Total CVEs

138,502

Critical Severity

3,573

High Severity

12,821

Last 7 Days

1,988
Quick preset (or use dates below)
Clear Filters
Showing 1,121 - 1,140 of 13,341 CVEs
CVE-2026-11559 MEDIUM - 6.3

A vulnerability was detected in CodeAstro Payroll System 1.0. This affects an unknown function of the file /view_account.php. The manipulation of the argument ID results in sql injection. The attack may be performed from remote. The exploit is now public and may be used.

Vendor: CodeAstro
Product: Payroll System
Published: Jun 08, 2026
Source: NVD
CVE-2026-11558 MEDIUM - 6.3

A security vulnerability has been detected in CodeAstro Payroll System 1.0. The impacted element is an unknown function of the file /home_salary.php. The manipulation of the argument rate/salary_rate leads to sql injection. The attack is possible to be carried out remotely. The exploit has been disc...

Vendor: CodeAstro
Product: Payroll System
Published: Jun 08, 2026
Source: NVD
CVE-2026-10787 MEDIUM - 4.3

Missing authorization in the deleted user groups API in Devolutions Server allows an authenticated low-privileged user to enumerate metadata of deleted user groups via a crafted API request. This issue affects : * Devolutions Server 2026.2.4.0 * Devolutions Server 2026.1.20.0 and earlier

Vendor: Devolutions
Product: Server
Published: Jun 08, 2026
Source: NVD
CVE-2026-10786 MEDIUM - 6.5

Improper access control in the ticketing integration settings in Devolutions Server allows an authenticated low-privileged user to obtain cleartext credentials for configured ticketing integrations via a crafted API request. This issue affects : * Devolutions Server 2026.2.4.0 * Devolutions ...

Vendor: Devolutions
Product: Server
Published: Jun 08, 2026
Source: NVD
CVE-2026-10544 MEDIUM - 6.5

Improper neutralization of special elements in the built-in PAM provider password rotation templates in Devolutions Server allows an authenticated user with write access to a vault to execute arbitrary commands on the systems managed by the affected PAM provider. This issue affects : * Devoluti...

Vendor: Devolutions
Product: Server
Published: Jun 08, 2026
Source: NVD

Actual is an open-source personal finance application. In the macOS desktop application version 25.x (built on Electron 39.2.7), the ELECTRON_RUN_AS_NODE fuse is not disabled, allowing an attacker who can place a file on disk or control command-line arguments to invoke the signed Actual.app binary w...

Vendor: npm
Product: actual
Published: Jun 08, 2026
Source: GitHub
CVE-2026-11554 MEDIUM - 4.3

A vulnerability was determined in TOTOLINK CP450 4.1.0cu.747. This vulnerability affects unknown code of the file /etc/vsftpd.conf of the component vsftpd. This manipulation causes least privilege violation. The attack may be initiated remotely. The exploit has been publicly disclosed and may be uti...

Vendor: TOTOLINK
Product: CP450
Published: Jun 08, 2026
Source: NVD
CVE-2026-11552 MEDIUM - 5.3

A vulnerability has been found in SourceCodester Onlne Examination & Learning Management System and Syllabus-aligned Learning Management and Examination System 1.0. Affected by this issue is some unknown functionality of the file import_users.php. The manipulation of the argument raw_password wi...

Vendor: SourceCodester
Product: Onlne Examination & Learning Management System, Syllabus-aligned Learning Management and Examination System
Published: Jun 08, 2026
Source: NVD
CVE-2026-41479 MEDIUM - 5.4

Authlib OAuth 2.0 has Open Redirect in Authorization API that allows attacker-controlled redirect_uri through unsupported response_type

Vendor: pip
Product: authlib
Published: Jun 08, 2026
Source: GitHub
CVE-2026-39908 MEDIUM - 6.5

OpenBullet2 through version 0.3.2 on Windows contains a credential disclosure vulnerability that allows remote attackers to capture the NTLMv2 hash of the process user by configuring a job proxy source with a UNC path pointing to an attacker-controlled server. When the job starts, the application at...

