Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.1 HIGH
CVE-2026-40987 — Remote-file synchronizer in Spring Integration writes server-supplied filename under loca…

A malicious or compromised FTP/SFTP/SMB server can write arbitrary files anywhere on the client filesystem (outside the configured local-directory) with attacker-controlled content. Affected version…

spring_integration | Remote | Path Traversal
Jun 11, 2026 Jun 11, 2026
Jun 11, 2026
Jun 11, 2026
4.8 MEDIUM
CVE-2026-40986 — Spring Web Flow JS RemotingHandler renders non-HTML Response as HTML

Spring Web Flow's JavaScript RemotingHandler renders the body of an error response as HTML even when the response is not "text/html", which can result in a scripting attack in the user's browser if t…

Remote | Cross-Site Scripting
Jun 11, 2026 Jun 11, 2026
Jun 11, 2026
Jun 11, 2026
8.1 HIGH
CVE-2026-10795 — UpdraftPlus: WP Backup & Migration Plugin <= 1.26.4 - Unauthenticated Authentication Bypa…

The UpdraftPlus: WP Backup & Migration Plugin plugin for WordPress is vulnerable to Authentication Bypass in all versions up to, and including, 1.26.4 via the UpdraftPlus_Remote_Communications_V2::wp…

updraftplus | Remote | Authentication
Jun 11, 2026 Jun 11, 2026
Jun 11, 2026
Jun 11, 2026
6.4 MEDIUM
CVE-2026-40985 — Data Binding Vulnerability in Spring Web Flow with Unified EL Parser

Applications that configure the WebFlowELExpressionParser are vulnerable to the use of malicious Unified EL expressions. Affected versions: Spring Web Flow 4.0.0; 3.0.0 through 3.0.1; 2.5.0 through …

Remote | Injection
Jun 11, 2026 Jun 11, 2026
Jun 11, 2026
Jun 11, 2026
9.8 CRITICAL
CVE-2026-35273 — Oracle PeopleSoft: Unauthenticated Takeover of Updates Environment Management

Vulnerability in the PeopleSoft Enterprise PeopleTools product of Oracle PeopleSoft (component: Updates Environment Management). Supported versions that are affected are 8.61 and 8.62. Easily exploit…

peoplesoft_enterprise_peopletools | Remote | Authentication
Jun 11, 2026 Jun 11, 2026
Jun 11, 2026
Jun 11, 2026
4.7 MEDIUM
CVE-2026-2827 — Open User Map PRO <= 1.4.31 - Unauthenticated Stored Cross-Site Scripting via 'oum_locati…

The Open User Map PRO plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'oum_location_notification' parameter in versions up to, and including, 1.4.31 due to insufficient inpu…

Remote | Cross-Site Scripting
Jun 11, 2026 Jun 11, 2026
Jun 11, 2026
Jun 11, 2026
6.2 MEDIUM
CVE-2026-53465 — ImageMagick: Heap Buffer Over-Write in SF3 encoder when writing multi-frame image

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-25, a crafted multi-frame can result in a heap buffer over-write when encoding it…

imagemagick | Memory Corruption
Jun 10, 2026 Jun 11, 2026
Jun 10, 2026
Jun 11, 2026
4.0 MEDIUM
CVE-2026-53464 — ImageMagick: Memory Leak in wand option parser when providing invalid arguments

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-25, when providing invalid options to the wand option parser a small memory leak …

imagemagick | Memory Corruption
Jun 10, 2026 Jun 11, 2026
Jun 10, 2026
Jun 11, 2026
4.3 MEDIUM
CVE-2026-53463 — ImageMagick: Null Pointer Dereference in distort operation when passing incorrect argumen…

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-50 and 7.1.2-25, when passing incorrect arguments in the distort operation a nu…

imagemagick | Remote | Memory Corruption
Jun 10, 2026 Jun 11, 2026
Jun 10, 2026
Jun 11, 2026
5.9 MEDIUM
CVE-2026-53462 — ImageMagick: Use-After-Free when allocation in CheckPrimitiveExtent fails

