Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.0 HIGH
CVE-2026-13517 — Tenda JD12L WifiBasicSet formWifiBasicSet stack-based overflow

A flaw has been found in Tenda JD12L 16.03.53.23. The impacted element is the function formWifiBasicSet of the file /goform/WifiBasicSet. Executing a manipulation of the argument security_5g can lead…

Remote | Memory Corruption
Jun 29, 2026 Jun 29, 2026
Jun 29, 2026
Jun 29, 2026
7.5 HIGH
CVE-2026-36848 — Gigamon GVOS H-VUE Directory Traversal

Gigamon GVOS v5.16.1 and below is vulnerable to Directory Traversal in the GVOS H-VUE subsystem.

Remote | Path Traversal
Jun 29, 2026 Jun 29, 2026
Jun 29, 2026
Jun 29, 2026
0.0 NA
CVE-2026-51219 — lib60870 Heap Buffer Overflow

A heap buffer overflow in the HighPriorityASDUQueue_hasUnconfirmedIMessages function of lib60870 v2.3.3 to v2.3.6 allows attackers to cause a Denial of Service (DoS) via a crafted payload.

| Memory Corruption
Jun 29, 2026 Jun 29, 2026
Jun 29, 2026
Jun 29, 2026
0.0 NA
CVE-2026-51218 — Snap7 Heap Buffer Overflow

A heap buffer overflow in the TS7Worker::PerformFunctionWrite() function (/core/s7_server.cpp) of snap7 v1.4.3 allows attackers to cause a Denial of Service (DoS) via a crafted packet.

| Memory Corruption
Jun 29, 2026 Jun 29, 2026
Jun 29, 2026
Jun 29, 2026
0.0 NA
CVE-2026-51221 — EIPStackGroup OpENer: Buffer Overflow Denial of Service

A buffer overflow in the Get_Attribute_List function of EIPStackGroup OpENer commit 76b95c allows attackers to cause a Denial of Service (DoS) via supplying a crafted Common Packet Format (CPF) packe…

| Memory Corruption
Jun 29, 2026 Jun 29, 2026
Jun 29, 2026
Jun 29, 2026
9.1 CRITICAL
CVE-2026-37637 — Alexantr Filemanager Arbitrary Code Execution

An issue in Alexantr filemanager v.1.0 allows a remote attacker to execute arbitrary code via the filemanager.php component

Remote | Injection
Jun 29, 2026 Jun 29, 2026
Jun 29, 2026
Jun 29, 2026
7.8 HIGH
CVE-2026-57919 — Matrix42 Empirum SYSTEM Privilege Escalation via Named Pipe Manipulation

PBackupVSS.exe in Matrix42 Empirum before 25.5 and 26.x before 26.2 creates a named pipe (\\.\pipe\PBackupVSS) with a DACL that grants GENERIC_READ and GENERIC_WRITE permissions to all authenticated …

| Misconfiguration
Jun 29, 2026 Jun 29, 2026
Jun 29, 2026
Jun 29, 2026
6.5 MEDIUM
CVE-2026-31016 — Squidex.io Squidex CMS: Cross-Site Request Forgery (CSRF) leading to Privilege Escalation

Cross Site Request Forgery vulnerability in Squidex.io Squidex CMS v.7.21.0 and before allows a remote attacker to escalate privileges via the IdentityServer account profile endpoint

Remote | Cross-Site Request Forgery
Jun 29, 2026 Jun 29, 2026
Jun 29, 2026
Jun 29, 2026
9.0 HIGH
CVE-2026-13516 — Tenda JD12L WifiGuestSet fromSetWifiGusetBasic stack-based overflow

A vulnerability was detected in Tenda JD12L 16.03.53.23. The affected element is the function fromSetWifiGusetBasic of the file /goform/WifiGuestSet. Performing a manipulation of the argument shareSp…

Remote | Memory Corruption
Jun 28, 2026 Jun 28, 2026
Jun 28, 2026
Jun 28, 2026
9.0 HIGH
CVE-2026-13515 — Tenda JD12L SetPptpServerCfg formSetPPTPServer stack-based overflow

A security vulnerability has been detected in Tenda JD12L 16.03.53.23. Impacted is the function formSetPPTPServer of the file /goform/SetPptpServerCfg. Such manipulation of the argument startIp leads…

Remote | Memory Corruption
Jun 28, 2026 Jun 28, 2026
Jun 28, 2026
Jun 28, 2026
2.4 LOW
CVE-2026-13514 — Chess Play and Learn App com.chess AndroidManifest.xml backup

