Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-12808 — Edimax BR-6478AC V2 POST Request stainfo command injection

A vulnerability was determined in Edimax BR-6478AC V2 1.23. This impacts the function stainfo of the file /goform/stainfo of the component POST Request Handler. This manipulation of the argument inte…

br-6478ac | Injection
Jun 21, 2026 Jun 21, 2026
Jun 21, 2026
Jun 21, 2026
0.0 NA
CVE-2026-12807 — Edimax BR-6478AC V2 POST Request setWAN command injection

A vulnerability was found in Edimax BR-6478AC V2 1.23. This affects the function setWAN of the file /goform/setWAN of the component POST Request Handler. The manipulation of the argument pppUserName/…

br-6478ac | Injection
Jun 21, 2026 Jun 21, 2026
Jun 21, 2026
Jun 21, 2026
0.0 NA
CVE-2026-12806 — Edimax BR-6478AC V2 POST Request formWlSiteSurvey buffer overflow

A vulnerability has been found in Edimax BR-6478AC V2 1.23. The impacted element is the function formWlSiteSurvey of the file /goform/formWlSiteSurvey of the component POST Request Handler. The manip…

br-6478ac | Memory Corruption
Jun 21, 2026 Jun 21, 2026
Jun 21, 2026
Jun 21, 2026
0.0 NA
CVE-2026-12805 — OFFIS DCMTK ofxml.cc parseFile heap-based overflow

A flaw has been found in OFFIS DCMTK up to 3.7.0. The affected element is the function XMLNode::parseFile in the library ofstd/libsrc/ofxml.cc. Executing a manipulation can lead to heap-based buffer …

dcmtk | Memory Corruption
Jun 21, 2026 Jun 21, 2026
Jun 21, 2026
Jun 21, 2026
5.0 MEDIUM
CVE-2026-12804 — lemonldap-ng SAML Common Domain Cookie Endpoint CDC.pm redirect

A vulnerability was detected in lemonldap-ng up to 2.23.0. Impacted is an unknown function in the library lemonldap-ng-portal/lib/Lemonldap/NG/Portal/CDC.pm of the component SAML Common Domain Cookie…

Remote | Misconfiguration
Jun 21, 2026 Jun 21, 2026
Jun 21, 2026
Jun 21, 2026
4.9 MEDIUM
CVE-2026-56412 — Expat Use-After-Free Vulnerability

libexpat before 2.8.2 does not consider XML_TOK_DATA_CHARS in doCdataSection and thus lacks handler call depth tracking for various calls from within handlers in cases of a policy violation. Thus, a …

libexpat | Memory Corruption
Jun 21, 2026 Jun 21, 2026
Jun 21, 2026
Jun 21, 2026
6.9 MEDIUM
CVE-2026-56411 — libexpat: Integer Overflow in endDoctypeDecl

xmlwf in libexpat before 2.8.2 has an integer overflow in endDoctypeDecl via NOTATION declarations.

libexpat | Injection
Jun 21, 2026 Jun 21, 2026
Jun 21, 2026
Jun 21, 2026
6.9 MEDIUM
CVE-2026-56410 — libexpat Integer Overflow

xmlwf in libexpat before 2.8.2 has an integer overflow in resolveSystemId.

libexpat | Misconfiguration
Jun 21, 2026 Jun 21, 2026
Jun 21, 2026
Jun 21, 2026
6.5 MEDIUM
CVE-2026-56409 — libexpat: Integer Overflow in xmlwf Output Filename

xmlwf in libexpat before 2.8.2 has an integer overflow for the output filename when -d outputDir is used.

libexpat | Memory Corruption
Jun 21, 2026 Jun 21, 2026
Jun 21, 2026
Jun 21, 2026
6.9 MEDIUM
CVE-2026-56408 — libexpat Integer Overflow

libexpat before 2.8.2 has an integer overflow in copyString.

