Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.0 HIGH
CVE-2026-9628 — UTT HiPER 1200GW Web Management formPptpClientConfig stack-based overflow

A weakness has been identified in UTT HiPER 1200GW up to 2.5.3-170306. Affected is an unknown function of the file /goform/formPptpClientConfig of the component Web Management Interface. This manipul…

hiper_1200gw | Remote | Memory Corruption
May 27, 2026 May 28, 2026
May 27, 2026
May 28, 2026
9.0 HIGH
CVE-2026-9627 — UTT HiPER 1200GW Web Management setSysAdm strcpy buffer overflow

A security flaw has been discovered in UTT HiPER 1200GW up to 2.5.3-170306. This impacts the function strcpy of the file /goform/setSysAdm of the component Web Management Interface. The manipulation …

hiper_1200gw | Remote | Memory Corruption
May 27, 2026 May 27, 2026
May 27, 2026
May 27, 2026
5.8 MEDIUM
CVE-2026-9609 — QianFox FoxCMS Admin.php edit password recovery

A vulnerability was identified in QianFox FoxCMS up to 1.2.6. This affects the function Edit of the file Admin.php. The manipulation leads to weak password recovery. The attack can be initiated remot…

foxcms | Remote | Authentication
May 27, 2026 May 27, 2026
May 27, 2026
May 27, 2026
3.3 LOW
CVE-2026-9608 — QianFox FoxCMS Administrator Backend edit cross site scripting

A vulnerability was determined in QianFox FoxCMS up to 1.2.6. The impacted element is an unknown function of the file /Tag/edit of the component Administrator Backend. Executing a manipulation can le…

foxcms | Remote | Cross-Site Scripting
May 27, 2026 May 27, 2026
May 27, 2026
May 27, 2026
8.8 HIGH
CVE-2026-9207 — Tanium addressed an unauthorized code execution vulnerability in Connect.

Tanium addressed an unauthorized code execution vulnerability in Connect.

connect | Remote | Injection
May 27, 2026 May 28, 2026
May 27, 2026
May 28, 2026
7.5 HIGH
CVE-2026-9156 — Tanium addressed a denial of service vulnerability in Tanium Server.

Tanium addressed a denial of service vulnerability in Tanium Server.

server | Remote | Denial of Service
May 27, 2026 May 29, 2026
May 27, 2026
May 29, 2026
5.3 MEDIUM
CVE-2026-7493 — Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin <= 1.6.11.5 - …

The Appointment Booking Calendar — Simply Schedule Appointments Booking Plugin plugin for WordPress is vulnerable to denial of service in all versions up to, and including, 1.6.11.5. This is due to a…

simply_schedule_appointments | Remote | Denial of Service
May 27, 2026 May 27, 2026
May 27, 2026
May 27, 2026
6.4 MEDIUM
CVE-2026-6565 — Style Kits – Advanced Theme Styles for Elementor <= 2.5.0 - Authenticated (Contributor+) …

The Style Kits – Advanced Theme Styles for Elementor, Elementor Kits & Elementor Patterns plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the '/wp-json/agwp/v1/tokens/save' endp…

Remote | Cross-Site Scripting
May 27, 2026 May 27, 2026
May 27, 2026
May 27, 2026
7.1 HIGH
CVE-2026-49017 — OpenStack Swift S3API Middleware Infinite Loop Denial of Service Vulnerability

In OpenStack Swift before 2.36.2 and 2.37.2, s3api middleware enters an infinite loop when processing a truncated aws-chunked PUT request body. The StreamingInput class repeatedly appends an empty bu…

swift | Remote | Denial of Service
May 27, 2026 Jun 02, 2026
May 27, 2026
Jun 02, 2026
7.8 HIGH
CVE-2026-49014 — "GDAL NetCDF Driver Stack Buffer Overflow"

In GDAL 3.1.0 through 3.13.0, scanForGeometryContainers in the netCDF driver allows code execution via a stack-based buffer overflow. It reads a geometry attribute into a fixed-size stack buffer with…

gdal gdal | Memory Corruption
May 27, 2026 Jun 04, 2026
May 27, 2026
Jun 04, 2026
6.5 MEDIUM
CVE-2026-9607 — itsourcecode Courier Management System parcel_list.php sql injection