A weakness has been identified in Chess Play and Learn App up to 4.9.42 on Android. This issue affects some unknown processing of the file AndroidManifest.xml of the component com.chess. This manipul…

play_and_learn_app | Information Disclosure
Jun 28, 2026 Jun 28, 2026
Jun 28, 2026
Jun 28, 2026
5.0 MEDIUM
CVE-2026-13513 — MyScale MyScaleDB SegmentId.h getCacheKey data authenticity

A security flaw has been discovered in MyScale MyScaleDB up to 1.8.0. This vulnerability affects the function SegmentId::getCacheKey in the library src/VectorIndex/Common/SegmentId.h. The manipulatio…

myscaledb | Remote | Misconfiguration
Jun 28, 2026 Jun 28, 2026
Jun 28, 2026
Jun 28, 2026
6.5 MEDIUM
CVE-2026-13512 — Databend Tenant client_session_manager.rs state_key authorization

A vulnerability was identified in Databend up to 1.2.881 on HTTP. This affects the function ClientSessionManager::state_key of the file src/query/service/src/servers/http/v1/session/client_session_ma…

databend | Remote | Authorization
Jun 28, 2026 Jun 28, 2026
Jun 28, 2026
Jun 28, 2026
3.1 LOW
CVE-2026-13511 — VoltAgent Memory REST API memory.handlers.ts handleGetMemoryConversation improper authori…

A vulnerability was determined in VoltAgent up to 2.1.17. Affected by this issue is the function handleGetMemoryConversation of the file packages/server-core/src/handlers/memory.handlers.ts of the co…

voltagent | Remote | Authorization
Jun 28, 2026 Jun 28, 2026
Jun 28, 2026
Jun 28, 2026
3.7 LOW
CVE-2026-13510 — SimStudioAI sim Password Protection deployment.ts weak hash

A vulnerability was found in SimStudioAI sim up to 0.6.92. Affected by this vulnerability is an unknown functionality in the library apps/sim/lib/core/security/deployment.ts of the component Password…

sim | Remote | Cryptography
Jun 28, 2026 Jun 28, 2026
Jun 28, 2026
Jun 28, 2026
6.5 MEDIUM
CVE-2026-13509 — RAGapp Knowledge File files.py FileHandler.remove_file path traversal

A vulnerability has been found in RAGapp up to 0.1.5. Affected is the function FileHandler.upload_file/FileHandler.remove_file of the file src/ragapp/backend/controllers/files.py of the component Kno…

ragapp | Remote | Path Traversal
Jun 28, 2026 Jun 28, 2026
Jun 28, 2026
Jun 28, 2026
6.5 MEDIUM
CVE-2026-13508 — khoj-ai khoj Conversation Sharing api_chat.py authorization

A flaw has been found in khoj-ai khoj up to 2.0.0-beta.28. This impacts an unknown function of the file src/khoj/routers/api_chat.py of the component Conversation Sharing Handler. This manipulation o…

khoj | Remote | Authorization
Jun 28, 2026 Jun 28, 2026
Jun 28, 2026
Jun 28, 2026
5.0 MEDIUM
CVE-2026-13507 — volcengine OpenViking Local VectorDB Primary-key Label str_to_uint64.py str_to_uint64 dat…

A vulnerability was detected in volcengine OpenViking up to 0.3.21. This affects the function str_to_uint64 of the file openviking/storage/vectordb/utils/str_to_uint64.py of the component Local Vecto…

openviking | Remote | Injection
Jun 28, 2026 Jun 28, 2026
Jun 28, 2026
Jun 28, 2026
9.8 CRITICAL
CVE-2026-49048 — Joomla Extension - joomcoder.com - Unauthenticated SQL Injection in JoomCCK extension for…

The Joomla extension JoomCCK exposes a front-end controller task, that builds two SQL statements by directly concatenating a user-supplied request parameter into the query string without escaping or …

Remote | Injection
Jun 28, 2026 Jun 28, 2026
Jun 28, 2026
Jun 28, 2026
4.0 MEDIUM
CVE-2026-13504 — code-projects Project Management System Mail Compose mail.php cross site scripting

A vulnerability has been found in code-projects Project Management System 1.0. This vulnerability affects unknown code of the file /mail.php of the component Mail Compose Page. Such manipulation lead…

project_management_system | Remote | Cross-Site Scripting
Jun 28, 2026 Jun 28, 2026
Jun 28, 2026
Jun 28, 2026
Showing 20 of 7380 Results