Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-12804 — lemonldap-ng SAML Common Domain Cookie Endpoint CDC.pm redirect

A vulnerability was detected in lemonldap-ng up to 2.23.0. Impacted is an unknown function in the library lemonldap-ng-portal/lib/Lemonldap/NG/Portal/CDC.pm of the component SAML Common Domain Cookie…

| Misconfiguration
Jun 21, 2026 Jun 21, 2026
Jun 21, 2026
Jun 21, 2026
4.9 MEDIUM
CVE-2026-56412 — Expat Use-After-Free Vulnerability

libexpat before 2.8.2 does not consider XML_TOK_DATA_CHARS in doCdataSection and thus lacks handler call depth tracking for various calls from within handlers in cases of a policy violation. Thus, a …

| Memory Corruption
Jun 21, 2026 Jun 21, 2026
Jun 21, 2026
Jun 21, 2026
6.9 MEDIUM
CVE-2026-56411 — libexpat: Integer Overflow in endDoctypeDecl

xmlwf in libexpat before 2.8.2 has an integer overflow in endDoctypeDecl via NOTATION declarations.

| Injection
Jun 21, 2026 Jun 21, 2026
Jun 21, 2026
Jun 21, 2026
6.9 MEDIUM
CVE-2026-56410 — libexpat Integer Overflow

xmlwf in libexpat before 2.8.2 has an integer overflow in resolveSystemId.

| Misconfiguration
Jun 21, 2026 Jun 21, 2026
Jun 21, 2026
Jun 21, 2026
6.5 MEDIUM
CVE-2026-56409 — libexpat: Integer Overflow in xmlwf Output Filename

xmlwf in libexpat before 2.8.2 has an integer overflow for the output filename when -d outputDir is used.

| Memory Corruption
Jun 21, 2026 Jun 21, 2026
Jun 21, 2026
Jun 21, 2026
6.9 MEDIUM
CVE-2026-56408 — libexpat Integer Overflow

libexpat before 2.8.2 has an integer overflow in copyString.

| Memory Corruption
Jun 21, 2026 Jun 21, 2026
Jun 21, 2026
Jun 21, 2026
6.9 MEDIUM
CVE-2026-56407 — libexpat Integer Overflow

libexpat before 2.8.2 has an integer overflow in doProlog that is related to storeEntityValue and entity textLen.

| Memory Corruption
Jun 21, 2026 Jun 21, 2026
Jun 21, 2026
Jun 21, 2026
6.9 MEDIUM
CVE-2026-56406 — Expat XML_ParseBuffer Integer Overflow

libexpat before 2.8.2 has an integer overflow in XML_ParseBuffer because it lacked a check that was present in XML_Parse.

| Memory Corruption
Jun 21, 2026 Jun 21, 2026
Jun 21, 2026
Jun 21, 2026
6.9 MEDIUM
CVE-2026-56405 — libexpat Integer Overflow

libexpat before 2.8.2 has an integer overflow in getAttributeId.

| Memory Corruption
Jun 21, 2026 Jun 21, 2026
Jun 21, 2026
Jun 21, 2026
6.9 MEDIUM
CVE-2026-56404 — libexpat Integer Overflow

libexpat before 2.8.2 has an integer overflow in addBinding.

| Memory Corruption
Jun 21, 2026 Jun 21, 2026
Jun 21, 2026
Jun 21, 2026
6.9 MEDIUM
CVE-2026-56403 — Expat Integer Overflow

libexpat before 2.8.2 has an integer overflow in storeAtts.

| Memory Corruption
Jun 21, 2026 Jun 21, 2026
Jun 21, 2026
Jun 21, 2026
9.6 CRITICAL
CVE-2026-56397 — SiYuan - Remote Code Execution via Malicious Bazaar Package Metadata and README

SiYuan before v3.6.1 fails to sanitize package metadata and README content in the Bazaar marketplace, allowing malicious package authors to inject arbitrary HTML and JavaScript. Attackers can achieve…