A vulnerability was found in itsourcecode Courier Management System 1.0. The affected element is an unknown function of the file /parcel_list.php. Performing a manipulation of the argument s results …

courier_management_system | Remote | Injection
May 27, 2026 May 28, 2026
May 27, 2026
May 28, 2026
7.5 HIGH
CVE-2026-9606 — itsourcecode Courier Management System manage_user.php sql injection

A vulnerability has been found in itsourcecode Courier Management System 1.0. Impacted is an unknown function of the file /manage_user.php. Such manipulation of the argument ID leads to sql injection…

courier_management_system | Remote | Injection
May 27, 2026 May 27, 2026
May 27, 2026
May 27, 2026
7.5 HIGH
CVE-2026-9605 — GNU libredwg Dwgbmp Utility bits.c bit_read_RC heap-based overflow

A flaw has been found in GNU libredwg up to 0.13.4.8160. This issue affects the function bit_read_RC of the file bits.c of the component Dwgbmp Utility. This manipulation causes heap-based buffer ove…

libredwg | Remote | Memory Corruption
May 27, 2026 May 28, 2026
May 27, 2026
May 28, 2026
9.2 CRITICAL
CVE-2026-9312 — Server-Side Request Forgery vulnerability in GitHub Enterprise Server allowed access to i…

A server-side request forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to send crafted requests to internal services by exploiting insu…

enterprise_server | Remote | Server-Side Request Forgery
May 27, 2026 Jun 02, 2026
May 27, 2026
Jun 02, 2026
7.0 HIGH
CVE-2026-8606 — Server-Side Request Forgery in GitHub Enterprise Server via Advisory Package URL Endpoint

A Server-Side Request Forgery (SSRF) vulnerability was identified in GitHub Enterprise Server that allowed an attacker to cause the server to issue HTTP requests to internal services via the security…

enterprise_server | Remote | Server-Side Request Forgery
May 27, 2026 Jun 01, 2026
May 27, 2026
Jun 01, 2026
4.3 MEDIUM
CVE-2026-9604 — JeecgBoot AiragModelController access control

A vulnerability was detected in JeecgBoot up to 3.9.1. This vulnerability affects unknown code of the component AiragModelController. The manipulation of the argument list/queryById results in improp…

jeecgboot | Remote | Authorization
May 26, 2026 May 27, 2026
May 26, 2026
May 27, 2026
4.8 MEDIUM
CVE-2026-8647 — Crypt::ScryptKDF versions through 0.010 for Perl uses insecure random number source when …

Crypt::ScryptKDF versions through 0.010 for Perl uses insecure random number source when no CSPRNG module is available. The random_bytes function fell back to using the built-in rand() function when…

Remote | Cryptography
May 26, 2026 May 28, 2026
May 26, 2026
May 28, 2026
5.3 MEDIUM
CVE-2026-46740 — Mojolicious::Plugin::Statsd versions through 0.04 for Perl allowed metric injections

Mojolicious::Plugin::Statsd versions through 0.04 for Perl allowed metric injections. The metric names and set values were not checked for newlines, colons or pipes. Metrics generated from untrusted…

Remote | Injection
May 26, 2026 May 28, 2026
May 26, 2026
May 28, 2026
6.5 MEDIUM
CVE-2026-9603 — SourceCodester eDoc Doctor Appointment System delete-session.php authorization

A security vulnerability has been detected in SourceCodester eDoc Doctor Appointment System 1.0. This affects an unknown part of the file /admin/delete-session.php. The manipulation of the argument I…

edoc_doctor_appointment_system | Remote | Authorization
May 26, 2026 May 27, 2026
May 26, 2026
May 27, 2026
7.5 HIGH
CVE-2026-9584 — code-projects Project Management System Login chk.php sql injection

A security vulnerability has been detected in code-projects Project Management System 1.0. Affected is an unknown function of the file chk.php of the component Login. The manipulation leads to sql in…

project_management_system | Remote | Injection
May 26, 2026 May 27, 2026
May 26, 2026
May 27, 2026
Showing 20 of 6747 Results