Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.9 MEDIUM
CVE-2026-21033 — Samsung Assistant: ExpressHomeWidgetReceiver Component Export Vulnerability

Improper export of android application components in ExpressHomeWidgetReceiver of Samsung Assistant prior to version 9.3.14 allows local attacker to execute arbitrary script.

assistant | Authentication
Jun 05, 2026 Jun 05, 2026
Jun 05, 2026
Jun 05, 2026
6.9 MEDIUM
CVE-2026-21032 — Samsung Assistant: Intent Redirection Vulnerability

Improper export of android application components in SmartHomeWidgetReceiver of Samsung Assistant prior to version 9.3.14 allows local attacker to execute arbitrary script.

assistant | Authentication
Jun 05, 2026 Jun 05, 2026
Jun 05, 2026
Jun 05, 2026
5.2 MEDIUM
CVE-2026-21031 — AppBlock Improper Authorization Local Activity Launch

Improper authorization in AppBlock prior to SMR Jun-2026 Release 1 allows local attacker to launch arbitrary activity. User interaction is required for triggering this vulnerability.

| Authorization
Jun 05, 2026 Jun 05, 2026
Jun 05, 2026
Jun 05, 2026
6.4 MEDIUM
CVE-2026-21030 — MediaTek Audio HAL Access Control Vulnerability

Improper access control in MediaTek Audio HAL prior to SMR Jun-2026 Release 1 allows local attackers to trigger privileged functions.

| Authorization
Jun 05, 2026 Jun 05, 2026
Jun 05, 2026
Jun 05, 2026
6.8 MEDIUM
CVE-2026-21029 — Samsung Galaxy Editing Service Component Export Vulnerability

Improper export of android application components in Galaxy Editing Service prior to SMR Jun-2026 Release 1 allows local attacker to execute privileged operations.

| Authentication
Jun 05, 2026 Jun 05, 2026
Jun 05, 2026
Jun 05, 2026
5.1 MEDIUM
CVE-2026-21028 — SAP AuditLogService Improper Access Control Information Disclosure

Improper access control in AuditLogService prior to SMR Jun-2026 Release 1 allows local attackers to access sensitive information.

| Authorization
Jun 05, 2026 Jun 05, 2026
Jun 05, 2026
Jun 05, 2026
4.8 MEDIUM
CVE-2026-21027 — Samsung ImsSettings: Component Export Leads to Log Triggering

Improper export of android application components in ImsSettings prior to SMR Jun-2026 Release 1 allows local attackers to trigger logging function.

| Information Disclosure
Jun 05, 2026 Jun 05, 2026
Jun 05, 2026
Jun 05, 2026
6.4 MEDIUM
CVE-2026-21026 — SpriteWallpaper Improper Export of Android Application Components Information Disclosure

Improper export of android application components in SpriteWallpaper prior to SMR Jun-2026 Release 1 allows local attackers to access to sensitive information.

| Information Disclosure
Jun 05, 2026 Jun 05, 2026
Jun 05, 2026
Jun 05, 2026
6.9 MEDIUM
CVE-2026-21025 — Telephony Improper Privilege Assignment Information Disclosure

Incorrect privilege assignment in Telephony prior to SMR Jun-2026 Release 1 allows local attackers to access sensitive information.

| Authorization
Jun 05, 2026 Jun 05, 2026
Jun 05, 2026
Jun 05, 2026
4.6 MEDIUM
CVE-2026-21017 — SecTelephonyProvider Insufficient Privileges Local File Access

Improper handling of insufficient privileges in SecTelephonyProvider prior to SMR Jun-2026 Release 1 allows local attackers to access privileged files.

| Authorization
Jun 05, 2026 Jun 05, 2026
Jun 05, 2026
Jun 05, 2026
8.5 HIGH
CVE-2026-11347 — Hardcoded Cryptographic Keys and Weak IV Generation in linqi

