Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.8 HIGH
CVE-2022-49042 — Synology Hyper Backup Explorer: Local Code Execution via Untrusted Control Sphere Inclusi…

An inclusion of functionality from untrusted control sphere vulnerability in MinGW DLL component in Synology Hyper Backup Explorer before 3.0.1-0156 allows local users to execute arbitrary code via u…

| Supply Chain
Jun 03, 2026 Jun 04, 2026
Jun 03, 2026
Jun 04, 2026
7.8 HIGH
CVE-2022-49036 — Synology Active Backup for Business Recovery Media Creator Arbitrary Code Execution

An inclusion of functionality from untrusted control sphere vulnerability in OpenSSL configuration in Synology Active Backup for Business Recovery Media Creator before 2.5.0-2081 allows local users t…

| Misconfiguration
Jun 03, 2026 Jun 04, 2026
Jun 03, 2026
Jun 04, 2026
8.8 HIGH
CVE-2026-35085 — Stack buffer overflow in method gdv-serverconfig

A remote attacker with user privileges can exploit a stack buffer overflow in gdv-serverconfig to gain full system access as root.

Jun 03, 2026 Jun 04, 2026
Jun 03, 2026
Jun 04, 2026
8.8 HIGH
CVE-2026-35084 — Stack buffer overflow in method dali-devconfig

A remote attacker with user privileges can exploit a stack buffer overflow in dali-devconfig to gain full system access as root.

Jun 03, 2026 Jun 04, 2026
Jun 03, 2026
Jun 04, 2026
8.8 HIGH
CVE-2026-35083 — Stack buffer overflow in method bac-deviceobject

A remote attacker with user privileges can exploit a stack buffer overflow to gain full system access as root.

Jun 03, 2026 Jun 04, 2026
Jun 03, 2026
Jun 04, 2026
8.8 HIGH
CVE-2026-35082 — Local file inclusion vulnerability and deletion in ugw-logread method

The ugw-logread method allows a remote attacker with user privileges to access arbitrary local files due to insufficient validation of user-supplied input.

Jun 03, 2026 Jun 04, 2026
Jun 03, 2026
Jun 04, 2026
8.1 HIGH
CVE-2026-35081 — Arbitrary process termination vulnerability in method ugw-logstop

The ugw-logstop method allows a remote attacker with user privileges to terminate arbitrary processes due to insufficient validation of user-supplied input.

Jun 03, 2026 Jun 04, 2026
Jun 03, 2026
Jun 04, 2026
8.1 HIGH
CVE-2026-35080 — Arbitrary file delete vulnerability in method ugw-restoreinfo

The ugw-restoreinfo method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input.

Jun 03, 2026 Jun 04, 2026
Jun 03, 2026
Jun 04, 2026
8.1 HIGH
CVE-2026-35079 — Arbitrary file delete vulnerability in method ugw-restore

The ugw-restore method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input.

Jun 03, 2026 Jun 04, 2026
Jun 03, 2026
Jun 04, 2026
8.1 HIGH
CVE-2026-35078 — Arbitrary file delete vulnerability in method ugw-logstop

The ugw-logstop method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input.

Jun 03, 2026 Jun 04, 2026
Jun 03, 2026
Jun 04, 2026
8.1 HIGH
CVE-2026-35077 — Arbitrary file delete vulnerability in method ugw-delete-file

The ugw-delete-file method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input.

Jun 03, 2026 Jun 04, 2026
Jun 03, 2026
Jun 04, 2026
8.1 HIGH
CVE-2026-35076 — Arbitrary file delete vulnerability in method bac-scanresult

The bac-scanresult method allows a remote attacker with user privileges to delete arbitrary local files due to insufficient validation of user-controlled input.

Jun 03, 2026 Jun 04, 2026
Jun 03, 2026
Jun 04, 2026
9.8 CRITICAL
CVE-2026-35075 — Hardcoded default Password for Service Account

An unauthenticated remote attacker can recover a default, hard coded password from a firmware image and thus gain full access to all affected devices.

Jun 03, 2026 Jun 04, 2026
Jun 03, 2026
Jun 04, 2026
3.3 LOW
CVE-2026-10722 — cilium ebpf LoadCollectionSpec/LoadCollectionSpecFromReader btf.go loadRawSpec integer ov…

A vulnerability has been found in cilium ebpf up to 0.21.0. This affects the function loadRawSpec of the file btf/btf.go of the component LoadCollectionSpec/LoadCollectionSpecFromReader. Such manipul…

ebpf | Memory Corruption
Jun 03, 2026 Jun 04, 2026
Jun 03, 2026
Jun 04, 2026
7.3 HIGH
CVE-2025-41259 — SWUpdate Untrusted Script Execution via Signed Update TOCTOU

SWUpdate before 2026.05 is affected by a time-of-check time-of-use (TOCTOU) race condition that allows local unprivileged attackers to escalate privileges to root or install untrusted contents using …

| Race Condition
Jun 03, 2026 Jun 04, 2026
Jun 03, 2026
Jun 04, 2026
9.8 CRITICAL
CVE-2026-47065 — Apache MINA: Critical Deserialization Allow-list Bypass via resolveProxyClass - ZDRES-232

ZDRES-232: resolveProxyClass Not Overridden - acceptMatchers Filter Bypass via java.lang.reflect.Proxy Assessment: Fully addressed. When the serialised stream contains a TC_PROXYCLASSDESC (the ma…

mina | Remote | Authentication
Jun 03, 2026 Jun 04, 2026
Jun 03, 2026
Jun 04, 2026
7.5 HIGH
CVE-2026-41032 — Phoenix Contact: Unauthenticated log download vulnerability in the firmware of CHARX SEC-…

It is possible for an unauthenticated adjacent attacker to download log files of the controller, which may disclose some restricted information.

Jun 03, 2026 Jun 04, 2026
Jun 03, 2026
Jun 04, 2026
8.8 HIGH
CVE-2025-15656 — WordPress School Management plugin <= 93.2.0 - Privilege Escalation vulnerability

Incorrect Privilege Assignment vulnerability in Mojoomla School Management allows Privilege Escalation. This issue affects School Management: from n/a through 93.2.0.

Remote | Authorization
Jun 03, 2026 Jun 04, 2026
Jun 03, 2026
Jun 04, 2026
7.6 HIGH
CVE-2025-15655 — WordPress School Management plugin <= 93.2.0 - SQL Injection vulnerability

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mojoomla School Management allows SQL Injection. This issue affects School Management: from n/a …

Remote | Injection
Jun 03, 2026 Jun 04, 2026
Jun 03, 2026
Jun 04, 2026
7.4 HIGH
CVE-2025-14774 — Communication analysis between the Card Reader and TP2CardReaderService daemon

Incorrect Authorization vulnerability in ABB T-MAC Plus. This issue affects T-MAC Plus: 4.0-24.

| Authorization
Jun 03, 2026 Jun 04, 2026
Jun 03, 2026
Jun 04, 2026
Showing 20 of 7151 Results