Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.5 MEDIUM
CVE-2026-42895 — Microsoft Copilot Tampering Vulnerability

None

365_copilot | Remote
Jun 19, 2026 Jun 19, 2026
Jun 19, 2026
Jun 19, 2026
10.0 CRITICAL
CVE-2026-45480 — Azure Active Directory Elevation of Privilege Vulnerability

None

Jun 19, 2026 Jun 19, 2026
Jun 19, 2026
Jun 19, 2026
8.8 HIGH
CVE-2026-32208 — Microsoft Edge (Chromium-based) Spoofing Vulnerability

None

edge edge_chromium | Remote
Jun 19, 2026 Jun 19, 2026
Jun 19, 2026
Jun 19, 2026
7.5 HIGH
CVE-2026-50559 — Authentication/Authorization Bypass via Advanced Path Normalization Vulnerabilities

Quarkus is a Java framework for building cloud-native applications. Prior to versions 3.37.0, 3.36.3, 3.33.2.1, 3.33.3, 3.27.4.1, 3.27.5, and 3.20.6.2, Quarkus HTTP path-based authorization policies …

Remote | Authorization
Jun 19, 2026 Jun 19, 2026
Jun 19, 2026
Jun 19, 2026
1.3 LOW
CVE-2026-48794 — Authelia has an Edge Case Access Control Rule Mismatch

Authelia is an open-source authentication and authorization server providing two-factor authentication and single sign-on (SSO) for applications via a web portal. In versions 4.36.0 through 4.39.19, …

authelia | Remote | Authorization
Jun 19, 2026 Jun 19, 2026
Jun 19, 2026
Jun 19, 2026
2.9 LOW
CVE-2026-47203 — Authelia Missing Username Canonicalization in Basic Auth (LDAP)

Authelia is an open-source authentication and authorization server providing two-factor authentication and single sign-on (SSO) for applications via a web portal. In versions 4.38.0 through 4.39.19, …

authelia | Remote | Authentication
Jun 19, 2026 Jun 19, 2026
Jun 19, 2026
Jun 19, 2026
6.5 MEDIUM
CVE-2026-48129 — Kestra task inputFiles accepts traversal filenames for worker file writes

Kestra is an open-source, event-driven orchestration platform. Prior to versions 1.3.19, 1.2.19, 1.1.19, and 1.0.43, Kestra task `inputFiles` writes rendered file names directly under the task workin…

kestra | Remote | Path Traversal
Jun 19, 2026 Jun 19, 2026
Jun 19, 2026
Jun 19, 2026
7.1 HIGH
CVE-2026-49346 — libde265 has a heap buffer overflow in de265_image_get_buffer via SPS dimension integer o…

libde265 is an open source implementation of the h.265 video codec. Prior to version 1.1.0, a crafted H.265 bitstream with large SPS dimensions and 16-bit bit depth causes a signed integer overflow i…

libde265 | Remote | Memory Corruption
Jun 19, 2026 Jun 19, 2026
Jun 19, 2026
Jun 19, 2026
7.1 HIGH
CVE-2026-49295 — libde265 has an out-of-bounds write in process_reference_picture_set via predicted short-…

libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.20, a crafted H.265 bitstream can cause an out-of-bounds array write in `decoder_context::process_reference_pi…

libde265 | Remote | Memory Corruption
Jun 19, 2026 Jun 19, 2026
Jun 19, 2026
Jun 19, 2026
4.3 MEDIUM
CVE-2026-49337 — libde265 has an unbounded memory leak via orphaned slice headers in `read_slice_NAL`

libde265 is an open source implementation of the h.265 video codec. Prior to version 1.0.20, a crafted sequence of H.265 NAL units causes `decoder_context::read_slice_NAL()` (`libde265/decctx.cc:481`…

libde265 | Remote | Denial of Service
Jun 19, 2026 Jun 19, 2026
Jun 19, 2026
Jun 19, 2026
7.4 HIGH
CVE-2026-48787 — gin-vue-admin vulnerable to RCE

gin-vue-admin is an AI-assisted basic development platform. In version 2.9.1, an authenticated attacker with access to the code-generation feature and MCP management interface can exploit this vulner…

gin-vue-admin | Remote | Injection
Jun 19, 2026 Jun 19, 2026
Jun 19, 2026
Jun 19, 2026
7.1 HIGH
CVE-2026-48089 — DevGuard has improper authorization on public assets

