Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.2 HIGH
CVE-2026-44487 — Axios: Proxy-Authorization Credential Leak to Origin Server Across HTTP-to-HTTPS Redirect…

Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios’s Node.js HTTP adapter may forward a Proxy-Authorization header to a redirected origin during speci…

axios | Remote | Misconfiguration
Jun 11, 2026 Jun 11, 2026
Jun 11, 2026
Jun 11, 2026
7.5 HIGH
CVE-2026-44486 — Axios: Proxy-Authorization header leaks to redirect target when proxy is re-evaluated to …

Axios is a promise based HTTP client for the browser and Node.js. Prior to 0.32.0 and 1.16.0, Axios’ Node.js HTTP adapter can leak proxy credentials to a redirect target in affected versions. When a …

axios | Remote | Misconfiguration
Jun 11, 2026 Jun 11, 2026
Jun 11, 2026
Jun 11, 2026
6.4 MEDIUM
CVE-2026-11945 — PostgreSQL Anonymizer: SQL injection in the rules import functions

PostgreSQL Anonymizer contains a vulnerability that allows a user to gain superuser privileges by creating a JSON document and placing malicious code inside a particular key-value pair. If a superuse…

| Injection
Jun 11, 2026 Jun 11, 2026
Jun 11, 2026
Jun 11, 2026
9.1 CRITICAL
CVE-2026-9648 — CVE-2026-9648

The crypton-x509-validation Haskell library fails to enforce X.509 NameConstraints, allowing TLS clients to accept certificates whose Subject Alternative Names fall outside the issuing CA’s permitted…

Remote | Misconfiguration
Jun 11, 2026 Jun 11, 2026
Jun 11, 2026
Jun 11, 2026
8.8 HIGH
CVE-2026-7870 — IBM i is Affected by Privilege Escalation []

IBM i 7.6, 7.5, 7.4, and 7.3 could allow a user to gain elevated privileges due to an unqualified library call. A malicious actor could cause user-controlled code to run with administrator privilege.

i i | Remote | Authorization
Jun 11, 2026 Jun 11, 2026
Jun 11, 2026
Jun 11, 2026
7.5 HIGH
CVE-2026-7787 — Unauthenticated Session History Access via Public Flow Execution

IBM Langflow OSS 1.0.0 through 1.9.1 could allow an authenticated user to read or modify sensitive information by bypassing authentication using insecure direct object references.

langflow_oss | Remote | Authentication
Jun 11, 2026 Jun 11, 2026
Jun 11, 2026
Jun 11, 2026
8.6 HIGH
CVE-2026-53777 — Perry < 0.5.1159 Path Traversal via ArtifactReady WebSocket

Perry before 0.5.1159 contains a path traversal vulnerability that allows a malicious build server to write arbitrary content to any location writable by the running process by supplying unsanitized …

Remote | Path Traversal
Jun 11, 2026 Jun 11, 2026
Jun 11, 2026
Jun 11, 2026
6.5 MEDIUM
CVE-2026-4096 — A vulnerability has been identified in IBM DevOps Plan that allows a Host Header Injectio…

IBM DevOps Plan 3.0.0 through 3.0.6 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against…

devops_plan | Remote | Injection
Jun 11, 2026 Jun 11, 2026
Jun 11, 2026
Jun 11, 2026
5.4 MEDIUM
CVE-2026-3341 — IBM Langflow Desktop 1.0.0 - 1.9.2 DNS Rebinding Bypasses SSRF Protection Allowing Access…

IBM Langflow Desktop 1.0.0 through 1.9.2 IBM Langflow is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, pote…

langflow_desktop | Remote | Server-Side Request Forgery
Jun 11, 2026 Jun 11, 2026
Jun 11, 2026
Jun 11, 2026
9.9 CRITICAL
CVE-2026-11839 — Arbitrary File Upload in Basarsoft's Rotaban

Unrestricted upload of file with dangerous type vulnerability in Başarsoft Information Technologies Inc. Rotaban allows Upload a Web Shell to a Web Server. This issue affects Rotaban: from V2026.06.…

Remote | Misconfiguration
Jun 11, 2026 Jun 11, 2026
Jun 11, 2026
Jun 11, 2026
4.1 MEDIUM
CVE-2024-45636 — IBM Security QRadar EDR Software has a vulnerability where user credentials may be stored…

