Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.3 MEDIUM
CVE-2026-7261 — SoapServer session-persisted object use-after-free via SOAP header fault

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, when SoapServer is configured with SOAP_PERSISTENCE_SESSION, the handler object is persisted acr…

Remote | Memory Corruption
May 10, 2026 May 10, 2026
May 10, 2026
May 10, 2026
2.1 LOW
CVE-2026-7259 — Null pointer dereference in php_mb_check_encoding() via mb_ereg_search_init()

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, a mismatch between encoding lists in Oniguruma and mbfl leads to  a NULL pointer dereference, re…

Remote | Denial of Service
May 10, 2026 May 10, 2026
May 10, 2026
May 10, 2026
6.3 MEDIUM
CVE-2026-7258 — Out-of-bounds read in urldecode() on NetBSD

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, some functions, including urldecode(), pass signed char to ctype functions (like isxdigit()). On…

Remote | Denial of Service
May 10, 2026 May 10, 2026
May 10, 2026
May 10, 2026
7.3 HIGH
CVE-2026-6735 — XSS within PHP-FPM status endpoint

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, 8.5.* before 8.5.6, due to improper sanitation of user data, it allows an attacker to compose an URL, which will cause t…

Remote | Cross-Site Scripting
May 10, 2026 May 10, 2026
May 10, 2026
May 10, 2026
9.5 CRITICAL
CVE-2026-6722 — Use-After-Free in SOAP using Apache map

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the SOAP extension's object deduplication mechanism stores pointers to PHP objects in a global m…

Remote | Memory Corruption
May 10, 2026 May 10, 2026
May 10, 2026
May 10, 2026
7.4 HIGH
CVE-2025-14179 — SQL injection in pdo_firebird via NUL bytes in quoted strings

In PHP versions 8.2.* before 8.2.31, 8.3.* before 8.3.31, 8.4.* before 8.4.21, and 8.5.* before 8.5.6, the PDO Firebird driver improperly handles NUL bytes when preparing SQL queries. During token-by…

Remote | Injection
May 10, 2026 May 10, 2026
May 10, 2026
May 10, 2026
5.5 MEDIUM
CVE-2026-8224 — Open5GS PCF context.c pcf_sess_set_ipv6prefix denial of service

A vulnerability was determined in Open5GS up to 2.7.7. Affected by this issue is the function pcf_sess_set_ipv6prefix of the file /src/pcf/context.c of the component PCF. Executing a manipulation of …

Remote | Denial of Service
May 10, 2026 May 10, 2026
May 10, 2026
May 10, 2026
5.5 MEDIUM
CVE-2026-8223 — Open5GS sm-policies Endpoint pcf_sess_sbi_discover_and_send denial of service

A vulnerability was found in Open5GS up to 2.7.7. Affected by this vulnerability is the function pcf_sess_sbi_discover_and_send of the component sm-policies Endpoint. Performing a manipulation result…

Remote | Denial of Service
May 10, 2026 May 10, 2026
May 10, 2026
May 10, 2026
5.5 MEDIUM
CVE-2026-8222 — Open5GS sm-policies Endpoint nbsf-handler.c pcf_nbsf_management_handle_register denial of…

A vulnerability has been found in Open5GS up to 2.7.7. Affected is the function pcf_nbsf_management_handle_register of the file src/pcf/nbsf-handler.c of the component sm-policies Endpoint. Such mani…

Remote | Denial of Service
May 10, 2026 May 10, 2026
May 10, 2026
May 10, 2026
3.3 LOW
CVE-2026-8221 — Devs Palace ERP Online item-save cross site scripting

A flaw has been found in Devs Palace ERP Online up to 4.0.0. This impacts an unknown function of the file /inventory/item-save. This manipulation causes cross site scripting. The attack is possible t…

Remote | Cross-Site Scripting
May 10, 2026 May 10, 2026
May 10, 2026
May 10, 2026
3.3 LOW
CVE-2026-8220 — Devs Palace ERP Online customer-save cross site scripting

A vulnerability was detected in Devs Palace ERP Online up to 4.0.0. This affects an unknown function of the file /inventory/customer-save. The manipulation results in cross site scripting. The attack…

