Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.9 MEDIUM
CVE-2026-56405 — libexpat Integer Overflow

libexpat before 2.8.2 has an integer overflow in getAttributeId.

libexpat | Memory Corruption
Jun 21, 2026 Jun 21, 2026
Jun 21, 2026
Jun 21, 2026
6.9 MEDIUM
CVE-2026-56404 — libexpat Integer Overflow

libexpat before 2.8.2 has an integer overflow in addBinding.

libexpat | Memory Corruption
Jun 21, 2026 Jun 21, 2026
Jun 21, 2026
Jun 21, 2026
6.9 MEDIUM
CVE-2026-56403 — Expat Integer Overflow

libexpat before 2.8.2 has an integer overflow in storeAtts.

libexpat | Memory Corruption
Jun 21, 2026 Jun 21, 2026
Jun 21, 2026
Jun 21, 2026
9.6 CRITICAL
CVE-2026-56397 — SiYuan - Remote Code Execution via Malicious Bazaar Package Metadata and README

SiYuan before v3.6.1 fails to sanitize package metadata and README content in the Bazaar marketplace, allowing malicious package authors to inject arbitrary HTML and JavaScript. Attackers can achieve…

siyuan | Remote | Cross-Site Scripting
Jun 21, 2026 Jun 21, 2026
Jun 21, 2026
Jun 21, 2026
8.8 HIGH
CVE-2026-56396 — phpMyFAQ - Privilege Escalation via Missing Authorization in editUser() and updateUserRig…

phpMyFAQ before 4.1.4 contains missing authorization vulnerabilities in editUser() and updateUserRights() endpoints that allow authenticated administrators to escalate privileges. Non-SuperAdmin user…

phpmyfaq | Remote | Authorization
Jun 21, 2026 Jun 21, 2026
Jun 21, 2026
Jun 21, 2026
9.6 CRITICAL
CVE-2026-56395 — SiYuan - Remote Code Execution via Malicious Bazaar Package Metadata and README

SiYuan before v3.6.1 fails to sanitize package metadata and README content in the Bazaar marketplace, allowing malicious package authors to inject arbitrary HTML and JavaScript. Attackers can achieve…

siyuan | Remote | Cross-Site Scripting
Jun 21, 2026 Jun 21, 2026
Jun 21, 2026
Jun 21, 2026
7.1 HIGH
CVE-2026-56394 — Craft CMS - Authenticated Path Traversal in assets/icon Extension Parameter

Craft CMS from 4.0.0-RC1 contains an authenticated path traversal vulnerability in the assets/icon endpoint where the extension parameter is not validated before file existence checks. Attackers can …

cms | Remote | Path Traversal
Jun 21, 2026 Jun 21, 2026
Jun 21, 2026
Jun 21, 2026
4.8 MEDIUM
CVE-2026-56393 — Craft CMS - Multiple Stored Cross-Site Scripting in Settings Names and Field Options

Craft CMS 4.x (>= 4.0.0-RC1, < 4.17.0-beta.1) and 5.x (>= 5.0.0-RC1, < 5.9.0-beta.1) contain multiple stored cross-site scripting vulnerabilities where settings names and field option labels are rend…

cms | Remote | Cross-Site Scripting
Jun 21, 2026 Jun 21, 2026
Jun 21, 2026
Jun 21, 2026
5.3 MEDIUM
CVE-2026-56385 — Craft CMS - Authorization Bypass in assets/preview-file Endpoint

Craft CMS versions >= 5.0.0-RC1, <= 5.9.13 and >= 4.0.0-RC1, <= 4.17.7 contain an authorization bypass in the assets/preview-file endpoint. The action does not enforce per-asset view authorization be…

cms | Remote | Authorization
Jun 21, 2026 Jun 21, 2026
Jun 21, 2026
Jun 21, 2026
5.3 MEDIUM
CVE-2026-56384 — Craft CMS - Missing Authorization in assets/preview-thumb Endpoint

Craft CMS contains a missing authorization vulnerability in the assets/preview-thumb endpoint. A Control Panel user without permission to view a target private asset can call the endpoint with an att…

cms | Remote | Authorization
Jun 21, 2026 Jun 21, 2026
Jun 21, 2026
Jun 21, 2026
4.8 MEDIUM
CVE-2026-56383 — Craft CMS - Stored XSS in Table Field via Row Heading Column Type

