Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.5 HIGH
CVE-2026-49134 — CodexBar < 0.32.0 Privilege Escalation via CLI Installer Temp File

CodexBar prior to 0.32.0 contains a privilege escalation vulnerability in the CLI installer that allows local attackers to execute arbitrary commands as root by exploiting a race condition in tempora…

Remote | Race Condition
Jun 01, 2026 Jun 02, 2026
Jun 01, 2026
Jun 02, 2026
8.2 HIGH
CVE-2026-37234 — FlexRIC xApp ID Resource Leak

FlexRIC v2.0.0 allows a single SCTP connection to bind multiple xapp_ids by sending multiple E42_SETUP_REQUESTs. On disconnect, only the first registered xapp_id's resources are cleaned up; subsequen…

Remote | Information Disclosure
Jun 01, 2026 Jun 02, 2026
Jun 01, 2026
Jun 02, 2026
8.2 HIGH
CVE-2026-24751 — Kiteworks Secure Data Forms Vulnerable to Cross-site Scripting

Kiteworks is a private data network (PDN). Prior to version 9.3.0, a reflected XSS vulnerability in Kiteworks Secure Data Forms could allow an external attacker to trick a user into executing arbitra…

kiteworks | Remote | Cross-Site Scripting
Jun 01, 2026 Jun 03, 2026
Jun 01, 2026
Jun 03, 2026
5.0 MEDIUM
CVE-2026-10289 — code-projects Hotel and Tourism Reservation System tour.php cross site scripting

A security flaw has been discovered in code-projects Hotel and Tourism Reservation System 1.0. Impacted is an unknown function of the file /ht/tour.php. Performing a manipulation of the argument name…

hotel_and_tourism_reservation_system | Remote | Cross-Site Scripting
Jun 01, 2026 Jun 02, 2026
Jun 01, 2026
Jun 02, 2026
7.5 HIGH
CVE-2026-10288 — code-projects Hotel and Tourism Reservation System Admin Login login.php password_verify …

A vulnerability was identified in code-projects Hotel and Tourism Reservation System 1.0. This issue affects the function password_verify of the file /admin/login.php of the component Admin Login. Su…

hotel_and_tourism_reservation_system | Remote | Authentication
Jun 01, 2026 Jun 02, 2026
Jun 01, 2026
Jun 02, 2026
7.5 HIGH
CVE-2026-10287 — SourceCodester SEO Meta Tag Extractor index.php get_headers server-side request forgery

A vulnerability was determined in SourceCodester SEO Meta Tag Extractor 1.0. This vulnerability affects the function get_headers of the file /index.php. This manipulation of the argument url causes s…

seo_meta_tag_extractor | Remote | Server-Side Request Forgery
Jun 01, 2026 Jun 02, 2026
Jun 01, 2026
Jun 02, 2026
6.5 MEDIUM
CVE-2026-10286 — CodeAstro Payroll System home_employee.php sql injection

A vulnerability was found in CodeAstro Payroll System 1.0. This affects an unknown part of the file /home_employee.php. The manipulation of the argument emp_id results in sql injection. The attack ma…

payroll_system | Remote | Injection
Jun 01, 2026 Jun 02, 2026
Jun 01, 2026
Jun 02, 2026
5.5 MEDIUM
CVE-2026-10285 — DevaslanPHP project-management Ticket KanbanScrumHelper.php recordUpdated improper author…

A vulnerability has been found in DevaslanPHP project-management up to 2.0.0-beta1. Affected by this issue is the function KanbanScrumHelper::recordUpdated of the file app/Helpers/KanbanScrumHelper.p…

project-management | Remote | Authorization
Jun 01, 2026 Jun 02, 2026
Jun 01, 2026
Jun 02, 2026
5.5 MEDIUM
CVE-2026-10284 — DevaslanPHP project-management Livewire ViewTicket.php doDeleteComment improper authoriza…

A flaw has been found in DevaslanPHP project-management up to 2.0.0-beta1. Affected by this vulnerability is the function editComment/doDeleteComment of the file app/Filament/Resources/TicketResource…

project-management | Remote | Authorization
Jun 01, 2026 Jun 02, 2026
Jun 01, 2026
Jun 02, 2026
7.5 HIGH
CVE-2025-70099 — lwext4 NULL Pointer Dereference

