Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
3.7 LOW
CVE-2026-48850 — PuTTY RSA KEX Double Free Vulnerability

PuTTY 0.72 before 0.84 has a double free in RSA KEX.

Remote | Memory Corruption
May 25, 2026 May 25, 2026
May 25, 2026
May 25, 2026
0.0 NA
CVE-2026-9498 — Dromara lamp-cloud Message Template GroovyClassLoader.parseClass special elements used in…

A vulnerability has been found in Dromara lamp-cloud up to 5.6.2. Impacted is the function GroovyClassLoader.parseClass of the component Message Template Handler. Such manipulation of the argument De…

| Injection
May 25, 2026 May 25, 2026
May 25, 2026
May 25, 2026
0.0 NA
CVE-2026-9497 — changmingxie tcc-transaction Fastjson AutoType REST API Fastjson.parseObject deserializat…

A flaw has been found in changmingxie tcc-transaction up to 2.1.0. This issue affects the function Fastjson.parseObject of the component Fastjson AutoType REST API. This manipulation causes deseriali…

| Injection
May 25, 2026 May 25, 2026
May 25, 2026
May 25, 2026
4.4 MEDIUM
CVE-2026-48849 — Roundcube Webmail Stored XSS/HTML/CSS Injection

In Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1, an unsanitized subject field in the draft restored value could lead to stored XSS/HTML/CSS injection on shared mailboxes.

Remote | Cross-Site Scripting
May 25, 2026 May 25, 2026
May 25, 2026
May 25, 2026
0.0 NA
CVE-2026-9486 — SourceCodester Student Grades Management System cross-site request forgery

A security flaw has been discovered in SourceCodester Student Grades Management System 1.0. This affects an unknown part. The manipulation results in cross-site request forgery. The attack can be exe…

| Cross-Site Request Forgery
May 25, 2026 May 25, 2026
May 25, 2026
May 25, 2026
7.2 HIGH
CVE-2026-48848 — Roundcube Webmail CSS Injection Vulnerability

Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7 has insufficient HTML sanitization that could lead to Cascading Style Sheets (CSS) injection via an SVG document that has an animate element…

Remote | Cross-Site Scripting
May 25, 2026 May 25, 2026
May 25, 2026
May 25, 2026
5.3 MEDIUM
CVE-2026-24546 — WordPress GamiPress plugin <= 7.6.3 - Broken Access Control vulnerability

Missing Authorization vulnerability in Ruben Garcia GamiPress allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects GamiPress: from n/a through 7.6.3.

Remote | Authorization
May 25, 2026 May 25, 2026
May 25, 2026
May 25, 2026
3.7 LOW
CVE-2026-48847 — Roundcube Webmail Redis/Memcache File Deletion Vulnerability

Roundcube Webmail 1.6.x before 1.6.16, and 1.7.x before 1.7.1 allows pre-authentication arbitrary file deletion via redis/memcache session poisoning bypass.

Remote | Misconfiguration
May 25, 2026 May 25, 2026
May 25, 2026
May 25, 2026
6.5 MEDIUM
CVE-2026-48846 — Roundcube Webmail CSS Injection Vulnerability

In Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1, the remote image blocking feature can be bypassed via a crafted CSS var() value in an e-mail message, which may lead to information di…

Remote | Information Disclosure
May 25, 2026 May 25, 2026
May 25, 2026
May 25, 2026
6.5 MEDIUM
CVE-2026-48845 — Roundcube Webmail Local/Private Image Disclosure Vulnerability

In Roundcube Webmail 1.6.x between 1.6.14 and 1.6.16 and 1.7.x before 1.7.1, remote image blocking was not honored for URLs pointing to local/private destinations, which may lead to information discl…

Remote | Information Disclosure
May 25, 2026 May 25, 2026
May 25, 2026
May 25, 2026
0.0 NA
CVE-2026-9485 — SourceCodester Student Grades Management System students.php cross site scripting

