Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.3 MEDIUM
CVE-2026-9500 — GNU LibreDWG Dwgread Utility decode.c read_2004_compressed_section heap-based overflow

A vulnerability was found in GNU LibreDWG up to 0.14. The affected element is the function read_2004_compressed_section of the file src/decode.c of the component Dwgread Utility. Performing a manipul…

libredwg | Memory Corruption
May 25, 2026 May 26, 2026
May 25, 2026
May 26, 2026
3.7 LOW
CVE-2026-48852 — PuTTY ECDSA Signature Verification Assertion Failure

PuTTY 0.71 before 0.84 has an assertion failure in ECDSA signature verification.

putty | Remote | Cryptography
May 25, 2026 May 27, 2026
May 25, 2026
May 27, 2026
3.1 LOW
CVE-2026-48851 — PuTTY TELNET Icon Trust Indication Vulnerability

PuTTY 0.77 before 0.84 uses a copy of the PuTTY icon as a trust indication for TELNET data but the trust status is not cleared between proxy authentication and the main session.

putty | Remote | Misconfiguration
May 25, 2026 May 27, 2026
May 25, 2026
May 27, 2026
5.9 MEDIUM
CVE-2026-48850 — PuTTY RSA KEX Double Free Vulnerability

PuTTY 0.72 before 0.84 has a double free in RSA KEX.

putty | Remote | Memory Corruption
May 25, 2026 May 27, 2026
May 25, 2026
May 27, 2026
5.4 MEDIUM
CVE-2026-48589 — Apache Shiro: Jakarta EE open redirect via untrusted Referer in post-login redirect flow

Apache Shiro’s Jakarta EE module used the HTTP Referer header in certain cases to issue redirect after a user login. In affected versions, insufficient validation of this client-controlled value coul…

shiro | Remote | Information Disclosure
May 25, 2026 May 28, 2026
May 25, 2026
May 28, 2026
5.4 MEDIUM
CVE-2026-44598 — Apache Shiro Jakarta EE module: Open redirect and SSRF (requires valid credentials)

With valid login credentials, URL Redirection to Untrusted Site ('Open Redirect'), Server-Side Request Forgery (SSRF) vulnerability in Apache Shiro. This issue affects Apache Shiro from 2.0-alpha…

shiro | Remote | Server-Side Request Forgery
May 25, 2026 May 28, 2026
May 25, 2026
May 28, 2026
6.5 MEDIUM
CVE-2026-43828 — Apache Shiro: Shiro's native session and rememberMe cookies do not have secure flag set b…

Default configurations of Apache Shiro send sensitive cookies in HTTPS session without 'Secure' attribute. This issue affects Apache Shiro from 1.0 to 2.1.0, and 3.0.0-alpha-1. Users are recommen…

shiro | Remote | Misconfiguration
May 25, 2026 May 28, 2026
May 25, 2026
May 28, 2026
6.5 MEDIUM
CVE-2026-43827 — Apache Shiro: Session fixation: new session is not created after login by default

Default configurations of Apache Shiro have a session fixation vulnerability. This issue affects Apache Shiro from 1.0 to 2.1.0, and 3.0.0-alpha-1. Users are recommended to upgrade to version 2.1.1…

shiro | Remote | Authentication
May 25, 2026 May 28, 2026
May 25, 2026
May 28, 2026
4.3 MEDIUM
CVE-2026-24597 — WordPress Organization chart plugin <= 1.7.5 - Cross Site Request Forgery (CSRF) vulnerab…

Cross-Site Request Forgery (CSRF) vulnerability in WpDevArt Organization chart allows Cross Site Request Forgery. This issue affects Organization chart: from n/a through 1.7.5.

organization_chart | Remote | Cross-Site Request Forgery
May 25, 2026 May 26, 2026
May 25, 2026
May 26, 2026
6.5 MEDIUM
CVE-2026-24574 — WordPress Export WP Page to Static HTML/CSS plugin <= 6.0.0 - Cross Site Request Forgery …

