Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
4.9 MEDIUM
CVE-2026-56131 — Expat XML_ResumeParser Use-After-Free Vulnerability

libexpat before 2.8.2 lacks handler call depth tracking for calls to XML_ResumeParser from within handlers in cases of a policy violation. Thus, a use-after-free can occur (similar to the CVE-2026-50…

libexpat | Memory Corruption
Jun 19, 2026 Jun 19, 2026
Jun 19, 2026
Jun 19, 2026
8.7 HIGH
CVE-2026-8806 — Denial-of-service (DoS) vulnerability in MELSEC iQ-F Series FX5-ENET/IP Ethernet module

Expected Behavior Violation vulnerability in Mitsubishi Electric MELSEC iQ-F Series FX5-ENET/IP Ethernet Module FX5-ENET/IP all versions allows a remote attacker to cause a denial-of-service (DoS) co…

Remote | Denial of Service
Jun 19, 2026 Jun 19, 2026
Jun 19, 2026
Jun 19, 2026
4.3 MEDIUM
CVE-2026-11775 — User Admin Simplifier <= 3.0.0 - Cross-Site Request Forgery

The User Admin Simplifier plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 3.0.0. This is due to missing or incorrect nonce validation on the use…

Remote | Cross-Site Request Forgery
Jun 19, 2026 Jun 19, 2026
Jun 19, 2026
Jun 19, 2026
8.7 HIGH
CVE-2026-8805 — Denial-of-service (DoS) vulnerability in MELSEC iQ-F Series EtherNet/IP module

Integer Overflow or Wraparound vulnerability in the EtherNet/IP function of Mitsubishi Electric MELSEC iQ-F Series FX5-EIP EtherNet/IP module FX5-EIP versions 1.000 and prior allows a remote attacker…

Remote | Denial of Service
Jun 19, 2026 Jun 19, 2026
Jun 19, 2026
Jun 19, 2026
0.0 NA
CVE-2025-62821 — Microsoft HEIF Image Extensions Out-of-Bounds Read

Microsoft HEIF Image Extensions 1.2.22.0 has an out-of-bounds read because CHEIFItemInfoEntry_GetDataSize can return success while leaving the reported data size as 0. This causes a caller to make a …

| Memory Corruption
Jun 19, 2026 Jun 19, 2026
Jun 19, 2026
Jun 19, 2026
0.0 NA
CVE-2026-51845 — Tenda AC7 Stack Buffer Overflow

Tenda AC7 v15.03.06.44 contains a stack buffer overflow vulnerability in the /goform/AdvSetMacMtuWan interface via the mac parameter.

| Memory Corruption
Jun 19, 2026 Jun 19, 2026
Jun 19, 2026
Jun 19, 2026
0.0 NA
CVE-2026-51843 — Tenda AC7 Stack Buffer Overflow

Tenda AC7 v15.03.06.44 contains a stack buffer overflow vulnerability in the /goform/AdvSetMacMtuWan interface via the wanMTU parameter.

| Memory Corruption
Jun 19, 2026 Jun 19, 2026
Jun 19, 2026
Jun 19, 2026
0.0 NA
CVE-2026-51844 — Tenda AC7 Stack Buffer Overflow

Tenda AC7 v15.03.06.44 contains a stack buffer overflow vulnerability in the /goform/AdvSetMacMtuWan interface via the cloneType parameter.

| Memory Corruption
Jun 19, 2026 Jun 19, 2026
Jun 19, 2026
Jun 19, 2026
0.0 NA
CVE-2026-51846 — Tenda AC7 Stack Buffer Overflow

In Tenda AC7 v15.03.06.44, the wanSpeed parameter of the route /goform/AdvSetMacMtuWan has a stack buffer overflow vulnerability that can lead to remote arbitrary code execution.

| Memory Corruption
Jun 19, 2026 Jun 19, 2026
Jun 19, 2026
Jun 19, 2026
9.8 CRITICAL
CVE-2026-40624 — AVer PTC cameras Files or Directories Accessible to External Parties

Improper input validation in AVer PTC500S, PTC115, PTC500+, and PTC115+ cameras may allow a remote, unauthenticated attacker to achieve arbitrary code execution via a specially crafted web request.

