Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.8 MEDIUM
CVE-2026-21029 — Samsung Galaxy Editing Service Component Export Vulnerability

Improper export of android application components in Galaxy Editing Service prior to SMR Jun-2026 Release 1 allows local attacker to execute privileged operations.

| Authentication
Jun 05, 2026 Jun 05, 2026
Jun 05, 2026
Jun 05, 2026
5.1 MEDIUM
CVE-2026-21028 — SAP AuditLogService Improper Access Control Information Disclosure

Improper access control in AuditLogService prior to SMR Jun-2026 Release 1 allows local attackers to access sensitive information.

| Authorization
Jun 05, 2026 Jun 05, 2026
Jun 05, 2026
Jun 05, 2026
4.8 MEDIUM
CVE-2026-21027 — Samsung ImsSettings: Component Export Leads to Log Triggering

Improper export of android application components in ImsSettings prior to SMR Jun-2026 Release 1 allows local attackers to trigger logging function.

| Information Disclosure
Jun 05, 2026 Jun 05, 2026
Jun 05, 2026
Jun 05, 2026
6.4 MEDIUM
CVE-2026-21026 — SpriteWallpaper Improper Export of Android Application Components Information Disclosure

Improper export of android application components in SpriteWallpaper prior to SMR Jun-2026 Release 1 allows local attackers to access to sensitive information.

| Information Disclosure
Jun 05, 2026 Jun 05, 2026
Jun 05, 2026
Jun 05, 2026
6.9 MEDIUM
CVE-2026-21025 — Telephony Improper Privilege Assignment Information Disclosure

Incorrect privilege assignment in Telephony prior to SMR Jun-2026 Release 1 allows local attackers to access sensitive information.

| Authorization
Jun 05, 2026 Jun 05, 2026
Jun 05, 2026
Jun 05, 2026
4.6 MEDIUM
CVE-2026-21017 — SecTelephonyProvider Insufficient Privileges Local File Access

Improper handling of insufficient privileges in SecTelephonyProvider prior to SMR Jun-2026 Release 1 allows local attackers to access privileged files.

| Authorization
Jun 05, 2026 Jun 05, 2026
Jun 05, 2026
Jun 05, 2026
8.5 HIGH
CVE-2026-11347 — Hardcoded Cryptographic Keys and Weak IV Generation in linqi

The linqi application contains hardcoded cryptographic keys. Additionally, the application uses a weak algorithm with a limited ASCII charset to dynamically generate Initialization Vectors (IVs) for …

| Cryptography
Jun 05, 2026 Jun 05, 2026
Jun 05, 2026
Jun 05, 2026
9.8 CRITICAL
CVE-2026-6274 — Authentication Bypass in DTS Electronics' Redline WR3200

Improper Authentication, Missing authentication for critical function, Weak Authentication vulnerability in DTS Electronics Industry and Trade Ltd. Co. Redline WR3200 allows Accessing Functionality N…

Remote | Authentication
Jun 05, 2026 Jun 05, 2026
Jun 05, 2026
Jun 05, 2026
10.0 CRITICAL
CVE-2026-49777 — WordPress Product Slider Pro for WooCommerce plugin < 3.5.3 - Backdoor vulnerability

Improper Validation of Specified Quantity in Input vulnerability in ShapedPlugin, LLC Product Slider Pro for WooCommerce allows Malicious Software Implanted. This issue affects Product Slider Pro fo…

Remote | Injection
Jun 05, 2026 Jun 05, 2026
Jun 05, 2026
Jun 05, 2026
7.8 HIGH
CVE-2026-11332 — Ansible-core: argument injection in ansible-galaxy role install leads to arbitrary code e…

A flaw was found in ansible-core. The ansible-galaxy role install command processes dependency specifications from a role's meta/requirements.yml file. Due to improper neutralization of argument deli…

Jun 05, 2026 Jun 05, 2026
Jun 05, 2026
Jun 05, 2026
2.7 LOW
CVE-2026-9088 — Keycloak: keycloak: information disclosure due to user profile permission bypass

A flaw was found in org.keycloak.services. An administrator with delegated access to read group memberships and users can bypass user profile permissions by accessing the group members endpoint. This…

build_of_keycloak | Remote | Authorization
Jun 05, 2026 Jun 05, 2026
Jun 05, 2026
Jun 05, 2026
10.0 CRITICAL
CVE-2026-48907 — Joomla Extension - joomlacontenteditor.net - Remote Code Execution in JCE extension for J…

A vulnerability in the JCE editor extension for Joomla allows the creation of new editor profiles for unauthenticated users, ultimately resulting in PHP code upload and execution.