libexpat | Memory Corruption
Jun 21, 2026 Jun 21, 2026
Jun 21, 2026
Jun 21, 2026
6.9 MEDIUM
CVE-2026-56407 — libexpat Integer Overflow

libexpat before 2.8.2 has an integer overflow in doProlog that is related to storeEntityValue and entity textLen.

libexpat | Memory Corruption
Jun 21, 2026 Jun 21, 2026
Jun 21, 2026
Jun 21, 2026
6.9 MEDIUM
CVE-2026-56406 — Expat XML_ParseBuffer Integer Overflow

libexpat before 2.8.2 has an integer overflow in XML_ParseBuffer because it lacked a check that was present in XML_Parse.

libexpat | Memory Corruption
Jun 21, 2026 Jun 21, 2026
Jun 21, 2026
Jun 21, 2026
6.9 MEDIUM
CVE-2026-56405 — libexpat Integer Overflow

libexpat before 2.8.2 has an integer overflow in getAttributeId.

libexpat | Memory Corruption
Jun 21, 2026 Jun 21, 2026
Jun 21, 2026
Jun 21, 2026
6.9 MEDIUM
CVE-2026-56404 — libexpat Integer Overflow

libexpat before 2.8.2 has an integer overflow in addBinding.

libexpat | Memory Corruption
Jun 21, 2026 Jun 21, 2026
Jun 21, 2026
Jun 21, 2026
6.9 MEDIUM
CVE-2026-56403 — Expat Integer Overflow

libexpat before 2.8.2 has an integer overflow in storeAtts.

libexpat | Memory Corruption
Jun 21, 2026 Jun 21, 2026
Jun 21, 2026
Jun 21, 2026
9.6 CRITICAL
CVE-2026-56397 — SiYuan - Remote Code Execution via Malicious Bazaar Package Metadata and README

SiYuan before v3.6.1 fails to sanitize package metadata and README content in the Bazaar marketplace, allowing malicious package authors to inject arbitrary HTML and JavaScript. Attackers can achieve…

siyuan | Remote | Cross-Site Scripting
Jun 21, 2026 Jun 21, 2026
Jun 21, 2026
Jun 21, 2026
8.8 HIGH
CVE-2026-56396 — phpMyFAQ - Privilege Escalation via Missing Authorization in editUser() and updateUserRig…

phpMyFAQ before 4.1.4 contains missing authorization vulnerabilities in editUser() and updateUserRights() endpoints that allow authenticated administrators to escalate privileges. Non-SuperAdmin user…

phpmyfaq | Remote | Authorization
Jun 21, 2026 Jun 21, 2026
Jun 21, 2026
Jun 21, 2026
9.6 CRITICAL
CVE-2026-56395 — SiYuan - Remote Code Execution via Malicious Bazaar Package Metadata and README

SiYuan before v3.6.1 fails to sanitize package metadata and README content in the Bazaar marketplace, allowing malicious package authors to inject arbitrary HTML and JavaScript. Attackers can achieve…

siyuan | Remote | Cross-Site Scripting
Jun 21, 2026 Jun 21, 2026
Jun 21, 2026
Jun 21, 2026
7.1 HIGH
CVE-2026-56394 — Craft CMS - Authenticated Path Traversal in assets/icon Extension Parameter

Craft CMS from 4.0.0-RC1 contains an authenticated path traversal vulnerability in the assets/icon endpoint where the extension parameter is not validated before file existence checks. Attackers can …

cms | Remote | Path Traversal
Jun 21, 2026 Jun 21, 2026
Jun 21, 2026
Jun 21, 2026
4.8 MEDIUM
CVE-2026-56393 — Craft CMS - Multiple Stored Cross-Site Scripting in Settings Names and Field Options

Craft CMS 4.x (>= 4.0.0-RC1, < 4.17.0-beta.1) and 5.x (>= 5.0.0-RC1, < 5.9.0-beta.1) contain multiple stored cross-site scripting vulnerabilities where settings names and field option labels are rend…

cms | Remote | Cross-Site Scripting
Jun 21, 2026 Jun 21, 2026
Jun 21, 2026
Jun 21, 2026
Showing 20 of 7372 Results