Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.0 HIGH
CVE-2026-13516 — Tenda JD12L WifiGuestSet fromSetWifiGusetBasic stack-based overflow

A vulnerability was detected in Tenda JD12L 16.03.53.23. The affected element is the function fromSetWifiGusetBasic of the file /goform/WifiGuestSet. Performing a manipulation of the argument shareSp…

Remote | Memory Corruption
Jun 28, 2026 Jun 28, 2026
Jun 28, 2026
Jun 28, 2026
9.0 HIGH
CVE-2026-13515 — Tenda JD12L SetPptpServerCfg formSetPPTPServer stack-based overflow

A security vulnerability has been detected in Tenda JD12L 16.03.53.23. Impacted is the function formSetPPTPServer of the file /goform/SetPptpServerCfg. Such manipulation of the argument startIp leads…

Remote | Memory Corruption
Jun 28, 2026 Jun 28, 2026
Jun 28, 2026
Jun 28, 2026
2.4 LOW
CVE-2026-13514 — Chess Play and Learn App com.chess AndroidManifest.xml backup

A weakness has been identified in Chess Play and Learn App up to 4.9.42 on Android. This issue affects some unknown processing of the file AndroidManifest.xml of the component com.chess. This manipul…

play_and_learn_app | Information Disclosure
Jun 28, 2026 Jun 28, 2026
Jun 28, 2026
Jun 28, 2026
5.0 MEDIUM
CVE-2026-13513 — MyScale MyScaleDB SegmentId.h getCacheKey data authenticity

A security flaw has been discovered in MyScale MyScaleDB up to 1.8.0. This vulnerability affects the function SegmentId::getCacheKey in the library src/VectorIndex/Common/SegmentId.h. The manipulatio…

myscaledb | Remote | Misconfiguration
Jun 28, 2026 Jun 28, 2026
Jun 28, 2026
Jun 28, 2026
6.5 MEDIUM
CVE-2026-13512 — Databend Tenant client_session_manager.rs state_key authorization

A vulnerability was identified in Databend up to 1.2.881 on HTTP. This affects the function ClientSessionManager::state_key of the file src/query/service/src/servers/http/v1/session/client_session_ma…

databend | Remote | Authorization
Jun 28, 2026 Jun 28, 2026
Jun 28, 2026
Jun 28, 2026
3.1 LOW
CVE-2026-13511 — VoltAgent Memory REST API memory.handlers.ts handleGetMemoryConversation improper authori…

A vulnerability was determined in VoltAgent up to 2.1.17. Affected by this issue is the function handleGetMemoryConversation of the file packages/server-core/src/handlers/memory.handlers.ts of the co…

voltagent | Remote | Authorization
Jun 28, 2026 Jun 28, 2026
Jun 28, 2026
Jun 28, 2026
3.7 LOW
CVE-2026-13510 — SimStudioAI sim Password Protection deployment.ts weak hash

A vulnerability was found in SimStudioAI sim up to 0.6.92. Affected by this vulnerability is an unknown functionality in the library apps/sim/lib/core/security/deployment.ts of the component Password…

sim | Remote | Cryptography
Jun 28, 2026 Jun 28, 2026
Jun 28, 2026
Jun 28, 2026
6.5 MEDIUM
CVE-2026-13509 — RAGapp Knowledge File files.py FileHandler.remove_file path traversal

A vulnerability has been found in RAGapp up to 0.1.5. Affected is the function FileHandler.upload_file/FileHandler.remove_file of the file src/ragapp/backend/controllers/files.py of the component Kno…

ragapp | Remote | Path Traversal
Jun 28, 2026 Jun 28, 2026
Jun 28, 2026
Jun 28, 2026
6.5 MEDIUM
CVE-2026-13508 — khoj-ai khoj Conversation Sharing api_chat.py authorization

A flaw has been found in khoj-ai khoj up to 2.0.0-beta.28. This impacts an unknown function of the file src/khoj/routers/api_chat.py of the component Conversation Sharing Handler. This manipulation o…

khoj | Remote | Authorization
Jun 28, 2026 Jun 28, 2026
Jun 28, 2026
Jun 28, 2026
5.0 MEDIUM
CVE-2026-13507 — volcengine OpenViking Local VectorDB Primary-key Label str_to_uint64.py str_to_uint64 dat…

A vulnerability was detected in volcengine OpenViking up to 0.3.21. This affects the function str_to_uint64 of the file openviking/storage/vectordb/utils/str_to_uint64.py of the component Local Vecto…

openviking | Remote | Injection
Jun 28, 2026 Jun 28, 2026
Jun 28, 2026
Jun 28, 2026
0.0 NA
CVE-2026-49048 — Joomla Extension - joomcoder.com - Unauthenticated SQL Injection in JoomCCK extension for…

