Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.5 HIGH
CVE-2026-13521 — SourceCodester Class and Exam Timetabling System preview5.php sql injection

A vulnerability was identified in SourceCodester Class and Exam Timetabling System 1.0/5.php. Affected by this vulnerability is an unknown functionality of the file /preview5.php. Such manipulation o…

class_and_exam_timetabling_system | Remote | Injection
Jun 29, 2026 Jun 29, 2026
Jun 29, 2026
Jun 29, 2026
6.5 MEDIUM
CVE-2026-13520 — itsourcecode Hospital Management System Appointment appointmentapproval.php sql injection

A vulnerability was determined in itsourcecode Hospital Management System 1.0. Affected is an unknown function of the file /appointmentapproval.php of the component Appointment Handler. This manipula…

hospital_management_system | Remote | Injection
Jun 29, 2026 Jun 29, 2026
Jun 29, 2026
Jun 29, 2026
9.0 HIGH
CVE-2026-13519 — Tenda JD12L NatStaticSetting fromNatStaticSetting stack-based overflow

A vulnerability was found in Tenda JD12L 16.03.53.23. This impacts the function fromNatStaticSetting of the file /goform/NatStaticSetting. The manipulation of the argument page results in stack-based…

Remote | Memory Corruption
Jun 29, 2026 Jun 29, 2026
Jun 29, 2026
Jun 29, 2026
9.0 HIGH
CVE-2026-13518 — Tenda JD12L addressNat fromAddressNat stack-based overflow

A vulnerability has been found in Tenda JD12L 16.03.53.23. This affects the function fromAddressNat of the file /goform/addressNat. The manipulation of the argument page leads to stack-based buffer o…

Remote | Memory Corruption
Jun 29, 2026 Jun 29, 2026
Jun 29, 2026
Jun 29, 2026
9.0 HIGH
CVE-2026-13517 — Tenda JD12L WifiBasicSet formWifiBasicSet stack-based overflow

A flaw has been found in Tenda JD12L 16.03.53.23. The impacted element is the function formWifiBasicSet of the file /goform/WifiBasicSet. Executing a manipulation of the argument security_5g can lead…

Remote | Memory Corruption
Jun 29, 2026 Jun 29, 2026
Jun 29, 2026
Jun 29, 2026
9.0 HIGH
CVE-2026-13516 — Tenda JD12L WifiGuestSet fromSetWifiGusetBasic stack-based overflow

A vulnerability was detected in Tenda JD12L 16.03.53.23. The affected element is the function fromSetWifiGusetBasic of the file /goform/WifiGuestSet. Performing a manipulation of the argument shareSp…

Remote | Memory Corruption
Jun 28, 2026 Jun 28, 2026
Jun 28, 2026
Jun 28, 2026
9.0 HIGH
CVE-2026-13515 — Tenda JD12L SetPptpServerCfg formSetPPTPServer stack-based overflow

A security vulnerability has been detected in Tenda JD12L 16.03.53.23. Impacted is the function formSetPPTPServer of the file /goform/SetPptpServerCfg. Such manipulation of the argument startIp leads…

Remote | Memory Corruption
Jun 28, 2026 Jun 28, 2026
Jun 28, 2026
Jun 28, 2026
2.4 LOW
CVE-2026-13514 — Chess Play and Learn App com.chess AndroidManifest.xml backup

A weakness has been identified in Chess Play and Learn App up to 4.9.42 on Android. This issue affects some unknown processing of the file AndroidManifest.xml of the component com.chess. This manipul…

play_and_learn_app | Information Disclosure
Jun 28, 2026 Jun 28, 2026
Jun 28, 2026
Jun 28, 2026
5.0 MEDIUM
CVE-2026-13513 — MyScale MyScaleDB SegmentId.h getCacheKey data authenticity

A security flaw has been discovered in MyScale MyScaleDB up to 1.8.0. This vulnerability affects the function SegmentId::getCacheKey in the library src/VectorIndex/Common/SegmentId.h. The manipulatio…

myscaledb | Remote | Misconfiguration
Jun 28, 2026 Jun 28, 2026
Jun 28, 2026
Jun 28, 2026
6.5 MEDIUM
CVE-2026-13512 — Databend Tenant client_session_manager.rs state_key authorization

A vulnerability was identified in Databend up to 1.2.881 on HTTP. This affects the function ClientSessionManager::state_key of the file src/query/service/src/servers/http/v1/session/client_session_ma…

databend | Remote | Authorization
Jun 28, 2026 Jun 28, 2026
Jun 28, 2026
Jun 28, 2026
3.1 LOW
CVE-2026-13511 — VoltAgent Memory REST API memory.handlers.ts handleGetMemoryConversation improper authori…

