bin/luci/rpc of the component LuCI JSON-RPC Interface. Such manipu…

gl-mt3000_firmware | Remote | Injection
Jun 07, 2026 Jun 09, 2026
Jun 07, 2026
Jun 09, 2026
5.8 MEDIUM
CVE-2026-11448 — GL.iNet GL-MT3000 Minidlna Service rpc realpath command injection

A weakness has been identified in GL.iNet GL-MT3000 up to 4.4.5. The affected element is the function realpath of the file /rpc of the component Minidlna Service. This manipulation of the argument ku…

gl-mt3000_firmware | Remote | Injection
Jun 07, 2026 Jun 08, 2026
Jun 07, 2026
Jun 08, 2026
6.5 MEDIUM
CVE-2026-11447 — GL.iNet GL-MT3000 MTK Backend iwinfo.so iwinfo_backend command injection

A security flaw has been discovered in GL.iNet GL-MT3000 up to 4.4.5. Impacted is the function iwinfo_backend of the file iwinfo.so of the component MTK Backend. The manipulation of the argument devi…

gl-mt3000_firmware | Remote | Injection
Jun 07, 2026 Jun 08, 2026
Jun 07, 2026
Jun 08, 2026
8.4 HIGH
CVE-2026-26422 — Clash Verge Service IPC Local Privilege Escalation

clash-verge-service-ipc before 2.3.0 has a world-reachable IPC endpoint, leading to local privilege escalation.

| Authentication
Jun 06, 2026 Jun 08, 2026
Jun 06, 2026
Jun 08, 2026
6.5 MEDIUM
CVE-2026-11441 — theonedev Pull Request issues canAccessIssue improper authorization

A vulnerability was identified in theonedev onedev up to 15.0.5. This vulnerability affects the function canAccessIssue of the file /issues/ of the component Pull Request Handler. Such manipulation o…

onedev | Remote | Authorization
Jun 06, 2026 Jun 08, 2026
Jun 06, 2026
Jun 08, 2026
6.5 MEDIUM
CVE-2026-11440 — theonedev REST API default-branch improper authorization

A vulnerability was determined in theonedev onedev up to 15.0.5. This affects an unknown part of the file /repositories/{projectId}/default-branch of the component REST API. This manipulation of the …

onedev | Remote | Authorization
Jun 06, 2026 Jun 08, 2026
Jun 06, 2026
Jun 08, 2026
6.5 MEDIUM
CVE-2026-11439 — theonedev Parent Project projects improper authorization

A vulnerability was found in theonedev onedev up to 15.0.5. Affected by this issue is some unknown functionality of the file /projects/ of the component Parent Project Handler. The manipulation of th…

onedev | Remote | Authorization
Jun 06, 2026 Jun 08, 2026
Jun 06, 2026
Jun 08, 2026
6.5 MEDIUM
CVE-2026-11438 — theonedev projects improper authorization

A vulnerability has been found in theonedev onedev up to 15.0.5. Affected by this vulnerability is an unknown functionality of the file /projects. The manipulation of the argument project.forkedFromI…

onedev | Remote | Authorization
Jun 06, 2026 Jun 08, 2026
Jun 06, 2026
Jun 08, 2026
7.5 HIGH
CVE-2026-11437 — perfree go-fastdfs-web Installation Endpoint checkServer server-side request forgery

A flaw has been found in perfree go-fastdfs-web up to 1.3.7. Affected is the function checkServer of the file /install/checkServer of the component Installation Endpoint. Executing a manipulation can…

go-fastdfs-web | Remote | Server-Side Request Forgery
Jun 06, 2026 Jun 08, 2026
Jun 06, 2026
Jun 08, 2026
5.0 MEDIUM
CVE-2026-11436 — Mage AI Sign-in Flow index.tsx useMutation cross site scripting

A vulnerability was detected in Mage AI up to 0.9.79. This impacts the function useMutation of the file mage_ai/frontend/components/Sessions/SignForm/index.tsx of the component Sign-in Flow. Performi…

mage_ai | Remote | Cross-Site Scripting
Jun 06, 2026 Jun 08, 2026
Jun 06, 2026
Jun 08, 2026
Showing 20 of 8061 Results