The Joomla extension JoomCCK exposes a front-end controller task, that builds two SQL statements by directly concatenating a user-supplied request parameter into the query string without escaping or …

| Injection
Jun 28, 2026 Jun 28, 2026
Jun 28, 2026
Jun 28, 2026
4.0 MEDIUM
CVE-2026-13504 — code-projects Project Management System Mail Compose mail.php cross site scripting

A vulnerability has been found in code-projects Project Management System 1.0. This vulnerability affects unknown code of the file /mail.php of the component Mail Compose Page. Such manipulation lead…

project_management_system | Remote | Cross-Site Scripting
Jun 28, 2026 Jun 28, 2026
Jun 28, 2026
Jun 28, 2026
5.5 MEDIUM
CVE-2026-13503 — antlr ANTLR4 tokenVocab Grammar Option TokenVocabParser.java getImportedVocabFile path tr…

A vulnerability was detected in antlr ANTLR4 up to 4.13.2. Affected by this issue is the function getImportedVocabFile of the file tool/src/org/antlr/v4/parse/TokenVocabParser.java of the component t…

antlr4 | Remote | Path Traversal
Jun 28, 2026 Jun 28, 2026
Jun 28, 2026
Jun 28, 2026
4.5 MEDIUM
CVE-2026-13502 — antlr ANTLR4 Maven Plugin GrammarDependencies.java ObjectInputStream.readObject toctou

A flaw has been found in antlr ANTLR4 up to 4.13.2. This affects the function ObjectInputStream.readObject of the file antlr4-maven-plugin/src/main/java/org/antlr/mojo/antlr4/GrammarDependencies.java…

antlr4 | Race Condition
Jun 28, 2026 Jun 28, 2026
Jun 28, 2026
Jun 28, 2026
5.3 MEDIUM
CVE-2026-13501 — antlr ANTLR4 gofmt GoTarget.java GoTarget command injection

A security vulnerability has been detected in antlr ANTLR4 up to 4.13.2. Affected by this vulnerability is the function GoTarget of the file tool/src/org/antlr/v4/codegen/target/GoTarget.java of the …

antlr4 | Injection
Jun 28, 2026 Jun 28, 2026
Jun 28, 2026
Jun 28, 2026
7.5 HIGH
CVE-2026-13500 — antlr ANTLR4 Grammar Action Block OutputFile.java code injection

A weakness has been identified in antlr ANTLR4 up to 4.13.2. Affected is an unknown function of the file tool/src/org/antlr/v4/codegen/model/OutputFile.java of the component Grammar Action Block Hand…

antlr4 | Remote | Injection
Jun 28, 2026 Jun 28, 2026
Jun 28, 2026
Jun 28, 2026
5.0 MEDIUM
CVE-2026-13499 — yashpokharna2555 restaurent-management-system Registration login_register.php cross site …

A security flaw has been discovered in yashpokharna2555 restaurent-management-system. This impacts an unknown function of the file login_register.php of the component Registration Handler. Performing…

restaurent-management-system | Remote | Cross-Site Scripting
Jun 28, 2026 Jun 28, 2026
Jun 28, 2026
Jun 28, 2026
7.5 HIGH
CVE-2026-13498 — yashpokharna2555 restaurent-management-system POST Parameter forgotpassword.php sql injec…

A vulnerability was identified in yashpokharna2555 restaurent-management-system. This affects an unknown function of the file /forgotpassword.php of the component POST Parameter Handler. Such manipul…

restaurent-management-system | Remote | Injection
Jun 28, 2026 Jun 28, 2026
Jun 28, 2026
Jun 28, 2026
6.5 MEDIUM
CVE-2026-13497 — itsourcecode Hospital Management System appointment.php sql injection

A vulnerability was determined in itsourcecode Hospital Management System 1.0. The impacted element is an unknown function of the file /appointment.php. This manipulation of the argument editid cause…

hospital_management_system | Remote | Injection
Jun 28, 2026 Jun 28, 2026
Jun 28, 2026
Jun 28, 2026
6.5 MEDIUM
CVE-2026-13496 — itsourcecode Hospital Management System ajaxmedicine.php sql injection

A vulnerability was found in itsourcecode Hospital Management System 1.0. The affected element is an unknown function of the file /ajaxmedicine.php. The manipulation of the argument medicineid result…

hospital_management_system | Remote | Injection
Jun 28, 2026 Jun 28, 2026
Jun 28, 2026
Jun 28, 2026
Showing 20 of 7202 Results