Craft CMS contains a stored cross-site scripting (XSS) vulnerability in the editableTable.twig component when using the 'Row Heading' column type. The application fails to sanitize input within row h…

cms | Remote | Cross-Site Scripting
Jun 21, 2026 Jun 21, 2026
Jun 21, 2026
Jun 21, 2026
8.6 HIGH
CVE-2026-56382 — Craft CMS - Remote Code Execution via Missing Config Sanitization in FieldsController

Craft CMS (composer package craftcms/cms) versions >= 5.5.0 and <= 5.9.13 contain a remote code execution vulnerability in the FieldsController::actionRenderCardPreview() method, which passes the fie…

cms | Remote | Injection
Jun 21, 2026 Jun 21, 2026
Jun 21, 2026
Jun 21, 2026
4.8 MEDIUM
CVE-2026-56381 — Craft CMS - Stored XSS via User Group Name in User Permissions Page

Craft CMS from version 5.0.0-RC1 contains a stored cross-site scripting vulnerability in the User Permissions page where user group names are rendered without proper HTML escaping. Attackers with adm…

cms | Remote | Cross-Site Scripting
Jun 21, 2026 Jun 21, 2026
Jun 21, 2026
Jun 21, 2026
6.3 MEDIUM
CVE-2026-56378 — ImageMagick - Heap Out-of-Bounds Read in PCD Decoder

ImageMagick before 7.1.2-15 (and 6.x before 6.9.13-40) contains a heap out-of-bounds read in the PCD coder's DecodeImage loop. A crafted PCD file can trigger a one-byte heap out-of-bounds read during…

imagemagick | Remote | Memory Corruption
Jun 21, 2026 Jun 21, 2026
Jun 21, 2026
Jun 21, 2026
6.3 MEDIUM
CVE-2026-56367 — ImageMagick - Heap Out-of-Bounds Read in PSB RLE Decoding

ImageMagick before 7.1.2-15 and 6.9.x before 6.9.13-40 contains an integer overflow in the PSB (PSD v2) RLE decoding path (ReadPSDChannelRLE in coders/psd.c) that causes a heap out-of-bounds read on …

imagemagick | Remote | Memory Corruption
Jun 21, 2026 Jun 21, 2026
Jun 21, 2026
Jun 21, 2026
6.9 MEDIUM
CVE-2026-56316 — Cap-go - Job Existence Oracle via Unauthenticated OPTIONS /build/upload/:jobId/*

Cap-go before 12.128.2 contains an information disclosure vulnerability in the OPTIONS /build/upload/:jobId/* endpoint that allows unauthenticated attackers to enumerate valid builder job IDs through…

Remote | Information Disclosure
Jun 21, 2026 Jun 21, 2026
Jun 21, 2026
Jun 21, 2026
6.9 MEDIUM
CVE-2026-56299 — Capgo - Denial of Service via Unauthenticated OPTIONS Request to /build/upload Endpoint

Capgo before 12.128.2 contains an authentication bypass vulnerability in the /build/upload/:jobId/* endpoint that allows unauthenticated attackers to trigger consistent 500 errors. Remote attackers c…

Remote | Authentication
Jun 21, 2026 Jun 21, 2026
Jun 21, 2026
Jun 21, 2026
9.8 CRITICAL
CVE-2026-56265 — Crawl4AI - Authentication Bypass via Hardcoded JWT Signing Key

Crawl4AI before 0.8.7 contains an authentication bypass vulnerability due to a hardcoded default JWT signing key in the Docker API server. Attackers who know the default key can forge valid authentic…

Remote | Authentication
Jun 21, 2026 Jun 21, 2026
Jun 21, 2026
Jun 21, 2026
8.7 HIGH
CVE-2026-56253 — Capgo - Unauthenticated Organization Member Email Disclosure via get_org_members RPC

Capgo before 12.128.2 contains an improper access control vulnerability in the public.get_org_members RPC function that allows unauthenticated attackers to enumerate organization members. Attackers c…

Remote | Authorization
Jun 21, 2026 Jun 21, 2026
Jun 21, 2026
Jun 21, 2026
7.0 HIGH
CVE-2026-56251 — Capgo - Privilege Escalation via Broken Row Level Security in org_users

Capgo before 12.128.2 contains a broken row level security policy in the org_users table that allows authenticated users to elevate privileges from admin to super_admin. Attackers can exploit the ins…

Remote | Authorization
Jun 21, 2026 Jun 21, 2026
Jun 21, 2026
Jun 21, 2026
Showing 20 of 7359 Results