Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.2 HIGH
CVE-2026-50232 — Lyrion Music Server 9.2.0 Stored XSS via Metadata Tags

Lyrion Music Server 9.2.0 contains a stored cross-site scripting vulnerability that allows attackers to inject malicious scripts through media file metadata tags like GENRE, ARTIST, and ALBUM. Attack…

Remote | Cross-Site Scripting
Jun 05, 2026 Jun 08, 2026
Jun 05, 2026
Jun 08, 2026
7.2 HIGH
CVE-2026-50231 — Lyrion Music Server 9.2.0 Unauthenticated Stored XSS via server.log

Lyrion Music Server 9.2.0 contains an unauthenticated stored cross-site scripting vulnerability in the log viewer that allows attackers to inject malicious scripts by exploiting unescaped template va…

Remote | Cross-Site Scripting
Jun 05, 2026 Jun 05, 2026
Jun 05, 2026
Jun 05, 2026
6.1 MEDIUM
CVE-2026-50230 — Lyrion Music Server 9.2.0 Reflected XSS via server.log

Lyrion Music Server 9.2.0 contains an unauthenticated reflected cross-site scripting vulnerability in the server.log endpoint that allows attackers to inject arbitrary HTML and JavaScript code throug…

Remote | Cross-Site Scripting
Jun 05, 2026 Jun 05, 2026
Jun 05, 2026
Jun 05, 2026
7.1 HIGH
CVE-2026-11369 — IDOR in Comment API Allows Cross-Process Comment Read and Write

The Comment API (GET /api/Comment and POST /api/Comment) in the affected application fails to perform authorization checks to verify that the requesting user has access to the object identified by th…

Remote | Authorization
Jun 05, 2026 Jun 05, 2026
Jun 05, 2026
Jun 05, 2026
3.6 LOW
CVE-2026-11330 — thedotmack claude-mem Observation Content Hash store.ts computeObservationContentHash wea…

A weakness has been identified in thedotmack claude-mem up to 11.0.1. The affected element is the function computeObservationContentHash of the file src/services/sqlite/observations/store.ts of the c…

claude-mem | Cryptography
Jun 05, 2026 Jun 05, 2026
Jun 05, 2026
Jun 05, 2026
3.6 LOW
CVE-2026-11329 — onnx onnx-mlir Placeholder Node Cache backend.py generate_hash_key weak hash

A vulnerability has been found in onnx onnx-mlir up to 0.5.0.0. Affected by this issue is the function generate_hash_key of the file src/Runtime/python/torch_onnxmlir/src/torch_onnxmlir/backend.py of…

onnx-mlir | Cryptography
Jun 05, 2026 Jun 05, 2026
Jun 05, 2026
Jun 05, 2026
7.8 HIGH
CVE-2026-50264 — Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: out-of-bounds heap write in d…

An out-of-bounds write flaw was found in the X.Org X server and Xwayland in DRIGetBuffers/DRIGetBuffersWithFormat. A client that requests multiple DRI2BufferBackLeft attachments and one DRI2BufferFro…

enterprise_linux enterprise_linux | Memory Corruption
Jun 05, 2026 Jun 05, 2026
Jun 05, 2026
Jun 05, 2026
5.5 MEDIUM
CVE-2026-50263 — Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: use-after-free information di…

A use-after-free flaw was found in the X.Org X server and Xwayland in CreateSaverWindow(). A client can trigger a use-after-free read after changing window attributes and forcing the screen saver, le…

enterprise_linux enterprise_linux | Memory Corruption
Jun 05, 2026 Jun 05, 2026
Jun 05, 2026
Jun 05, 2026
5.5 MEDIUM
CVE-2026-50262 — Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: out-of-bounds read/write in g…

An out-of-bounds read flaw was found in the X.Org X server and Xwayland in __glXDisp_ChangeDrawableAttributes(). A wrong size validation check can read a client-controlled number of bytes, exceeding …

enterprise_linux enterprise_linux | Information Disclosure
Jun 05, 2026 Jun 05, 2026
Jun 05, 2026
Jun 05, 2026
7.8 HIGH
CVE-2026-50261 — Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: use-after-free in syncchangec…

A use-after-free flaw was found in the X.Org X server and Xwayland in SyncChangeCounter(). A client that sets up multiple SyncCounters can trigger a use-after-free when destroying those counters via …

enterprise_linux enterprise_linux | Memory Corruption
Jun 05, 2026 Jun 05, 2026
Jun 05, 2026
Jun 05, 2026
7.8 HIGH
CVE-2026-50260 — Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: use-after-free in freecounter…

