Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.9 MEDIUM
CVE-2026-11238 — Google Chrome DevTools Information Disclosure

Inappropriate implementation in DevTools in Google Chrome prior to 149.0.7827.53 allowed an attacker who convinced a user to install a malicious extension to obtain potentially sensitive information …

linux_kernel chrome macos chrome windows | Remote | Information Disclosure
Jun 05, 2026 Jun 05, 2026
Jun 05, 2026
Jun 05, 2026
8.8 HIGH
CVE-2026-10878 — D-Link DWR-M920 formSmsManage sub_41C8E8 command injection

A vulnerability was detected in D-Link DWR-M920 1.1.50/1.1.70. Affected is the function sub_41C8E8 of the file /boafrm/formSmsManage. Performing a manipulation of the argument action_value results in…

dwr-m920_firmware dwr-m920 | Remote | Injection
Jun 05, 2026 Jun 05, 2026
Jun 05, 2026
Jun 05, 2026
7.5 HIGH
CVE-2026-10877 — SourceCodester Ship Ferry Ticket Reservation System Admin Login login.php sql injection

A security vulnerability has been detected in SourceCodester Ship Ferry Ticket Reservation System up to 1.0. This impacts an unknown function of the file /admin/login.php of the component Admin Login…

Jun 05, 2026 Jun 05, 2026
Jun 05, 2026
Jun 05, 2026
6.5 MEDIUM
CVE-2026-10876 — SourceCodester Ship Ferry Ticket Reservation System admin improper authorization

A weakness has been identified in SourceCodester Ship Ferry Ticket Reservation System 1.0. This affects an unknown function of the file /admin/. This manipulation of the argument page causes improper…

ship_ferry_ticket_reservation_system | Remote | Authorization
Jun 05, 2026 Jun 05, 2026
Jun 05, 2026
Jun 05, 2026
7.2 HIGH
CVE-2026-10586 — Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns <= 6.1.3 - Auth…

The Gutenberg Essential Blocks – Page Builder for Gutenberg Blocks & Patterns plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 6.1.3 via the `sa…

essential_blocks | Remote | Server-Side Request Forgery
Jun 05, 2026 Jun 05, 2026
Jun 05, 2026
Jun 05, 2026
0.0 NA
CVE-2026-36501 — Controller Externalizable DoS

An issue in the Externalizable.readExternal() component of Controller v12.0.5 allows attackers to cause a Denial of Service (DoS) via a crafted input.

| Denial of Service
Jun 05, 2026 Jun 05, 2026
Jun 05, 2026
Jun 05, 2026
0.0 NA
CVE-2026-36500 — Controller Backup Datastore Directory Traversal

An issue in the cluster-admin:backup-datastore component of Controller v12.0.5 allows attackers to execute a directory traversal via a crafted request.

| Path Traversal
Jun 05, 2026 Jun 05, 2026
Jun 05, 2026
Jun 05, 2026
9.1 CRITICAL
CVE-2026-48579 — Microsoft Exchange Online Information Disclosure Vulnerability

Improper authorization in Microsoft Exchange Online allows an unauthorized attacker to disclose information over a network.

Jun 04, 2026 Jun 05, 2026
Jun 04, 2026
Jun 05, 2026
10.0 CRITICAL
CVE-2026-48567 — Azure HorizonDB Elevation of Privilege Vulnerability

Authentication bypass by spoofing in Azure HorizonDB allows an unauthorized attacker to elevate privileges over a network.

Jun 04, 2026 Jun 05, 2026
Jun 04, 2026
Jun 05, 2026
6.5 MEDIUM
CVE-2026-47655 — Microsoft Graph Information Disclosure Vulnerability

Exposure of sensitive information to an unauthorized actor in Microsoft Graph allows an authorized attacker to disclose information over a network.

Jun 04, 2026 Jun 05, 2026
Jun 04, 2026
Jun 05, 2026
6.5 MEDIUM
CVE-2026-47644 — Copilot Chat (Microsoft Edge) Information Disclosure Vulnerability

Improper neutralization of special elements in output used by a downstream component ('injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker to disclose information over a netw…

Jun 04, 2026 Jun 05, 2026
Jun 04, 2026
Jun 05, 2026
7.7 HIGH
CVE-2026-45497 — Microsoft M365 Copilot Remote Code Execution Vulnerability

Improper neutralization of special elements used in a command ('command injection') in Microsoft Copilot allows an authorized attacker to execute code over a network.

Jun 04, 2026 Jun 05, 2026
Jun 04, 2026
Jun 05, 2026
6.5 MEDIUM
CVE-2026-42824 — M365 Copilot Information Disclosure Vulnerability

Improper neutralization of special elements used in a command ('command injection') in M365 Copilot allows an unauthorized attacker to disclose information over a network.

Jun 04, 2026 Jun 05, 2026
Jun 04, 2026
Jun 05, 2026
7.8 HIGH
CVE-2026-20245 — Cisco Catalyst SD-WAN Controller Authenticated Privilege Escalation Vulnerability

A vulnerability in the CLI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, local attacker to execute arbitrary commands as root by supplying a crafted file to…

Jun 04, 2026 Jun 05, 2026
Jun 04, 2026
Jun 05, 2026
8.3 HIGH
CVE-2026-11237 — Google Chrome Media UI Spoofing

Insufficient validation of untrusted input in Media in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to perform UI spoofing via a crafted HTM…

chrome chrome | Remote | Information Disclosure
Jun 04, 2026 Jun 05, 2026
Jun 04, 2026
Jun 05, 2026
8.3 HIGH
CVE-2026-11236 — Google Chrome: Insufficient Policy Enforcement in Web Bluetooth

Insufficient policy enforcement in Web Bluetooth in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to potentially perform a sandbox escape via…

chrome chrome | Remote | Misconfiguration
Jun 04, 2026 Jun 05, 2026
Jun 04, 2026
Jun 05, 2026
8.8 HIGH
CVE-2026-11235 — Google Chrome Compositing Policy Bypass

Insufficient policy enforcement in Compositing in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to execute arbitrary code inside a sandbox vi…

chrome chrome | Remote | Misconfiguration
Jun 04, 2026 Jun 05, 2026
Jun 04, 2026
Jun 05, 2026
4.3 MEDIUM
CVE-2026-11234 — Google Chrome FoldableAPIs Improper Implementation Vulnerability

Inappropriate implementation in FoldableAPIs in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to bypass site isolation via a crafted HTML pag…

chrome chrome | Remote | Misconfiguration
Jun 04, 2026 Jun 05, 2026
Jun 04, 2026
Jun 05, 2026
4.7 MEDIUM
CVE-2026-11233 — Google Chrome FoldableAPIs Same Origin Policy Bypass

Insufficient policy enforcement in FoldableAPIs in Google Chrome prior to 149.0.7827.53 allowed a remote attacker who had compromised the renderer process to bypass same origin policy via a crafted H…

chrome chrome | Remote | Authorization
Jun 04, 2026 Jun 05, 2026
Jun 04, 2026
Jun 05, 2026
5.4 MEDIUM
CVE-2026-11232 — Google Chrome TabGroups UI Spoofing

Inappropriate implementation in TabGroups in Google Chrome prior to 149.0.7827.53 allowed a remote attacker to perform UI spoofing via malicious network traffic. (Chromium security severity: Low)

chrome chrome | Remote | Information Disclosure
Jun 04, 2026 Jun 05, 2026
Jun 04, 2026
Jun 05, 2026
Showing 20 of 7379 Results