Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.1 MEDIUM
CVE-2026-25699 — Apache Answer: Authorization Bypass in Timeline API

Exposure of Private Personal Information to an Unauthorized Actor vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. Timeline-related APIs lacked proper authorization …

answer | Remote | Authorization
Jun 09, 2026 Jun 09, 2026
Jun 09, 2026
Jun 09, 2026
6.1 MEDIUM
CVE-2026-25688 — Apache Answer: XSS in AI Answer Rendering

Improper Neutralization of Alternate XSS Syntax vulnerability in Apache Answer. This issue affects Apache Answer: through 2.0.0. AI-generated response content was rendered in the browser without pr…

answer | Remote | Cross-Site Scripting
Jun 09, 2026 Jun 09, 2026
Jun 09, 2026
Jun 09, 2026
8.8 HIGH
CVE-2026-11616 — Events Calendar for GeoDirectory <= 2.3.28 - Authenticated (Subscriber+) Privilege Escala…

The Events Calendar for GeoDirectory plugin for WordPress is vulnerable to Privilege Escalation in versions up to and including 2.3.28. This is due to the ajax_ayi_action() handler only applying str…

Remote | Authorization
Jun 09, 2026 Jun 09, 2026
Jun 09, 2026
Jun 09, 2026
9.1 CRITICAL
CVE-2009-10007 — Catalyst::Plugin::Authentication versions before 0.10_027 for Perl is susceptible to sess…

Catalyst::Plugin::Authentication versions before 0.10_027 for Perl is susceptible to session fixation attacks. Catalyst::Plugin::Authentication does not automatically change the session id after aut…

Remote | Authentication
Jun 09, 2026 Jun 09, 2026
Jun 09, 2026
Jun 09, 2026
9.8 CRITICAL
CVE-2026-9698 — DBI versions before 1.648 for Perl saved errors in a limited-sized buffer

DBI versions before 1.648 for Perl saved errors in a limited-sized buffer. Error messages that were returned when RaiseError, PrintError or HandleError were set were written to a 200-byte buffer wit…

dbi | Remote | Memory Corruption
Jun 09, 2026 Jun 09, 2026
Jun 09, 2026
Jun 09, 2026
7.6 HIGH
CVE-2026-5068 — bt: l2cap le coc: remote oob write via seg counter stored in net_buf user_data

A remote, unauthenticated BLE peer can trigger a 2-byte out-of-bounds write in the Bluetooth host during L2CAP LE CoC SDU reassembly. When the application enables segmentation (via chan_ops.alloc_buf…

zephyr | Memory Corruption
Jun 09, 2026 Jun 09, 2026
Jun 09, 2026
Jun 09, 2026
8.7 HIGH
CVE-2026-44083 — QuMagie

An authorization bypass through user-controlled key vulnerability has been reported to affect QuMagie. The remote attackers can then exploit the vulnerability to gain unintended privileges. We have …

qumagie | Remote | Authorization
Jun 09, 2026 Jun 09, 2026
Jun 09, 2026
Jun 09, 2026
2.4 LOW
CVE-2026-41986 — ACME File System Logic Bypass Denial of Service

Logic bypass vulnerability in the file system. Impact: Successful exploitation of this vulnerability may affect availability.

harmonyos | Authorization
Jun 09, 2026 Jun 09, 2026
Jun 09, 2026
Jun 09, 2026
5.1 MEDIUM
CVE-2026-41985 — Package Management Module Use-After-Free Vulnerability

UAF vulnerability in the package management module. Impact: Successful exploitation of this vulnerability may affect service integrity.

harmonyos | Memory Corruption
Jun 09, 2026 Jun 09, 2026
Jun 09, 2026
Jun 09, 2026
5.2 MEDIUM
CVE-2026-41984 — Vendor Package Manager Use-After-Free

UAF vulnerability in the package management module. Impact: Successful exploitation of this vulnerability may affect service integrity.

harmonyos | Memory Corruption
Jun 09, 2026 Jun 09, 2026
Jun 09, 2026
Jun 09, 2026
4.3 MEDIUM
CVE-2026-41983 — Browser Kernel DoS Vulnerability

DoS vulnerability in the browser kernel. Impact: Successful exploitation of this vulnerability may affect availability.

harmonyos | Remote | Denial of Service
Jun 09, 2026 Jun 09, 2026
Jun 09, 2026
Jun 09, 2026
6.4 MEDIUM
CVE-2026-41982 — [Vendor] IPC Module Race Condition Denial-of-Service

Race condition vulnerability in the IPC module. Impact: Successful exploitation of this vulnerability may affect availability.

harmonyos | Remote | Race Condition
Jun 09, 2026 Jun 09, 2026
Jun 09, 2026
Jun 09, 2026
5.3 MEDIUM
CVE-2026-41981 — IPC Module Out-of-Bounds Write Vulnerability

Out-of-bounds write vulnerability in the IPC module. Impact: Successful exploitation of this vulnerability may affect availability.

harmonyos | Memory Corruption
Jun 09, 2026 Jun 09, 2026
Jun 09, 2026
Jun 09, 2026
5.0 MEDIUM
CVE-2026-41977 — Log Service Denial of Service Vulnerability

DoS vulnerability in the log service. Impact: Successful exploitation of this vulnerability may affect availability.

emui harmonyos | Denial of Service
Jun 09, 2026 Jun 09, 2026
Jun 09, 2026
Jun 09, 2026
6.6 MEDIUM
CVE-2026-41976 — Google Android Audio Framework Information Disclosure

Permission control vulnerability in the audio framework. Impact: Successful exploitation of this vulnerability may affect service confidentiality.

emui harmonyos | Authorization
Jun 09, 2026 Jun 09, 2026
Jun 09, 2026
Jun 09, 2026
3.6 LOW
CVE-2026-41974 — ServiceNow Notification Permission Control Vulnerability

Permission control vulnerability in service notifications. Impact: Successful exploitation of this vulnerability may affect availability.

emui harmonyos | Authorization
Jun 09, 2026 Jun 09, 2026
Jun 09, 2026
Jun 09, 2026
5.9 MEDIUM
CVE-2026-41973 — Veeam Agent for Linux Access Control Vulnerability

Permission control vulnerability in calls. Impact: Successful exploitation of this vulnerability may affect availability.

emui harmonyos | Authorization
Jun 09, 2026 Jun 09, 2026
Jun 09, 2026
Jun 09, 2026
5.4 MEDIUM
CVE-2026-41972 — SMS App Path Traversal

Path traversal vulnerability in the SMS app. Impact: Successful exploitation of this vulnerability may affect availability.

harmonyos | Remote | Path Traversal
Jun 09, 2026 Jun 09, 2026
Jun 09, 2026
Jun 09, 2026
5.1 MEDIUM
CVE-2025-62858 — QTS, QuTS hero

A buffer overflow vulnerability has been reported to affect several QNAP operating system versions. If a remote attacker gains an administrator account, they can then exploit the vulnerability to mod…

quts_hero qts qts | Remote | Memory Corruption
Jun 09, 2026 Jun 09, 2026
Jun 09, 2026
Jun 09, 2026
3.5 LOW
CVE-2026-8981 — Lazy Blocks < 4.3.0 - Admin+ Stored XSS via Custom Block Frontend HTML

The Custom Block Builder WordPress plugin before 4.3.0 does not consistently check the unfiltered_html capability across all paths that write to its block template code fields, allowing administrato…

lazy_blocks | Remote | Authorization
Jun 09, 2026 Jun 09, 2026
Jun 09, 2026
Jun 09, 2026
Showing 20 of 7410 Results