Remote | Authentication
Jun 05, 2026 Jun 05, 2026
Jun 05, 2026
Jun 05, 2026
8.7 HIGH
CVE-2026-21837 — HCL Digital Experience is affected by an OS command injection vulnerability in the Digita…

HCL Digital Experience is affected by an OS command injection vulnerability in the Digital Asset Management API.  An attacker may execute arbitrary operating system commands, typically inheriting the…

digital_experience | Remote | Injection
Jun 05, 2026 Jun 05, 2026
Jun 05, 2026
Jun 05, 2026
6.1 MEDIUM
CVE-2026-21826 — HCL Digital Experience and HCL Digital Experience Compose could be susceptible to Host he…

HCL Digital Experience and HCL Digital Experience Compose could be susceptible to Host header injection.  An attacker can manipulate the Host header and cause the application to behave in unexpected …

Remote | Misconfiguration
Jun 05, 2026 Jun 05, 2026
Jun 05, 2026
Jun 05, 2026
6.1 MEDIUM
CVE-2026-21825 — HCL Digital Experience Compose is affected by a reflected cross-site scripting (XSS) vuln…

HCL Digital Experience Compose is affected by a reflected cross-site scripting (XSS) vulnerability in the search center.  An attacker could execute arbitrary JavaScript in the victim's browser.

Remote | Cross-Site Scripting
Jun 05, 2026 Jun 05, 2026
Jun 05, 2026
Jun 05, 2026
6.4 MEDIUM
CVE-2026-10732 — Decompress Arbitrary File Write via Symlink Race Condition

All versions of the package decompress are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip) when extracting a ZIP archive containing two entries with the same path - the first bei…

Remote | Path Traversal
Jun 05, 2026 Jun 05, 2026
Jun 05, 2026
Jun 05, 2026
7.3 HIGH
CVE-2026-50593 — Graphite Integer Underflow Out-of-Bounds Write

Graphite before 1.3.15 has an integer underflow and resultant out-of-bounds write via Graphite actions, because slotat does not ensure that an offset is within the allowed slot-map range.

graphite | Memory Corruption
Jun 05, 2026 Jun 05, 2026
Jun 05, 2026
Jun 05, 2026
0.0 NA
CVE-2026-7763 — Heap buffer overflow in morse.ko TIM IE processing

A heap-based buffer overflow vulnerability in the morse.ko HaLow Wi-Fi kernel driver in Morse Micro HaLowLink 2 software versions prior to 2.11.13 allows an unauthenticated attacker within radio rang…

halow_link_2 | Memory Corruption
Jun 05, 2026 Jun 05, 2026
Jun 05, 2026
Jun 05, 2026
0.0 NA
CVE-2026-7762 — Heap buffer overflow in dot11ah.ko S1G Capabilities IE processing

A heap-based buffer overflow vulnerability in the dot11ah.ko HaLow Wi-Fi kernel driver in Morse Micro HaLowLink 2 software versions prior to 2.11.13 allows an unauthenticated attacker within radio ra…

halow_link_2 | Memory Corruption
Jun 05, 2026 Jun 05, 2026
Jun 05, 2026
Jun 05, 2026
6.4 MEDIUM
CVE-2026-50592 — Znuny Reflected Cross-Site Scripting

In Znuny LTS before 6.5.21 and Znuny before 7.3.3, there is reflected XSS in AdminCommunicationLog (aka the communication log administration view).

znuny | Remote | Cross-Site Scripting
Jun 05, 2026 Jun 05, 2026
Jun 05, 2026
Jun 05, 2026
Showing 20 of 7247 Results