A vulnerability was determined in VoltAgent up to 2.1.17. Affected by this issue is the function handleGetMemoryConversation of the file packages/server-core/src/handlers/memory.handlers.ts of the co…

voltagent | Remote | Authorization
Jun 28, 2026 Jun 28, 2026
Jun 28, 2026
Jun 28, 2026
3.7 LOW
CVE-2026-13510 — SimStudioAI sim Password Protection deployment.ts weak hash

A vulnerability was found in SimStudioAI sim up to 0.6.92. Affected by this vulnerability is an unknown functionality in the library apps/sim/lib/core/security/deployment.ts of the component Password…

sim | Remote | Cryptography
Jun 28, 2026 Jun 28, 2026
Jun 28, 2026
Jun 28, 2026
6.5 MEDIUM
CVE-2026-13509 — RAGapp Knowledge File files.py FileHandler.remove_file path traversal

A vulnerability has been found in RAGapp up to 0.1.5. Affected is the function FileHandler.upload_file/FileHandler.remove_file of the file src/ragapp/backend/controllers/files.py of the component Kno…

ragapp | Remote | Path Traversal
Jun 28, 2026 Jun 28, 2026
Jun 28, 2026
Jun 28, 2026
6.5 MEDIUM
CVE-2026-13508 — khoj-ai khoj Conversation Sharing api_chat.py authorization

A flaw has been found in khoj-ai khoj up to 2.0.0-beta.28. This impacts an unknown function of the file src/khoj/routers/api_chat.py of the component Conversation Sharing Handler. This manipulation o…

khoj | Remote | Authorization
Jun 28, 2026 Jun 28, 2026
Jun 28, 2026
Jun 28, 2026
5.0 MEDIUM
CVE-2026-13507 — volcengine OpenViking Local VectorDB Primary-key Label str_to_uint64.py str_to_uint64 dat…

A vulnerability was detected in volcengine OpenViking up to 0.3.21. This affects the function str_to_uint64 of the file openviking/storage/vectordb/utils/str_to_uint64.py of the component Local Vecto…

openviking | Remote | Injection
Jun 28, 2026 Jun 28, 2026
Jun 28, 2026
Jun 28, 2026
0.0 NA
CVE-2026-49048 — Joomla Extension - joomcoder.com - Unauthenticated SQL Injection in JoomCCK extension for…

The Joomla extension JoomCCK exposes a front-end controller task, that builds two SQL statements by directly concatenating a user-supplied request parameter into the query string without escaping or …

| Injection
Jun 28, 2026 Jun 28, 2026
Jun 28, 2026
Jun 28, 2026
4.0 MEDIUM
CVE-2026-13504 — code-projects Project Management System Mail Compose mail.php cross site scripting

A vulnerability has been found in code-projects Project Management System 1.0. This vulnerability affects unknown code of the file /mail.php of the component Mail Compose Page. Such manipulation lead…

project_management_system | Remote | Cross-Site Scripting
Jun 28, 2026 Jun 28, 2026
Jun 28, 2026
Jun 28, 2026
5.5 MEDIUM
CVE-2026-13503 — antlr ANTLR4 tokenVocab Grammar Option TokenVocabParser.java getImportedVocabFile path tr…

A vulnerability was detected in antlr ANTLR4 up to 4.13.2. Affected by this issue is the function getImportedVocabFile of the file tool/src/org/antlr/v4/parse/TokenVocabParser.java of the component t…

antlr4 | Remote | Path Traversal
Jun 28, 2026 Jun 28, 2026
Jun 28, 2026
Jun 28, 2026
4.5 MEDIUM
CVE-2026-13502 — antlr ANTLR4 Maven Plugin GrammarDependencies.java ObjectInputStream.readObject toctou

A flaw has been found in antlr ANTLR4 up to 4.13.2. This affects the function ObjectInputStream.readObject of the file antlr4-maven-plugin/src/main/java/org/antlr/mojo/antlr4/GrammarDependencies.java…

antlr4 | Race Condition
Jun 28, 2026 Jun 28, 2026
Jun 28, 2026
Jun 28, 2026
5.3 MEDIUM
CVE-2026-13501 — antlr ANTLR4 gofmt GoTarget.java GoTarget command injection

A security vulnerability has been detected in antlr ANTLR4 up to 4.13.2. Affected by this vulnerability is the function GoTarget of the file tool/src/org/antlr/v4/codegen/target/GoTarget.java of the …

antlr4 | Injection
Jun 28, 2026 Jun 28, 2026
Jun 28, 2026
Jun 28, 2026
Showing 20 of 7234 Results