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-50 and 7.1.2-25, when an allocation fails in CheckPrimitiveExtent this can resu…

imagemagick | Remote | Memory Corruption
Jun 10, 2026 Jun 11, 2026
Jun 10, 2026
Jun 11, 2026
7.5 HIGH
CVE-2026-53461 — ImageMagick: Out-of-bounds write in ICON decoder due to incorrect loop

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-50 and 7.1.2-25, an incorrect loop in the ICON decoder can result in an out of …

imagemagick | Remote | Memory Corruption
Jun 10, 2026 Jun 11, 2026
Jun 10, 2026
Jun 11, 2026
7.5 HIGH
CVE-2026-53460 — ImageMagick: Policy Bypass can trigger out-of-Memory condition

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-50 and 7.1.2-25, a missing check for maximum memory request in AcquireAlignedMe…

imagemagick | Remote | Denial of Service
Jun 10, 2026 Jun 11, 2026
Jun 10, 2026
Jun 11, 2026
7.5 HIGH
CVE-2026-52726 — Dulwich's submodule path traversal in porcelain.submodule_update / porcelain.clone(recurs…

Dulwich is a pure-Python implementation of the Git file formats and protocols. Starting in version 0.23.2 and prior to version 1.2.5, `dulwich.porcelain.submodule_update`, and by extension `porcelain…

Remote | Path Traversal
Jun 10, 2026 Jun 11, 2026
Jun 10, 2026
Jun 11, 2026
8.8 HIGH
CVE-2026-50223 — Apache OFBiz: DataResource Low-Privileged Authenticated FreeMarker Template Injection Lea…

Improper Control of Generation of Code ('Code Injection') vulnerability in Apache OFBiz allows a low-privileged authenticated user with Content/DataResource editing privileges to perform template inj…

ofbiz | Remote | Injection
Jun 10, 2026 Jun 11, 2026
Jun 10, 2026
Jun 11, 2026
5.5 MEDIUM
CVE-2026-49219 — ImageMagick: Policy Bypass can read disallowed files

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-24, an incorrect parsing of the filename can result in a policy by…

imagemagick | Path Traversal
Jun 10, 2026 Jun 11, 2026
Jun 10, 2026
Jun 11, 2026
7.5 HIGH
CVE-2026-49218 — ImageMagick: Policy Bypass in DCM decoder could result in image with invalid dimensions

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-24, a missing check in the DCM decoder could result in an image wi…

imagemagick | Remote | Denial of Service
Jun 10, 2026 Jun 11, 2026
Jun 10, 2026
Jun 11, 2026
5.9 MEDIUM
CVE-2026-48994 — ImageMagick: Heap Buffer Over-Write in MAT decoder on 32-bit systems

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-48 and 7.1.2-24, a missing check of a return value could lead to a heap buffer …

imagemagick | Remote | Memory Corruption
Jun 10, 2026 Jun 11, 2026
Jun 10, 2026
Jun 11, 2026
5.5 MEDIUM
CVE-2026-48734 — ImageMagick: Stack Overflow in MVG decoder

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-49 and 7.1.2-24, a crafted MVG file could result in a stack overflow due to a m…

imagemagick | Memory Corruption
Jun 10, 2026 Jun 11, 2026
Jun 10, 2026
Jun 11, 2026
4.7 MEDIUM
CVE-2026-48733 — ImageMagick: Infinite Loop in subimage-search with crafted image

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 6.9.13-49 and 7.1.2-24, an infinite loop in the subimage-search operation can happen w…

imagemagick | Denial of Service
Jun 10, 2026 Jun 11, 2026
Jun 10, 2026
Jun 11, 2026
5.5 MEDIUM
CVE-2026-48724 — ImageMagick: Heap Buffer Underwrite in Floyd-Steinberg depth dithering

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to version 7.1.2-24, when using an image with mask the Floyd-Steinberg dithering method it will ca…

imagemagick | Memory Corruption
Jun 10, 2026 Jun 11, 2026
Jun 10, 2026
Jun 11, 2026
Showing 20 of 7134 Results