IBM Security QRadar EDR 3.12 through 3.12.24 stores user credentials in plain text which can be read by a local privileged user.

security_qradar_edr | Information Disclosure
Jun 11, 2026 Jun 11, 2026
Jun 11, 2026
Jun 11, 2026
7.1 HIGH
CVE-2026-8406 — openSIS Classic 9.3 - Insecure Direct Object Reference in Sent Mail

openSIS Classic 9.3 contains an insecure direct object reference vulnerability in the messaging module. Any authenticated user with access to the messaging module can request sent-message details fro…

Remote | Authorization
Jun 11, 2026 Jun 11, 2026
Jun 11, 2026
Jun 11, 2026
4.9 MEDIUM
CVE-2026-6338 — HTTP request smuggling in Kong Enteprise Gateway

A HTTP request smuggling and desynchronization vulnerability affects Kong Gateway Enterprise 3.4, 3.10, 3.11, 3.12, 3.13, and 3.14 series. The vulnerability is caused by a parsing flaw in Kong’s HTTP…

Remote | Misconfiguration
Jun 11, 2026 Jun 11, 2026
Jun 11, 2026
Jun 11, 2026
5.8 MEDIUM
CVE-2026-53723 — guzzlehttp/guzzle-services' XML Request Serialization Vulnerable to XML Injection via CDA…

Guzzle Services provides an implementation of the Guzzle Command library that uses Guzzle service descriptions to describe web services, serialize requests, and parse responses into easy to use model…

Remote | Injection
Jun 11, 2026 Jun 11, 2026
Jun 11, 2026
Jun 11, 2026
8.8 HIGH
CVE-2026-53661 — boruta-server sent sensitive session cookies without the Secure attribute

Boruta is a standalone authorization server that aims to implement OAuth 2.0 and Openid Connect up to decentralized identity specifications. Prior to version 0.9.1, boruta session cookies and the ide…

Remote | Authorization
Jun 11, 2026 Jun 11, 2026
Jun 11, 2026
Jun 11, 2026
9.8 CRITICAL
CVE-2026-38581 — Damasac thaipalliative_lte SQL Injection

SQL Injection vulnerability in damasac thaipalliative_lte through version 3.0 allows remote attackers to execute arbitrary SQL commands via the idFormMain parameter to /substudy/ezform.php (line 14) …

Remote | Injection
Jun 11, 2026 Jun 11, 2026
Jun 11, 2026
Jun 11, 2026
8.1 HIGH
CVE-2026-11816 — Path Traversal in keras-team/keras

Keras versions prior to 3.14.0 are vulnerable to a path traversal issue in the archive extraction utilities located in `keras/src/utils/file_utils.py`. The functions `filter_safe_tarinfos()` and `fil…

Remote | Path Traversal
Jun 11, 2026 Jun 11, 2026
Jun 11, 2026
Jun 11, 2026
7.8 HIGH
CVE-2026-10847 — Local Privilege Escalation vulnerability in Check Point Identity Agent Full for Windows OS

A local privilege escalation vulnerability exists in Check Point Identity Agent Full for Windows OS. An authenticated local user may be able to execute arbitrary code with SYSTEM privileges due to im…

identity_agent | Authorization
Jun 11, 2026 Jun 11, 2026
Jun 11, 2026
Jun 11, 2026
9.8 CRITICAL
CVE-2026-7852 — Unrestricted File Upload in Limatek's LimRAD NAC

Unrestricted upload of file with dangerous type vulnerability in Limatek System Inc. LimRAD NAC allows Remote Code Inclusion. This issue affects LimRAD NAC: before 5.5.7.3.9.

Remote | Misconfiguration
Jun 11, 2026 Jun 11, 2026
Jun 11, 2026
Jun 11, 2026
5.3 MEDIUM
CVE-2026-49214 — guzzlehttp/psr7 has CRLF Injection via URI Host Component

guzzlehttp/psr7 is a PSR-7 HTTP message library implementation in PHP. Versions prior to 2.10.2 did not reject ASCII control characters, whitespace, or DEL in first-party URI host components. A vulne…

Remote | Misconfiguration
Jun 11, 2026 Jun 11, 2026
Jun 11, 2026
Jun 11, 2026
Showing 20 of 7069 Results