A use-after-free flaw was found in the X.Org X server and Xwayland in FreeCounter(). A client that sets up multiple SyncCounters and awaits on those triggers can trigger a use-after-free when destroy…

enterprise_linux enterprise_linux | Memory Corruption
Jun 05, 2026 Jun 05, 2026
Jun 05, 2026
Jun 05, 2026
7.8 HIGH
CVE-2026-50259 — Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: stack buffer overflow in xkb …

A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. _XkbSetMapChecks() declares a fixed-size stack buffer mapWidths[256] indexed by key type index. The helper function Ch…

Jun 05, 2026 Jun 08, 2026
Jun 05, 2026
Jun 08, 2026
7.8 HIGH
CVE-2026-50258 — Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: stack buffer overflow in xkb …

A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. The X server has multiple stack buffers sized XkbMaxShiftLevel * XkbNumKbdGroups but CheckKeyTypes() does not verify o…

Jun 05, 2026 Jun 08, 2026
Jun 05, 2026
Jun 08, 2026
7.8 HIGH
CVE-2026-50257 — Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: use-after-free in misyncdestr…

A use-after-free flaw was found in the X.Org X server and Xwayland in miSyncDestroyFence(). A client that sets up multiple fence triggers can trigger a use-after-free function pointer call. An attack…

Jun 05, 2026 Jun 08, 2026
Jun 05, 2026
Jun 08, 2026
7.8 HIGH
CVE-2026-50256 — Xorg-x11-server: xorg-x11-server-xwayland: xorg-x11-server: stack buffer overflow in font…

A stack-based buffer overflow flaw was found in the X.Org X server and Xwayland. A mismatch between the X server and the libXfont2 library's maximum font name length can cause a stack buffer overflow…

Jun 05, 2026 Jun 08, 2026
Jun 05, 2026
Jun 08, 2026
7.1 HIGH
CVE-2026-25659 — Ericsson Packet Core Gateway (PCG) - Improper handling of missing values Vulnerability

Ericsson Packet Core Gateway (PCG) versions prior to 1.30 contain an Improper Handling of Missing Values (CWE-230) vulnerability where an attacker continuously sending a specially crafted message can…

packet_core_gateway | Denial of Service
Jun 05, 2026 Jun 08, 2026
Jun 05, 2026
Jun 08, 2026
7.1 HIGH
CVE-2026-25658 — Ericsson Packet Core Gateway (PCG) - Improper handling of missing values Vulnerability

Ericsson Packet Core Gateway (PCG) versions prior to 1.30 contain an Improper Handling of Missing Values (CWE-230) vulnerability where an attacker continuously sending a specially crafted message can…

packet_core_gateway | Denial of Service
Jun 05, 2026 Jun 08, 2026
Jun 05, 2026
Jun 08, 2026
7.1 HIGH
CVE-2026-25657 — Ericsson Packet Core Gateway (PCG) - Improper Handling of Syntactically Invalid Structure…

Ericsson Packet Core Gateway (PCG) versions prior to 1.30 contain an Improper Handling of Syntactically Invalid Structure (CWE-228) vulnerability where an attacker continuously sending a specially cr…

packet_core_gateway | Denial of Service
Jun 05, 2026 Jun 08, 2026
Jun 05, 2026
Jun 08, 2026
5.3 MEDIUM
CVE-2026-11346 — Server-Side Request Forgery (SSRF) allowing Internal Network Probing in linqi

A Server-Side Request Forgery (SSRF) vulnerability in the custom process creation feature of linqi allows an authenticated attacker to probe internal network components. By crafting a specific proces…

Remote | Server-Side Request Forgery
Jun 05, 2026 Jun 05, 2026
Jun 05, 2026
Jun 05, 2026
6.9 MEDIUM
CVE-2026-11345 — Improper Authentication Bypass in linqi CDN File Access

An Improper Authentication vulnerability in the /api/Cdn/GetFile endpoint of linqi allows unauthenticated, remote attackers to bypass file access controls. The ValidateAnonFileAccess function incorre…

Remote | Authentication
Jun 05, 2026 Jun 05, 2026
Jun 05, 2026
Jun 05, 2026
Showing 20 of 7534 Results