Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
4.8 MEDIUM
CVE-2026-25558 — QloApps 1.7.0 Stored XSS via SVG File Upload in Admin File Manager

QloApps through 1.7.0 contains a stored cross-site scripting vulnerability in the admin file manager that allows authenticated administrators to inject malicious JavaScript by uploading crafted SVG f…

Remote | Cross-Site Scripting
Jun 08, 2026 Jun 09, 2026
Jun 08, 2026
Jun 09, 2026
6.5 MEDIUM
CVE-2026-11521 — Mohammed-eid35 bank-management-system-springboot Transaction Endpoint TransactionControll…

A security vulnerability has been detected in Mohammed-eid35 bank-management-system-springboot up to 7b9bcc65ad7df3db29af71aed9bb500e5f24d948. This affects an unknown part of the file src/main/java/c…

bank-management-system-springboot | Remote | Authorization
Jun 08, 2026 Jun 09, 2026
Jun 08, 2026
Jun 09, 2026
4.0 MEDIUM
CVE-2026-11520 — SourceCodester Inventory System header.php cross site scripting

A weakness has been identified in SourceCodester Inventory System 1.0. Affected by this issue is some unknown functionality of the file header.php. This manipulation causes cross site scripting. It i…

inventory_system | Remote | Cross-Site Scripting
Jun 08, 2026 Jun 09, 2026
Jun 08, 2026
Jun 09, 2026
6.5 MEDIUM
CVE-2026-11519 — SourceCodester Inventory System Account Creation users_handler.php improper authorization

A security flaw has been discovered in SourceCodester Inventory System 1.0. Affected by this vulnerability is an unknown functionality of the file /Product_Inventory/api/users_handler.php of the comp…

inventory_system | Remote | Authorization
Jun 08, 2026 Jun 09, 2026
Jun 08, 2026
Jun 09, 2026
5.0 MEDIUM
CVE-2026-11518 — SourceCodester Inventory System User Management users.php cross site scripting

A vulnerability was identified in SourceCodester Inventory System 1.0. Affected is an unknown function of the file /users.php of the component User Management Page. The manipulation of the argument f…

inventory_system | Remote | Cross-Site Scripting
Jun 08, 2026 Jun 09, 2026
Jun 08, 2026
Jun 09, 2026
9.0 HIGH
CVE-2026-11517 — UTT HiPER 2610G formConfigDnsFilterGlobal strcpy buffer overflow

A vulnerability was determined in UTT HiPER 2610G up to 3.0.0-171107. This impacts the function strcpy of the file /goform/formConfigDnsFilterGlobal. Executing a manipulation of the argument GroupNam…

hiper_2610g | Remote | Memory Corruption
Jun 08, 2026 Jun 09, 2026
Jun 08, 2026
Jun 09, 2026
5.5 MEDIUM
CVE-2026-11516 — UTT HiPER 2610G formNatStaticMap strcpy buffer overflow

A vulnerability was found in UTT HiPER 2610G up to 3.0.0-171107. This affects the function strcpy of the file /goform/formNatStaticMap. Performing a manipulation of the argument NatBinds results in b…

hiper_2610g | Memory Corruption
Jun 08, 2026 Jun 09, 2026
Jun 08, 2026
Jun 09, 2026
4.8 MEDIUM
CVE-2026-9549 — Fix XSS in service discovery active check output

Stored cross-site scripting in the service discovery active check output in Checkmk <2.5.0p5, <2.4.0p31, <2.3.0p48, and all 2.2.0 versions allows an administrator who can configure active or custom c…

checkmk | Remote | Cross-Site Scripting
Jun 08, 2026 Jun 08, 2026
Jun 08, 2026
Jun 08, 2026
8.5 HIGH
CVE-2026-8833 — XSS in urls

Improper neutralization of HTML-encoded characters in the URL validation function in Checkmk <2.5.0p5, <2.4.0p31, <2.3.0p48, and all 2.2.0 versions allows an authenticated user to bypass URL validati…

checkmk | Remote | Cross-Site Scripting
Jun 08, 2026 Jun 09, 2026
Jun 08, 2026
Jun 09, 2026
4.8 MEDIUM
CVE-2026-8078 — Fix stored XSS in global settings change log