A NULL pointer dereference in the ext4_dir_en_get_name_len function in include/ext4_dir.h of lwext4 1.0.0 allows attackers to cause a denial of service by supplying a specially crafted EXT4 filesyste…

Remote | Memory Corruption
Jun 01, 2026 Jun 02, 2026
Jun 01, 2026
Jun 02, 2026
7.1 HIGH
CVE-2021-46747 — AMD Secure Processor: Privilege Escalation via SMN Aperture Mapping

Insufficient granularity of access control in ASP (AMD Secure Processor) may allow an attacker with an untrusted user space application to map sensitive SMN (System Management Network) apertures lead…

| Authorization
Jun 01, 2026 Jun 02, 2026
Jun 01, 2026
Jun 02, 2026
8.8 HIGH
CVE-2026-9614 — Ivanti Neurons for ITSM Improper Access Control to Administrator Privilege Escalation

An Improper Access Control vulnerability in Ivanti Neurons for ITSM (cloud and on-premises) allows a remote authenticated attacker to gain administrative access.

neurons_for_itsm | Remote | Authorization
Jun 01, 2026 Jun 02, 2026
Jun 01, 2026
Jun 02, 2026
8.5 HIGH
CVE-2026-9330 — IBM WebSphere Application Server is affected by remote code execution

IBM WebSphere Application Server 9.0, and 8.5 is affected by an improper validation of user-supplied data during deserialization using the SAML Web Single Sign-On component. This could result in remo…

websphere_application_server | Remote | Injection
Jun 01, 2026 Jun 04, 2026
Jun 01, 2026
Jun 04, 2026
9.0 CRITICAL
CVE-2026-9319 — IBM WebSphere Application Server is affected by a remote code execution vulnerability

IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to potential remote code execution due to deserialization of untrusted data via JAX-WS endpoints with WS-Security.

websphere_application_server | Remote | Injection
Jun 01, 2026 Jun 04, 2026
Jun 01, 2026
Jun 04, 2026
9.0 CRITICAL
CVE-2026-9311 — IBM WebSphere Application Server is affected by remote code execution

IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to remote code execution caused by the bypass of security controls.

websphere_application_server | Remote | Authentication
Jun 01, 2026 Jun 04, 2026
Jun 01, 2026
Jun 04, 2026
9.1 CRITICAL
CVE-2026-8644 — IBM WebSphere Application Server is affected by an identity spoofing vulnerability

IBM WebSphere Application Server 9.0, and 8.5 is vulnerable to identity spoofing.

websphere_application_server | Remote | Authentication
Jun 01, 2026 Jun 04, 2026
Jun 01, 2026
Jun 04, 2026
8.8 HIGH
CVE-2026-7770 — IBM i Access Client Solutions (ACS) is vulnerable to remote code execution when configure…

IBM i Access Family 1.1.5.0 through 1.1.9.12 IBM i Access Client Solutions (ACS) is vulnerable to remote code execution when configured to listen for requests from IBM i Navigator.

i_access_family | Remote | Misconfiguration
Jun 01, 2026 Jun 02, 2026
Jun 01, 2026
Jun 02, 2026
9.2 CRITICAL
CVE-2026-49121 — AI Tensor Engine for ROCm (AITER) 0.1.14 Unauthenticated RCE via MessageQueue.recv() Pick…

AI Tensor Engine for ROCm (AITER) through 0.1.14 contains an unauthenticated remote code execution vulnerability in the MessageQueue.recv() function within shm_broadcast.py that allows unauthenticate…

Remote | Authentication
Jun 01, 2026 Jun 02, 2026
Jun 01, 2026
Jun 02, 2026
8.0 HIGH
CVE-2026-47294 — Microsoft SharePoint Server Remote Code Execution Vulnerability

Deserialization of untrusted data in Microsoft Office SharePoint allows an authorized attacker to execute code over a network.

Jun 01, 2026 Jun 03, 2026
Jun 01, 2026
Jun 03, 2026
6.8 MEDIUM
CVE-2026-45810 — Nextcloud: Propfind requests for file comments allowed to load comments for other files

Nextcloud is an open source content collaboration platform. In Nextcloud Server from versions 31.0.0 to before 31.0.12, and 32.0.0 to before 32.0.3, a missing check of a relation allowed authenticate…

nextcloud_server notes | Remote | Authorization
Jun 01, 2026 Jun 04, 2026
Jun 01, 2026
Jun 04, 2026
Showing 20 of 7360 Results