The linqi application contains hardcoded cryptographic keys. Additionally, the application uses a weak algorithm with a limited ASCII charset to dynamically generate Initialization Vectors (IVs) for …

| Cryptography
Jun 05, 2026 Jun 05, 2026
Jun 05, 2026
Jun 05, 2026
9.8 CRITICAL
CVE-2026-6274 — Authentication Bypass in DTS Electronics' Redline WR3200

Improper Authentication, Missing authentication for critical function, Weak Authentication vulnerability in DTS Electronics Industry and Trade Ltd. Co. Redline WR3200 allows Accessing Functionality N…

Remote | Authentication
Jun 05, 2026 Jun 05, 2026
Jun 05, 2026
Jun 05, 2026
10.0 CRITICAL
CVE-2026-49777 — WordPress Product Slider Pro for WooCommerce plugin < 3.5.3 - Backdoor vulnerability

Improper Validation of Specified Quantity in Input vulnerability in ShapedPlugin, LLC Product Slider Pro for WooCommerce allows Malicious Software Implanted. This issue affects Product Slider Pro fo…

Remote | Injection
Jun 05, 2026 Jun 05, 2026
Jun 05, 2026
Jun 05, 2026
7.8 HIGH
CVE-2026-11332 — Ansible-core: argument injection in ansible-galaxy role install leads to arbitrary code e…

A flaw was found in ansible-core. The ansible-galaxy role install command processes dependency specifications from a role's meta/requirements.yml file. Due to improper neutralization of argument deli…

Jun 05, 2026 Jun 05, 2026
Jun 05, 2026
Jun 05, 2026
2.7 LOW
CVE-2026-9088 — Keycloak: keycloak: information disclosure due to user profile permission bypass

A flaw was found in org.keycloak.services. An administrator with delegated access to read group memberships and users can bypass user profile permissions by accessing the group members endpoint. This…

build_of_keycloak | Remote | Authorization
Jun 05, 2026 Jun 05, 2026
Jun 05, 2026
Jun 05, 2026
10.0 CRITICAL
CVE-2026-48907 — Joomla Extension - joomlacontenteditor.net - Remote Code Execution in JCE extension for J…

A vulnerability in the JCE editor extension for Joomla allows the creation of new editor profiles for unauthenticated users, ultimately resulting in PHP code upload and execution.

Remote | Authentication
Jun 05, 2026 Jun 05, 2026
Jun 05, 2026
Jun 05, 2026
8.7 HIGH
CVE-2026-21837 — HCL Digital Experience is affected by an OS command injection vulnerability in the Digita…

HCL Digital Experience is affected by an OS command injection vulnerability in the Digital Asset Management API.  An attacker may execute arbitrary operating system commands, typically inheriting the…

digital_experience | Remote | Injection
Jun 05, 2026 Jun 05, 2026
Jun 05, 2026
Jun 05, 2026
6.1 MEDIUM
CVE-2026-21826 — HCL Digital Experience and HCL Digital Experience Compose could be susceptible to Host he…

HCL Digital Experience and HCL Digital Experience Compose could be susceptible to Host header injection.  An attacker can manipulate the Host header and cause the application to behave in unexpected …

Remote | Misconfiguration
Jun 05, 2026 Jun 05, 2026
Jun 05, 2026
Jun 05, 2026
6.1 MEDIUM
CVE-2026-21825 — HCL Digital Experience Compose is affected by a reflected cross-site scripting (XSS) vuln…

HCL Digital Experience Compose is affected by a reflected cross-site scripting (XSS) vulnerability in the search center.  An attacker could execute arbitrary JavaScript in the victim's browser.

Remote | Cross-Site Scripting
Jun 05, 2026 Jun 05, 2026
Jun 05, 2026
Jun 05, 2026
6.4 MEDIUM
CVE-2026-10732 — Decompress Arbitrary File Write via Symlink Race Condition

All versions of the package decompress are vulnerable to Arbitrary File Write via Archive Extraction (Zip Slip) when extracting a ZIP archive containing two entries with the same path - the first bei…

Remote | Path Traversal
Jun 05, 2026 Jun 05, 2026
Jun 05, 2026
Jun 05, 2026
Showing 20 of 7244 Results