Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.7 HIGH
CVE-2026-41011 — BOSH OS Command Injection

PackagePersister.validate_tgz builds "tar -tf #{tgz} 2>&1" where tgz = File.join(release_dir, 'packages', "#{name}.tgz") and name = package_meta['name'] comes directly from release.MF inside the uplo…

bosh | Injection
Jun 04, 2026 Jun 04, 2026
Jun 04, 2026
Jun 04, 2026
6.9 MEDIUM
CVE-2026-10597 — ITPison|OMICARD EDM - Insecure Direct Object Reference

OMICARD EDM developed by ITPison has a Insecure Direct Object Reference vulnerability, allowing unauthenticated remote attackers to modify a specific parameter to obtain user's email address.

omicard_edm | Remote | Authorization
Jun 04, 2026 Jun 04, 2026
Jun 04, 2026
Jun 04, 2026
6.5 MEDIUM
CVE-2026-8653 — MasterStudy LMS Pro Plus <= 4.8.20 - Authenticated (Instructor+) SQL Injection via 'colum…

The MasterStudy LMS Pro Plus plugin for WordPress is vulnerable to generic SQL Injection via the 'columns' parameter in all versions up to, and including, 4.8.20 due to insufficient escaping on the u…

Remote | Injection
Jun 04, 2026 Jun 04, 2026
Jun 04, 2026
Jun 04, 2026
6.8 MEDIUM
CVE-2026-7764 — Out-of-bounds read in morse.ko Vendor IE processing

An out-of-bounds read vulnerability in the morse.ko HaLow Wi-Fi kernel driver in Morse Micro HaLowLink 2 software versions prior to 2.11.12 allows an unauthenticated attacker within radio range to di…

halow_link_2 | Memory Corruption
Jun 04, 2026 Jun 04, 2026
Jun 04, 2026
Jun 04, 2026
7.5 HIGH
CVE-2026-10737 — SP Project & Document Manager <= 4.71 - Missing Authorization to Unauthenticated Arbitrar…

The SP Project & Document Manager plugin for WordPress is vulnerable to unauthorized access due to a missing capability check on the view_file function in all versions up to, and including, 4.71. Thi…

sp_project_\&_document_manager | Remote | Authorization
Jun 04, 2026 Jun 04, 2026
Jun 04, 2026
Jun 04, 2026
0.0 NA
CVE-2026-8722 — Net::Async::Statsd::Client versions through 0.005 for Perl allow metric injections

Net::Async::Statsd::Client versions through 0.005 for Perl allow metric injections. The metric names are not checked for newlines, colons or pipes. Metrics generated from untrusted sources could inj…

| Injection
Jun 04, 2026 Jun 04, 2026
Jun 04, 2026
Jun 04, 2026
2.5 LOW
CVE-2026-10783 — gradio-app gradio Audio Cache Key save_audio_to_cache weak hash

A security flaw has been discovered in gradio-app gradio 6.14.0. This affects the function save_audio_to_cache of the component Audio Cache Key Handler. Performing a manipulation results in use of we…

gradio | Cryptography
Jun 04, 2026 Jun 04, 2026
Jun 04, 2026
Jun 04, 2026
7.5 HIGH
CVE-2026-10777 — ealpha072 Student-Management-System Administrative Backend config.php improper authentica…

A vulnerability was identified in ealpha072 Student-Management-System up to 01451bd7a2f58cdda07bd0b86e3967582e3ecd08. Affected by this issue is some unknown functionality of the file admin/config.php…

student-management-system | Remote | Authentication
Jun 03, 2026 Jun 04, 2026
Jun 03, 2026
Jun 04, 2026
3.6 LOW
CVE-2026-10775 — sgl-project SGLang Cache data_hash denial of service

A vulnerability was determined in sgl-project SGLang up to 0.5.11. Affected by this vulnerability is the function data_hash of the component Cache Handler. This manipulation causes denial of service.…

sglang | Denial of Service
Jun 03, 2026 Jun 04, 2026
Jun 03, 2026
Jun 04, 2026
5.8 MEDIUM
CVE-2026-46447 — OpenStack Ironic Boot Script Injection

OpenStack Ironic before 35.0.2 allows Boot Script Injection of an iPXE script if the attacker can set node.driver_info or node.instance_info.

ironic | Remote | Injection
Jun 03, 2026 Jun 04, 2026
Jun 03, 2026
Jun 04, 2026
5.3 MEDIUM
CVE-2026-22055 — Active IQ OneCollect Hard-coded Credentials for AutoSupport Operations

Active IQ OneCollect version 2.7.3 contains hard-coded credentials that could allow an authenticated attacker with low privileges to perform unauthorized AutoSupport operations.

