Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-12823 — Browserbase Autobrowse Trace Artifact default permission

A security flaw has been discovered in Browserbase up to 20260526. This impacts an unknown function of the component Autobrowse Trace Artifact Handler. The manipulation results in incorrect default p…

| Misconfiguration
Jun 21, 2026 Jun 21, 2026
Jun 21, 2026
Jun 21, 2026
0.0 NA
CVE-2026-12822 — langflow-ai langflow Bundle URL Loader code injection

A vulnerability was identified in langflow-ai langflow up to 1.9.3. This affects an unknown function of the component Bundle URL Loader. The manipulation leads to code injection. The attack needs to …

| Injection
Jun 21, 2026 Jun 21, 2026
Jun 21, 2026
Jun 21, 2026
0.0 NA
CVE-2026-12821 — FlowiseAI Flowise S3 Document Loader S3.ts path traversal

A vulnerability was determined in FlowiseAI Flowise up to 3.1.2. The impacted element is an unknown function of the file packages/components/nodes/documentloaders/S3/S3.ts of the component S3 Documen…

flowise | Path Traversal
Jun 21, 2026 Jun 21, 2026
Jun 21, 2026
Jun 21, 2026
0.0 NA
CVE-2026-12815 — coollabsio coolify Image Name os command injection

A vulnerability has been found in coollabsio coolify 4.0.0. Impacted is an unknown function of the component Image Name Handler. Such manipulation leads to os command injection. The attack may be per…

| Injection
Jun 21, 2026 Jun 21, 2026
Jun 21, 2026
Jun 21, 2026
0.0 NA
CVE-2026-12814 — Comfast CF-WR631AX V3 API Endpoint mbox-config system os command injection

A flaw has been found in Comfast CF-WR631AX V3 up to 2.7.0.8. This issue affects the function system of the file /cgi-bin/mbox-config?section=ping_config of the component API Endpoint. This manipulat…

| Injection
Jun 21, 2026 Jun 21, 2026
Jun 21, 2026
Jun 21, 2026
0.0 NA
CVE-2026-12813 — activepieces File URL file.ts handleUrlFile server-side request forgery

A vulnerability was detected in activepieces up to 0.83.0. This vulnerability affects the function handleUrlFile in the library packages/server/engine/src/lib/variables/processors/file.ts of the comp…

| Server-Side Request Forgery
Jun 21, 2026 Jun 21, 2026
Jun 21, 2026
Jun 21, 2026
0.0 NA
CVE-2026-12812 — Radware Cyber Controller HTML Report Generation HTML injection

A security vulnerability has been detected in Radware Cyber Controller up to 10.11.0. This affects an unknown part of the component HTML Report Generation. The manipulation leads to HTML injection. R…

| Injection
Jun 21, 2026 Jun 21, 2026
Jun 21, 2026
Jun 21, 2026
0.0 NA
CVE-2026-12811 — kortix-ai suna Auth Endpoint page.tsx router.push cross site scripting

A weakness has been identified in kortix-ai suna up to 0.8.38. Affected by this issue is the function router.replace/router.push of the file apps/frontend/src/app/auth/page.tsx of the component Auth …

| Cross-Site Scripting
Jun 21, 2026 Jun 21, 2026
Jun 21, 2026
Jun 21, 2026
0.0 NA
CVE-2026-12810 — Edimax BR-6478AC V2 POST Request mp command injection

A security flaw has been discovered in Edimax BR-6478AC V2 1.23. Affected by this vulnerability is the function mp of the file /goform/mp of the component POST Request Handler. Performing a manipulat…

br-6478ac | Injection
Jun 21, 2026 Jun 21, 2026
Jun 21, 2026
Jun 21, 2026
0.0 NA
CVE-2026-12809 — Edimax BR-6478AC V2 POST Request wiz_5in1_redirect command injection

A vulnerability was identified in Edimax BR-6478AC V2 1.23. Affected is the function wiz_5in1_redirect of the file /goform/wiz_5in1_redirect of the component POST Request Handler. Such manipulation o…

br-6478ac | Injection
Jun 21, 2026 Jun 21, 2026
Jun 21, 2026
Jun 21, 2026
6.5 MEDIUM
CVE-2026-12808 — Edimax BR-6478AC V2 POST Request stainfo command injection