DevGuard provides vulnerability management for the full software supply chain. Prior to 1.4.2, on a DevGuard API instance with one or more public assets, any authenticated user — including users from…

Remote | Authorization
Jun 19, 2026 Jun 19, 2026
Jun 19, 2026
Jun 19, 2026
7.5 HIGH
CVE-2026-48774 — ProxySQL MCP run_sql_readonly executes side-effecting MySQL multi-statements despite read…

ProxySQL is a proxy for MySQL and its forks, as well as PostgreSQL. In versions 3.0.0 through 3.0.8, ProxySQL's GenAI/MCP `run_sql_readonly` tool violates its documented read-only contract for MySQL …

Remote | Authorization
Jun 19, 2026 Jun 19, 2026
Jun 19, 2026
Jun 19, 2026
10.0 CRITICAL
CVE-2026-48772 — ProxySQL: PROXY-Protocol-v1 UNKNOWN parses spoofed source IP, bypassing mysql_query_rules…

ProxySQL is a proxy for MySQL and its forks, as well as PostgreSQL. In versions 2.0.0 through 3.0.8, the ProxySQL MySQL frontend accepts the `PROXY UNKNOWN <addr> <addr> <port> <port>\r\n` PP1 frame …

Remote | Misconfiguration
Jun 19, 2026 Jun 19, 2026
Jun 19, 2026
Jun 19, 2026
9.8 CRITICAL
CVE-2026-48773 — ProxySQL pre-auth heap overflow in MySQL and PostgreSQL first-packet handling

ProxySQL is a proxy for MySQL and its forks, as well as PostgreSQL. Versions 2.0.18 through 3.0.8 have a pre-authentication heap memory corruption vulnerability in the MySQL and PostgreSQL protocol f…

Remote | Memory Corruption
Jun 19, 2026 Jun 19, 2026
Jun 19, 2026
Jun 19, 2026
5.3 MEDIUM
CVE-2026-49345 — Mercator CVE Configuration Vulnerable to Server-Side Request Forgery (SSRF)

Mercator is an open source web application that enables mapping of the information system. Prior to version 2025.05.19, a Server-Side Request Forgery (SSRF) vulnerability exists in Mercator's CVE con…

mercator | Remote | Server-Side Request Forgery
Jun 19, 2026 Jun 19, 2026
Jun 19, 2026
Jun 19, 2026
7.1 HIGH
CVE-2026-49344 — Mercator has a Personal Identifiable Information Leak from Query Executor feature

Mercator is an open source web application that enables mapping of the information system. Prior to version 2025.05.19, Mercator's Query Engine (`/admin/queries/execute`) accepts a JSON DSL (`from` /…

mercator | Remote | Authorization
Jun 19, 2026 Jun 19, 2026
Jun 19, 2026
Jun 19, 2026
7.7 HIGH
CVE-2026-48715 — radvdump's Route Information Option Parser has a Stack Buffer Overflow

radvd is a router advertisement daemon for IPv6. Prior to version 2.21, the `radvdump` utility shipped with radvd contains a stack buffer overflow in the Route Information option parser. When process…

| Memory Corruption
Jun 19, 2026 Jun 19, 2026
Jun 19, 2026
Jun 19, 2026
5.3 MEDIUM
CVE-2026-49342 — YARD static cache reads raw traversal paths before router sanitization

YARD is a documentation generation tool for the Ruby programming language. Prior to version 0.9.44, YARD's static cache lookup reads a request path before the router's path cleanup runs. When a serve…

yard | Remote | Path Traversal
Jun 19, 2026 Jun 19, 2026
Jun 19, 2026
Jun 19, 2026
8.1 HIGH
CVE-2026-49340 — gonic has arbitrary file write in createPlaylist: any authenticated user can write playli…

gonic is a music streaming server / free-software subsonic server API implementation. Prior to version 0.21.0, a logic error in `ServeCreateOrUpdatePlaylist` allows any authenticated Subsonic user (i…

Remote | Path Traversal
Jun 19, 2026 Jun 19, 2026
Jun 19, 2026
Jun 19, 2026
Showing 20 of 7530 Results