Remote | Cross-Site Scripting
May 10, 2026 May 10, 2026
May 10, 2026
May 10, 2026
3.3 LOW
CVE-2026-8219 — Devs Palace ERP Online supplier-save cross site scripting

A security vulnerability has been detected in Devs Palace ERP Online up to 4.0.0. The impacted element is an unknown function of the file /inventory/supplier-save. The manipulation leads to cross sit…

Remote | Cross-Site Scripting
May 10, 2026 May 10, 2026
May 10, 2026
May 10, 2026
3.3 LOW
CVE-2026-8218 — Devs Palace ERP Online purchase_return_save cross site scripting

A weakness has been identified in Devs Palace ERP Online up to 4.0.0. The affected element is an unknown function of the file /inventory/purchase_return_save. Executing a manipulation can lead to cro…

Remote | Cross-Site Scripting
May 10, 2026 May 10, 2026
May 10, 2026
May 10, 2026
6.5 MEDIUM
CVE-2026-8217 — Industrial Application Software IAS Canias ERP RMI Runtime.getRuntime.exec os command inj…

A security flaw has been discovered in Industrial Application Software IAS Canias ERP 8.03. Impacted is the function Runtime.getRuntime.exec of the component RMI Interface. Performing a manipulation …

Remote | Injection
May 10, 2026 May 10, 2026
May 10, 2026
May 10, 2026
7.5 HIGH
CVE-2026-8216 — Industrial Application Software IAS Canias ERP Java RMI Session Management iasServerRemot…

A vulnerability was identified in Industrial Application Software IAS Canias ERP 8.03. This issue affects the function iasServerRemoteInterface.doAction of the component Java RMI Session Management. …

Remote | Authentication
May 10, 2026 May 10, 2026
May 10, 2026
May 10, 2026
5.5 MEDIUM
CVE-2026-8215 — Industrial Application Software IAS Canias ERP RMI iasRequestFileEvent path traversal

A vulnerability was determined in Industrial Application Software IAS Canias ERP 8.03. This vulnerability affects the function iasRequestFileEvent of the component RMI Interface. This manipulation of…

Remote | Path Traversal
May 10, 2026 May 10, 2026
May 10, 2026
May 10, 2026
5.5 MEDIUM
CVE-2026-8214 — Industrial Application Software IAS Canias ERP RMI doAction improper authentication

A vulnerability was found in Industrial Application Software IAS Canias ERP 8.03. This affects the function doAction of the component RMI Interface. The manipulation of the argument sessionId results…

Remote | Authentication
May 10, 2026 May 10, 2026
May 10, 2026
May 10, 2026
5.3 MEDIUM
CVE-2026-8213 — OSGeo gdal Grid File GDapi.c GDSDfldsrch heap-based overflow

A vulnerability has been found in OSGeo gdal up to 3.13.0dev-4. Affected by this issue is the function GDSDfldsrch of the file frmts/hdf4/hdf-eos/GDapi.c of the component Grid File Handler. The manip…

gdal | Memory Corruption
May 09, 2026 May 09, 2026
May 09, 2026
May 09, 2026
5.3 MEDIUM
CVE-2026-8212 — OSGeo gdal SWapi.c SWSDfldsrch heap-based overflow

A flaw has been found in OSGeo gdal up to 3.13.0dev-4. Affected by this vulnerability is the function SWSDfldsrch of the file frmts/hdf4/hdf-eos/SWapi.c. Executing a manipulation can lead to heap-bas…

gdal | Memory Corruption
May 09, 2026 May 09, 2026
May 09, 2026
May 09, 2026
5.8 MEDIUM
CVE-2026-8211 — codelibs Fess JSP File AdminDesignAction.java update code injection

A vulnerability was detected in codelibs Fess up to 15.5.1. Affected by this issue is the function update of the file org/codelibs/fess/app/web/admin/design/AdminDesignAction.java of the component JS…

fess | Remote | Injection
May 09, 2026 May 09, 2026
May 09, 2026
May 09, 2026
Showing 20 of 5551 Results