A vulnerability was identified in SourceCodester Student Grades Management System 1.0. Affected by this issue is some unknown functionality of the file students.php. The manipulation of the argument …

| Cross-Site Scripting
May 25, 2026 May 25, 2026
May 25, 2026
May 25, 2026
7.5 HIGH
CVE-2026-48844 — Roundcube Webmail LDAP Code Injection Vulnerability

Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has insecure code evaluation logic in LDAP the autovalues option that could lead to code injection. (Support for code evaluation has been …

Remote | Injection
May 25, 2026 May 25, 2026
May 25, 2026
May 25, 2026
7.2 HIGH
CVE-2026-48843 — Roundcube Webmail CSS Injection Vulnerability

Roundcube Webmail 1.6.x between 1.6.14 and 1.6.16,and 1.7.x before 1.7.1 has Insufficient Cascading Style Sheets (CSS) sanitization in HTML e-mail messages may lead to SSRF or Information Disclosure,…

Remote | Server-Side Request Forgery
May 25, 2026 May 25, 2026
May 25, 2026
May 25, 2026
8.1 HIGH
CVE-2026-48842 — Roundcube Webmail SQL Injection

Roundcube Webmail 1.6.x before 1.6.16 and 1.7.x before 1.7.1 has Pre-authentication SQL injection in the virtuser_query plugin via a preg_replace() backslash escape bypass.

Remote | Injection
May 25, 2026 May 25, 2026
May 25, 2026
May 25, 2026
0.0 NA
CVE-2026-9484 — SourceCodester Student Grades Management System classroom.php removeStudentFromClassroom …

A vulnerability was determined in SourceCodester Student Grades Management System 1.0. Affected by this vulnerability is the function getClassroomStudents/removeStudentFromClassroom of the file class…

| Authorization
May 25, 2026 May 25, 2026
May 25, 2026
May 25, 2026
0.0 NA
CVE-2026-9483 — SourceCodester Student Grades Management System grades.php improper authorization

A vulnerability was found in SourceCodester Student Grades Management System 1.0. Affected is an unknown function of the file grades.php. Performing a manipulation of the argument student_id results …

| Authorization
May 25, 2026 May 25, 2026
May 25, 2026
May 25, 2026
0.0 NA
CVE-2026-9482 — Edimax EW-7438RPn formSDHCP stack-based overflow

A vulnerability has been found in Edimax EW-7438RPn 1.31. This impacts the function formSDHCP of the file /goform/formSDHCP. Such manipulation of the argument submit-url leads to stack-based buffer o…

| Memory Corruption
May 25, 2026 May 25, 2026
May 25, 2026
May 25, 2026
0.0 NA
CVE-2026-9481 — Edimax EW-7438RPn formStats stack-based overflow

A flaw has been found in Edimax EW-7438RPn 1.31. This affects the function formStats of the file /goform/formStats. This manipulation of the argument submit-url causes stack-based buffer overflow. Th…

| Memory Corruption
May 25, 2026 May 25, 2026
May 25, 2026
May 25, 2026
0.0 NA
CVE-2026-9480 — Edimax EW-7438RPn formrefresh stack-based overflow

A vulnerability was detected in Edimax EW-7438RPn 1.31. The impacted element is the function formrefresh of the file /goform/formrefresh. The manipulation of the argument submit-url results in stack-…

| Memory Corruption
May 25, 2026 May 25, 2026
May 25, 2026
May 25, 2026
0.0 NA
CVE-2026-9479 — Edimax EW-7438RPn formLogout stack-based overflow

A security vulnerability has been detected in Edimax EW-7438RPn 1.31. The affected element is the function formLogout of the file /goform/formLogout. The manipulation of the argument submit-url leads…

| Memory Corruption
May 25, 2026 May 25, 2026
May 25, 2026
May 25, 2026
Showing 20 of 5879 Results