Remote | Authentication
Jun 03, 2026 Jun 04, 2026
Jun 03, 2026
Jun 04, 2026
5.3 MEDIUM
CVE-2026-22054 — Active IQ Config Advisor Hard-coded Credentials

Active IQ Config Advisor version 6.7.3 contains hard-coded credentials that could allow an authenticated attacker with low privileges to perform unauthorized AutoSupport operations.

Remote | Authentication
Jun 03, 2026 Jun 04, 2026
Jun 03, 2026
Jun 04, 2026
7.5 HIGH
CVE-2026-10771 — crmeb crmeb_java base64 Qrcode Endpoint RestTemplateUtil.java RestTemplate.getForEntity s…

A vulnerability was found in crmeb crmeb_java 1.4. Affected is the function RestTemplate.getForEntity of the file crmeb-common/src/main/java/com/zbkj/common/utils/RestTemplateUtil.java of the compone…

crmeb_java | Remote | Server-Side Request Forgery
Jun 03, 2026 Jun 04, 2026
Jun 03, 2026
Jun 04, 2026
7.3 HIGH
CVE-2026-50033 — Acronis DeviceLock DLP DLL Hijacking Privilege Escalation

Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis DeviceLock DLP (Windows) before build 9.0.15051.93227.

| Misconfiguration
Jun 03, 2026 Jun 04, 2026
Jun 03, 2026
Jun 04, 2026
7.3 HIGH
CVE-2026-44682 — Acronis DeviceLock DLP DLL Hijacking Local Privilege Escalation

Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis DeviceLock DLP (Windows) before build 9.0.15051.93227.

| Misconfiguration
Jun 03, 2026 Jun 04, 2026
Jun 03, 2026
Jun 04, 2026
7.3 HIGH
CVE-2026-44609 — Acronis DeviceLock DLP Privilege Escalation via EXE Hijacking

Local privilege escalation due to EXE hijacking vulnerability. The following products are affected: Acronis DeviceLock DLP (Windows) before build 9.0.15051.93227.

| Misconfiguration
Jun 03, 2026 Jun 04, 2026
Jun 03, 2026
Jun 04, 2026
4.8 MEDIUM
CVE-2026-43924 — FOSSBilling has an open redirect via administrator-configured redirect targets

FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, the Redirect module does not validate the URL scheme of administrator-configured destination URLs befo…

fossbilling | Remote | Misconfiguration
Jun 03, 2026 Jun 04, 2026
Jun 03, 2026
Jun 04, 2026
7.3 HIGH
CVE-2026-42061 — Acronis DeviceLock DLP Privilege Escalation

Local privilege escalation due to excessive permissions assigned to child processes. The following products are affected: Acronis DeviceLock DLP (Windows) before build 9.0.15051.93227.

| Authorization
Jun 03, 2026 Jun 04, 2026
Jun 03, 2026
Jun 04, 2026
6.9 MEDIUM
CVE-2026-40495 — FOSSBilling version exposed via asset cache buster

FOSSBilling is a free, open-source billing and client management system. Versions prior to 0.8.0 leak the exact system version through asset cache buster parameters in HTML output, bypassing the `hid…

fossbilling | Remote | Information Disclosure
Jun 03, 2026 Jun 04, 2026
Jun 03, 2026
Jun 04, 2026
0.0 NA
CVE-2026-37700 — MaxSite CMS Cross-Site Scripting

Cross Site Scripting vulnerability in MaxSite CMS v.109.2 allows a remote attacker to obtain sensitive information via the Backend page file upload endpoint used by admin_page

| Cross-Site Scripting
Jun 03, 2026 Jun 04, 2026
Jun 03, 2026
Jun 04, 2026
Showing 20 of 7141 Results