Stored cross-site scripting in the global settings change log in Checkmk <2.5.0p5, <2.4.0p31, <2.3.0p48, and all 2.2.0 versions allows an administrator who can change global settings to store malicio…

checkmk | Remote | Cross-Site Scripting
Jun 08, 2026 Jun 08, 2026
Jun 08, 2026
Jun 08, 2026
6.3 MEDIUM
CVE-2026-7765 — User Messages widget leaked issuer messages on shared dashboards

Incorrect authorization in the User Messages dashboard widget in Checkmk <2.5.0p5 causes the message-fetching endpoints to return the dashboard creator's messages rather than the viewer's, allowing a…

checkmk | Remote | Authorization
Jun 08, 2026 Jun 09, 2026
Jun 08, 2026
Jun 09, 2026
8.5 HIGH
CVE-2026-7186 — Fix stored XSS in URL dashboard widget via dangerous URI schemes

Stored cross-site scripting in the URL dashboard widget in Checkmk <2.5.0p5, <2.4.0p31, <2.3.0p48, and all 2.2.0 versions allows a user with dashboard editing permissions to store a URL with a danger…

checkmk | Remote | Cross-Site Scripting
Jun 08, 2026 Jun 08, 2026
Jun 08, 2026
Jun 08, 2026
7.2 HIGH
CVE-2026-11577 — Keycloak: keycloak: privilege escalation via partialimport fgap permission bypass

A flaw was found in Keycloak. A limited administrator can exploit an improper access control vulnerability in the POST /admin/realms/{realm}/partialImport endpoint. This allows them to bypass Fine-Gr…

Jun 08, 2026 Jun 08, 2026
Jun 08, 2026
Jun 08, 2026
5.5 MEDIUM
CVE-2026-11515 — SourceCodester Barangay Resident Profiling and Information Management System Password Res…

A vulnerability has been found in SourceCodester Barangay Resident Profiling and Information Management System 1.0. The impacted element is an unknown function of the file passsword_reset.php of the …

Jun 08, 2026 Jun 08, 2026
Jun 08, 2026
Jun 08, 2026
6.5 MEDIUM
CVE-2026-11514 — itsourcecode Hospital Management System addpatient.php sql injection

A flaw has been found in itsourcecode Hospital Management System 1.0. The affected element is an unknown function of the file /addpatient.php. This manipulation of the argument admissiontme causes sq…

hospital_management_system | Remote | Injection
Jun 08, 2026 Jun 08, 2026
Jun 08, 2026
Jun 08, 2026
6.5 MEDIUM
CVE-2026-11513 — itsourcecode Hospital Management System adminaccount.php sql injection

A vulnerability was detected in itsourcecode Hospital Management System 1.0. Impacted is an unknown function of the file /adminaccount.php. The manipulation of the argument Date results in sql inject…

hospital_management_system | Remote | Injection
Jun 08, 2026 Jun 08, 2026
Jun 08, 2026
Jun 08, 2026
5.0 MEDIUM
CVE-2026-11512 — itsourcecode Hospital Management System billing.php cross site scripting

A security vulnerability has been detected in itsourcecode Hospital Management System 1.0. This issue affects some unknown processing of the file /billing.php. The manipulation of the argument patien…

hospital_management_system | Remote | Cross-Site Scripting
Jun 08, 2026 Jun 08, 2026
Jun 08, 2026
Jun 08, 2026
4.0 MEDIUM
CVE-2026-11511 — Bolt CMS HTML Attribute TextType.php HTML injection

A weakness has been identified in Bolt CMS up to 3.7.5. This vulnerability affects unknown code of the file src/Storage/Field/Type/TextType.php of the component HTML Attribute Handler. Executing a ma…

cms | Remote | Injection
Jun 08, 2026 Jun 08, 2026
Jun 08, 2026
Jun 08, 2026
7.4 HIGH
CVE-2026-50752 — Certificate Validation Bypass in VPN Site-to-Site Connections Using IKEv1

A weakness in the certificate validation logic of the deprecated IKEv1 key exchange may allow an unauthenticated attacker positioned as a man-in-the-middle to bypass certificate validation in VPN sit…

quantum_security_gateway | Remote | Authentication
Jun 08, 2026 Jun 08, 2026
Jun 08, 2026
Jun 08, 2026
9.3 CRITICAL
CVE-2026-50751 — Check Point Security Gateway Improper Authentication Vulnerability - [Actively Exploited]

A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows an unauthenticated remote attacker to bypass user authentication and establish …

Jun 08, 2026 Jun 09, 2026
Jun 08, 2026
Jun 09, 2026
Showing 20 of 7424 Results