Remote | Cross-Site Scripting
Jun 21, 2026 Jun 21, 2026
Jun 21, 2026
Jun 21, 2026
8.8 HIGH
CVE-2026-56396 — phpMyFAQ - Privilege Escalation via Missing Authorization in editUser() and updateUserRig…

phpMyFAQ before 4.1.4 contains missing authorization vulnerabilities in editUser() and updateUserRights() endpoints that allow authenticated administrators to escalate privileges. Non-SuperAdmin user…

Remote | Authorization
Jun 21, 2026 Jun 21, 2026
Jun 21, 2026
Jun 21, 2026
9.6 CRITICAL
CVE-2026-56395 — SiYuan - Remote Code Execution via Malicious Bazaar Package Metadata and README

SiYuan before v3.6.1 fails to sanitize package metadata and README content in the Bazaar marketplace, allowing malicious package authors to inject arbitrary HTML and JavaScript. Attackers can achieve…

Remote | Cross-Site Scripting
Jun 21, 2026 Jun 21, 2026
Jun 21, 2026
Jun 21, 2026
7.1 HIGH
CVE-2026-56394 — Craft CMS - Authenticated Path Traversal in assets/icon Extension Parameter

Craft CMS from 4.0.0-RC1 contains an authenticated path traversal vulnerability in the assets/icon endpoint where the extension parameter is not validated before file existence checks. Attackers can …

Remote | Path Traversal
Jun 21, 2026 Jun 21, 2026
Jun 21, 2026
Jun 21, 2026
4.8 MEDIUM
CVE-2026-56393 — Craft CMS - Multiple Stored Cross-Site Scripting in Settings Names and Field Options

Craft CMS 4.x (>= 4.0.0-RC1, < 4.17.0-beta.1) and 5.x (>= 5.0.0-RC1, < 5.9.0-beta.1) contain multiple stored cross-site scripting vulnerabilities where settings names and field option labels are rend…

Remote | Cross-Site Scripting
Jun 21, 2026 Jun 21, 2026
Jun 21, 2026
Jun 21, 2026
5.3 MEDIUM
CVE-2026-56385 — Craft CMS - Authorization Bypass in assets/preview-file Endpoint

Craft CMS versions >= 5.0.0-RC1, <= 5.9.13 and >= 4.0.0-RC1, <= 4.17.7 contain an authorization bypass in the assets/preview-file endpoint. The action does not enforce per-asset view authorization be…

Remote | Authorization
Jun 21, 2026 Jun 21, 2026
Jun 21, 2026
Jun 21, 2026
5.3 MEDIUM
CVE-2026-56384 — Craft CMS - Missing Authorization in assets/preview-thumb Endpoint

Craft CMS contains a missing authorization vulnerability in the assets/preview-thumb endpoint. A Control Panel user without permission to view a target private asset can call the endpoint with an att…

Remote | Authorization
Jun 21, 2026 Jun 21, 2026
Jun 21, 2026
Jun 21, 2026
4.8 MEDIUM
CVE-2026-56383 — Craft CMS - Stored XSS in Table Field via Row Heading Column Type

Craft CMS contains a stored cross-site scripting (XSS) vulnerability in the editableTable.twig component when using the 'Row Heading' column type. The application fails to sanitize input within row h…

Remote | Cross-Site Scripting
Jun 21, 2026 Jun 21, 2026
Jun 21, 2026
Jun 21, 2026
8.6 HIGH
CVE-2026-56382 — Craft CMS - Remote Code Execution via Missing Config Sanitization in FieldsController

Craft CMS (composer package craftcms/cms) versions >= 5.5.0 and <= 5.9.13 contain a remote code execution vulnerability in the FieldsController::actionRenderCardPreview() method, which passes the fie…

Remote | Injection
Jun 21, 2026 Jun 21, 2026
Jun 21, 2026
Jun 21, 2026
Showing 20 of 7380 Results