A vulnerability was determined in Edimax BR-6478AC V2 1.23. This impacts the function stainfo of the file /goform/stainfo of the component POST Request Handler. This manipulation of the argument inte…

br-6478ac | Remote | Injection
Jun 21, 2026 Jun 21, 2026
Jun 21, 2026
Jun 21, 2026
6.5 MEDIUM
CVE-2026-12807 — Edimax BR-6478AC V2 POST Request setWAN command injection

A vulnerability was found in Edimax BR-6478AC V2 1.23. This affects the function setWAN of the file /goform/setWAN of the component POST Request Handler. The manipulation of the argument pppUserName/…

br-6478ac | Remote | Injection
Jun 21, 2026 Jun 21, 2026
Jun 21, 2026
Jun 21, 2026
9.0 HIGH
CVE-2026-12806 — Edimax BR-6478AC V2 POST Request formWlSiteSurvey buffer overflow

A vulnerability has been found in Edimax BR-6478AC V2 1.23. The impacted element is the function formWlSiteSurvey of the file /goform/formWlSiteSurvey of the component POST Request Handler. The manip…

br-6478ac | Remote | Memory Corruption
Jun 21, 2026 Jun 21, 2026
Jun 21, 2026
Jun 21, 2026
7.5 HIGH
CVE-2026-12805 — OFFIS DCMTK ofxml.cc parseFile heap-based overflow

A flaw has been found in OFFIS DCMTK up to 3.7.0. The affected element is the function XMLNode::parseFile in the library ofstd/libsrc/ofxml.cc. Executing a manipulation can lead to heap-based buffer …

dcmtk | Remote | Memory Corruption
Jun 21, 2026 Jun 21, 2026
Jun 21, 2026
Jun 21, 2026
5.0 MEDIUM
CVE-2026-12804 — lemonldap-ng SAML Common Domain Cookie Endpoint CDC.pm redirect

A vulnerability was detected in lemonldap-ng up to 2.23.0. Impacted is an unknown function in the library lemonldap-ng-portal/lib/Lemonldap/NG/Portal/CDC.pm of the component SAML Common Domain Cookie…

Remote | Misconfiguration
Jun 21, 2026 Jun 21, 2026
Jun 21, 2026
Jun 21, 2026
4.9 MEDIUM
CVE-2026-56412 — Expat Use-After-Free Vulnerability

libexpat before 2.8.2 does not consider XML_TOK_DATA_CHARS in doCdataSection and thus lacks handler call depth tracking for various calls from within handlers in cases of a policy violation. Thus, a …

libexpat | Memory Corruption
Jun 21, 2026 Jun 21, 2026
Jun 21, 2026
Jun 21, 2026
6.9 MEDIUM
CVE-2026-56411 — libexpat: Integer Overflow in endDoctypeDecl

xmlwf in libexpat before 2.8.2 has an integer overflow in endDoctypeDecl via NOTATION declarations.

libexpat | Injection
Jun 21, 2026 Jun 21, 2026
Jun 21, 2026
Jun 21, 2026
6.9 MEDIUM
CVE-2026-56410 — libexpat Integer Overflow

xmlwf in libexpat before 2.8.2 has an integer overflow in resolveSystemId.

libexpat | Misconfiguration
Jun 21, 2026 Jun 21, 2026
Jun 21, 2026
Jun 21, 2026
6.5 MEDIUM
CVE-2026-56409 — libexpat: Integer Overflow in xmlwf Output Filename

xmlwf in libexpat before 2.8.2 has an integer overflow for the output filename when -d outputDir is used.

libexpat | Memory Corruption
Jun 21, 2026 Jun 21, 2026
Jun 21, 2026
Jun 21, 2026
6.9 MEDIUM
CVE-2026-56408 — libexpat Integer Overflow

libexpat before 2.8.2 has an integer overflow in copyString.

libexpat | Memory Corruption
Jun 21, 2026 Jun 21, 2026
Jun 21, 2026
Jun 21, 2026
Showing 20 of 7361 Results