Remote | Injection
Jun 18, 2026 Jun 18, 2026
Jun 18, 2026
Jun 18, 2026
7.1 HIGH
CVE-2026-50034 — Apollo Pharmacy Blood Glucose Monitoring System APG-01 BT Cleartext Transmission of Sensi…

An attacker within BLE communication range can passively intercept wireless traffic and obtain sensitive health-related information, including glucose measurement values.

| Information Disclosure
Jun 18, 2026 Jun 18, 2026
Jun 18, 2026
Jun 18, 2026
7.1 HIGH
CVE-2026-52866 — Apollo Pharmacy Blood Glucose Monitoring System APG-01 BT Missing Authorization

An attacker within BLE communication range can monopolize the device's only available BLE connection slot, preventing legitimate users or applications from establishing a connection.

| Denial of Service
Jun 18, 2026 Jun 18, 2026
Jun 18, 2026
Jun 18, 2026
5.3 MEDIUM
CVE-2026-12049 — pgAdmin 4: Open redirect in multi-factor authentication flow via unvalidated 'next' param…

Open redirect in pgAdmin 4's multi-factor authentication flow. The MFA validate and register endpoints honoured the user-supplied 'next' query/form parameter without confirming the target pointed bac…

pgadmin_4 | Remote | Misconfiguration
Jun 18, 2026 Jun 18, 2026
Jun 18, 2026
Jun 18, 2026
9.3 CRITICAL
CVE-2026-12048 — pgAdmin 4: Stored XSS via untrusted error and plan-node text rendered through html-react-…

Stored cross-site scripting in pgAdmin 4's error-rendering and plan-node-rendering paths. Text returned by a PostgreSQL server (ErrorResponse messages, including object names quoted back inside relat…

pgadmin_4 | Remote | Cross-Site Scripting
Jun 18, 2026 Jun 18, 2026
Jun 18, 2026
Jun 18, 2026
4.8 MEDIUM
CVE-2026-12047 — pgAdmin 4: HTML injection in cloud verify_credentials / deploy endpoints via unsanitised …

HTML injection in pgAdmin 4's cloud deployment module. The verify_credentials, deploy, regions, and update-server endpoints under /rds/, /azure/, /google/, and the top-level /cloud/ blueprint propaga…

pgadmin_4 | Remote | Cross-Site Scripting
Jun 18, 2026 Jun 18, 2026
Jun 18, 2026
Jun 18, 2026
9.5 CRITICAL
CVE-2026-12046 — pgAdmin 4: Unauthenticated pickle deserialization in SQL Editor close / update_connection…

Two state-mutating endpoints in pgAdmin 4's SQL Editor blueprint -- DELETE /sqleditor/close/<trans_id> and POST /sqleditor/initialize/sqleditor/update_connection/<sgid>/<sid>/<did> -- were the only r…

pgadmin_4 | Remote | Authentication
Jun 18, 2026 Jun 18, 2026
Jun 18, 2026
Jun 18, 2026
9.4 CRITICAL
CVE-2026-12045 — pgAdmin 4: AI Assistant read-only transaction bypass allows unauthorised writes and remot…

Read-only transaction bypass in the pgAdmin 4 AI Assistant allows an attacker who can influence database content that the assistant reads to execute arbitrary SQL with the privileges of the pgAdmin u…

pgadmin_4 | Remote | Injection
Jun 18, 2026 Jun 18, 2026
Jun 18, 2026
Jun 18, 2026
5.3 MEDIUM
CVE-2026-12050 — pgAdmin 4: SQL injection in named restore point endpoint

SQL injection in pgAdmin 4's named restore point endpoint (POST /browser/server/restore_point/{gid}/{sid}). The user-supplied 'value' field was interpolated directly into the SQL string with str.form…

pgadmin_4 | Remote | Injection
Jun 18, 2026 Jun 18, 2026
Jun 18, 2026
Jun 18, 2026
8.8 HIGH
CVE-2026-12044 — pgAdmin 4: SQL injection in COMMENT ON ... IS '<description>' rendering across dialog tem…

SQL injection in pgAdmin 4 across every dialog template that renders ``COMMENT ON ... IS '<description>'`` for a user-supplied description field. The Jinja templates for Domains (and their constraint…

pgadmin_4 | Remote | Injection
Jun 18, 2026 Jun 18, 2026
Jun 18, 2026
Jun 18, 2026
8.8 HIGH
CVE-2026-56078 — PraisonAI - Arbitrary File Read and Write via Path Traversal in MultiAgentMonitor

PraisonAI before 1.5.115 contains a path traversal vulnerability in MultiAgentMonitor that fails to sanitize agent IDs when building file paths. Attackers can include traversal sequences like ../ in …

praisonai | Remote | Path Traversal
Jun 18, 2026 Jun 18, 2026
Jun 18, 2026
Jun 18, 2026
Showing 20 of 7584 Results