Vendor: openbullet
Product: openbullet2
Published: Jun 08, 2026
Source: NVD
CVE-2026-11611 MEDIUM - 6.5

A flaw was found in 389 Directory Server. The Content Synchronization persistent search plugin allows unbounded memory growth when an authenticated client stops reading sync responses, enabling denial of service. Additional race conditions in plugin thread lifecycle can cause crashes during connecti...

Vendor: Red Hat
Product: Red Hat Directory Server 11, Red Hat Directory Server 12, Red Hat Directory Server 13, Red Hat Enterprise Linux 10, Red Hat Enterprise Linux 6, Red Hat Enterprise Linux 7, Red Hat Enterprise Linux 8, Red Hat Enterprise Linux 9
Published: Jun 08, 2026
Source: NVD
CVE-2026-11533 MEDIUM - 5.4

A security vulnerability has been detected in imvks786 student_management_system up to 9599b560ad3c3b83e75d328b76bedcd489ef1f46. Affected by this vulnerability is an unknown functionality of the file /see.php of the component Student Deletion Endpoint. The manipulation of the argument del leads to i...

Vendor: imvks786
Product: student_management_system
Published: Jun 08, 2026
Source: NVD
CVE-2026-11532 MEDIUM - 6.3

A weakness has been identified in imvks786 student_management_system up to 9599b560ad3c3b83e75d328b76bedcd489ef1f46. Affected is an unknown function of the file /add.php of the component Student Record Handler. Executing a manipulation can lead to improper access controls. The attack may be performe...

Vendor: imvks786
Product: student_management_system
Published: Jun 08, 2026
Source: NVD
CVE-2026-46443 MEDIUM - 6.5

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, when credentials are fetched with a credentialName filter parameter, the encryptedData field is not stripped from the response. The code properly omits encryptedData when no filter is...

Vendor: FlowiseAI
Product: Flowise
Published: Jun 08, 2026
Source: NVD
CVE-2026-44119 MEDIUM - 5.5

Improper Privilege Management vulnerability in Apache HTTP Server 2.4.67 and earlier allows local .htaccess authors to read files with the privileges of the httpd user. This issue affects Apache HTTP Server: from through 2.4.67. Users are recommended to upgrade to version 2.4.68, which fixes the i...

Vendor: Apache Software Foundation
Product: Apache HTTP Server
Published: Jun 08, 2026
Source: NVD
CVE-2026-43951 MEDIUM - 6.5

Out-of-bounds Read vulnerability in Apache HTTP Server with mod_headers and mod_mime and multiple response languages. This issue affects Apache HTTP Server: from 2.4.0 through 2.4.67.

Vendor: Apache Software Foundation
Product: Apache HTTP Server
Published: Jun 08, 2026
Source: NVD
CVE-2026-29170 MEDIUM - 6.1

A cross-site scripting vulnerability exists in mod_proxy_ftp's HTML directory list generation in Apache HTTP Server 2.4.67 and earlier when listing FTP directory contents either via forward or reverse proxy configuration. Users are recommended to upgrade to version 2.4.68, which fixes this iss...

Vendor: Apache Software Foundation
Product: Apache HTTP Server
Published: Jun 08, 2026
Source: NVD
CVE-2026-11529 MEDIUM - 6.3

A vulnerability was determined in designcomputer mysql-mcp-server up to 0.2.2. The impacted element is the function read_resource of the file src/mysql_mcp_server/server.py of the component mysql URI Handler. This manipulation of the argument uri_str causes sql injection. Remote exploitation of the ...

Vendor: designcomputer
Product: mysql-mcp-server
Published: Jun 08, 2026
Source: NVD
CVE-2020-37248 MEDIUM - 6.5

OfflineIMAP before 8.0.3 trusts the server with their STARTTLS capability prior to authentication, which allows STRIPTLS/man-in-the-middle attacks, taking over the connection and extracting account credentials in cleartext.

Vendor: OfflineIMAP
Product: OfflineIMAP
Published: Jun 08, 2026
Source: NVD
CVE-2026-25558 MEDIUM - 4.8

QloApps through 1.7.0 contains a stored cross-site scripting vulnerability in the admin file manager that allows authenticated administrators to inject malicious JavaScript by uploading crafted SVG files. Attackers can embed JavaScript event handlers such as onload within SVG files uploaded through ...

Vendor: QloApps
Product: QloApps
Published: Jun 08, 2026
Source: NVD