Cross-Site Request Forgery (CSRF) vulnerability in Recorp Export WP Page to Static HTML/CSS allows Cross Site Request Forgery. This issue affects Export WP Page to Static HTML/CSS: from n/a through …

export_wp_page_to_static_html\/css | Remote | Cross-Site Request Forgery
May 25, 2026 May 26, 2026
May 25, 2026
May 26, 2026
4.3 MEDIUM
CVE-2026-24545 — WordPress QR Redirector plugin <= 2.0.3 - Broken Access Control vulnerability

Missing Authorization vulnerability in Nikki Blight QR Redirector allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects QR Redirector: from n/a through 2.0.3.

qr_redirector | Remote | Authorization
May 25, 2026 May 26, 2026
May 25, 2026
May 26, 2026
6.5 MEDIUM
CVE-2026-9498 — Dromara lamp-cloud Message Template GroovyClassLoader.parseClass special elements used in…

A vulnerability has been found in Dromara lamp-cloud up to 5.6.2. Impacted is the function GroovyClassLoader.parseClass of the component Message Template Handler. Such manipulation of the argument De…

lamp-cloud | Remote | Injection
May 25, 2026 May 26, 2026
May 25, 2026
May 26, 2026
6.5 MEDIUM
CVE-2026-9497 — changmingxie tcc-transaction Fastjson AutoType REST API Fastjson.parseObject deserializat…

A flaw has been found in changmingxie tcc-transaction up to 2.1.0. This issue affects the function Fastjson.parseObject of the component Fastjson AutoType REST API. This manipulation causes deseriali…

tcc-transaction | Remote | Injection
May 25, 2026 May 26, 2026
May 25, 2026
May 26, 2026
5.0 MEDIUM
CVE-2026-9486 — SourceCodester Student Grades Management System cross-site request forgery

A security flaw has been discovered in SourceCodester Student Grades Management System 1.0. This affects an unknown part. The manipulation results in cross-site request forgery. The attack can be exe…

student_grades_management_system | Remote | Cross-Site Request Forgery
May 25, 2026 May 26, 2026
May 25, 2026
May 26, 2026
4.0 MEDIUM
CVE-2026-9485 — SourceCodester Student Grades Management System students.php cross site scripting

A vulnerability was identified in SourceCodester Student Grades Management System 1.0. Affected by this issue is some unknown functionality of the file students.php. The manipulation of the argument …

student_grades_management_system | Remote | Cross-Site Scripting
May 25, 2026 May 26, 2026
May 25, 2026
May 26, 2026
6.5 MEDIUM
CVE-2026-9484 — SourceCodester Student Grades Management System classroom.php removeStudentFromClassroom …

A vulnerability was determined in SourceCodester Student Grades Management System 1.0. Affected by this vulnerability is the function getClassroomStudents/removeStudentFromClassroom of the file class…

student_grades_management_system | Remote | Authorization
May 25, 2026 May 26, 2026
May 25, 2026
May 26, 2026
4.4 MEDIUM
CVE-2026-48849 — Roundcube Webmail Stored XSS/HTML/CSS Injection

In Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1, an unsanitized subject field in the draft restored value could lead to stored XSS/HTML/CSS injection on shared mailboxes.

webmail | Remote | Cross-Site Scripting
May 25, 2026 May 26, 2026
May 25, 2026
May 26, 2026
7.2 HIGH
CVE-2026-48848 — Roundcube Webmail CSS Injection Vulnerability

Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7 has insufficient HTML sanitization that could lead to Cascading Style Sheets (CSS) injection via an SVG document that has an animate element…

webmail | Remote | Cross-Site Scripting
May 25, 2026 May 26, 2026
May 25, 2026
May 26, 2026
3.7 LOW
CVE-2026-48847 — Roundcube Webmail Redis/Memcache File Deletion Vulnerability

Roundcube Webmail 1.6.x before 1.6.16, and 1.7.x before 1.7.1 allows pre-authentication arbitrary file deletion via redis/memcache session poisoning bypass.

webmail | Remote | Misconfiguration
May 25, 2026 May 26, 2026
May 25, 2026
May 26, 2026
6.5 MEDIUM
CVE-2026-48846 — Roundcube Webmail CSS Injection Vulnerability

In Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1, the remote image blocking feature can be bypassed via a crafted CSS var() value in an e-mail message, which may lead to information di…

webmail | Remote | Information Disclosure
May 25, 2026 May 26, 2026
May 25, 2026
May 26, 2026
Showing 20 of 6724 Results