Total CVEs

138,714

Critical Severity

3,596

High Severity

12,883

Last 7 Days

1,746
Quick preset (or use dates below)
Clear Filters
๐Ÿ“… Showing Year: 2026 (January 1 - December 31, 2026) View All Years โ†’
Showing 1,621 - 1,640 of 13,053 CVEs
CVE-2026-10860 MEDIUM - 6.5

A logic error in the MISP CRUD component delete handler allowed validation failures to be bypassed when requests used the HTTP DELETE method. Due to missing parentheses in the delete condition, the expression was evaluated as ($validationError === null && POST) || DELETE, meaning a DELETE re...

Vendor: misp
Product: misp
Published: Jun 04, 2026
Source: NVD
CVE-2026-10811 MEDIUM - 6.3

A security vulnerability has been detected in itsourcecode Fees Management System 1.0. Affected by this vulnerability is an unknown functionality of the file /receipt.php. Such manipulation of the argument ef_id leads to sql injection. The attack may be performed from remote. The exploit has been di...

Vendor: itsourcecode
Product: Fees Management System
Published: Jun 04, 2026
Source: NVD
CVE-2026-45057 MEDIUM - 4.9

matrix-sdk-ui: Incomplete edit validation

Vendor: rust
Product: matrix-sdk-ui
Published: Jun 04, 2026
Source: GitHub

Matrix Rust SDK: Sender-binding gaps in to-device and room-key attribution

Vendor: rust
Product: matrix-sdk-crypto
Published: Jun 04, 2026
Source: GitHub
CVE-2026-47707 MEDIUM - 5.3

Strawberry GraphQL is a library for creating GraphQL APIs. In versions 0.172.0 through0.315.6, the MaxAliasesLimiter extension in Strawberry fails to account for the multiplicative/amplification effect of FragmentSpreadNode. While it correctly counts static aliases within the AST it does not conside...

Vendor: pip
Product: strawberry-graphql
Published: Jun 04, 2026
Source: GitHub
CVE-2026-47706 MEDIUM - 5.3

Strawberry GraphQL is a library for creating GraphQL APIs. In versions 0.71.0 through 0.315.6, the QueryDepthLimiter extension is vulnerable to an Application-level DOS due to a lack of cycle detection in fragment spreads. When a query contains circular fragment references the determine_depth functi...

Vendor: pip
Product: strawberry-graphql
Published: Jun 04, 2026
Source: GitHub

Doorkeeper Openid Connect: Dynamic Client Registration feature creates public clients with client_secret

Vendor: rubygems
Product: doorkeeper-openid_connect
Published: Jun 04, 2026
Source: GitHub
CVE-2026-44889 MEDIUM - 6.1

WebOb provides objects for HTTP requests and responses. Prior to 1.8.10, the normalization of the HTTP Location header during a redirect is vulnerable to an open redirect: WebOb joins the redirect target to the request URI using Python's urljoin, and since Python 3.10 the underlying urlsplit st...

Vendor: pip
Product: webob
Published: Jun 04, 2026
Source: GitHub
CVE-2026-10861 MEDIUM - 6.1

An open redirect vulnerability existed in MISP UsersController::routeafterlogin() because the value stored in the pre_login_requested_url session key was used as the post-login redirect destination without sufficiently enforcing that it was a local application path. An unauthenticated remote att...

Vendor: misp
Product: misp
Published: Jun 04, 2026
Source: NVD
CVE-2026-10856 MEDIUM - 6.1

A URL validation flaw in the MISP dashboard button widget allowed a crafted relative-looking URL to be accepted as a local path while being interpreted by browsers as an external URL. The validation rejected URLs containing an explicit scheme, host, or user component, but did not reject paths beginn...

Vendor: misp
Product: misp
Published: Jun 04, 2026
Source: NVD
CVE-2026-10855 MEDIUM - 4.3

An authorization flaw existed in the MISP Event Template Importer overwrite workflow. When importing an event template in overwrite mode, the application checked whether a matching template already existed but did not verify that the importing user belonged to the organization that owned the existin...

Vendor: misp
Product: misp
Published: Jun 04, 2026
Source: NVD
CVE-2026-10854 MEDIUM - 4.3

A visibility control issue in the event template creation workflow allowed non-site-admin users to access private galaxies belonging to other organisations. The event template builder loaded all enabled galaxies without applying organisation or distribution-based access restrictions, potentially exp...

Vendor: misp
Product: misp
Published: Jun 04, 2026
Source: NVD
CVE-2026-10810 MEDIUM - 4.3

A weakness has been identified in itsourcecode Fees Management System up to 1.0. Affected is an unknown function of the file /navbar.php. This manipulation of the argument page causes cross site scripting. The attack is possible to be carried out remotely. The exploit has been made available to the ...

Vendor: itsourcecode
Product: Fees Management System
Published: Jun 04, 2026
Source: NVD
CVE-2026-10809 MEDIUM - 6.3

A security flaw has been discovered in itsourcecode Fees Management System 1.0. This impacts an unknown function of the file /manage_user.php. The manipulation of the argument ID results in sql injection. The attack can be executed remotely. The exploit has been released to the public and may be use...

Vendor: itsourcecode
Product: Fees Management System
Published: Jun 04, 2026
Source: NVD
CVE-2026-10808 MEDIUM - 6.3

A vulnerability was identified in itsourcecode Fees Management System 1.0. This affects an unknown function of the file /manage_student.php. The manipulation of the argument ID leads to sql injection. Remote exploitation of the attack is possible. The exploit is publicly available and might be used.

Vendor: itsourcecode
Product: Fees Management System
Published: Jun 04, 2026
Source: NVD
CVE-2026-10807 MEDIUM - 6.3

A vulnerability was determined in mjperpinosa stumasy. The impacted element is an unknown function of the file application/PHP/objects/profiles/change_profile_image.php. Executing a manipulation of the argument pr_profile_image can lead to unrestricted upload. The attack may be launched remotely. Th...

Vendor: mjperpinosa
Product: stumasy
Published: Jun 04, 2026
Source: NVD
CVE-2026-10806 MEDIUM - 6.3

A vulnerability was found in mjperpinosa stumasy. The affected element is an unknown function of the file application/PHP/objects/updates/add_post.php. Performing a manipulation of the argument up_file_to_post results in unrestricted upload. The attack may be initiated remotely. The exploit has been...

Vendor: mjperpinosa
Product: stumasy
Published: Jun 04, 2026
Source: NVD
CVE-2019-25744 MEDIUM - 6.4

WordPress Popup Builder 3.49 contains a persistent cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by breaking out of option tags in the post_title parameter. Attackers can submit crafted POST requests to the post.php endpoint with script payloads i...

Vendor: Popup-Builder
Product: Popup Builder
Published: Jun 04, 2026
Source: NVD
CVE-2019-25743 MEDIUM - 6.4

WordPress Soliloquy Lite 2.5.6 contains a persistent cross-site scripting vulnerability that allows authenticated attackers to inject malicious scripts by inserting script tags in the post title field. Attackers can submit POST requests to the post editing endpoint with script payloads in the post_t...

Vendor: Soliloquywp
Product: Soliloquy Lite
Published: Jun 04, 2026
Source: NVD
CVE-2019-25742 MEDIUM - 6.4

WordPress Theme Zoner Real Estate 4.1.1 contains a persistent cross-site scripting vulnerability that allows authenticated agents to inject malicious scripts through the Address input field when creating properties. Attackers can inject JavaScript payloads in the property creation form that execute ...

Vendor: Fruitfulcode
Product: Zoner Real Estate
Published: Jun 04, 2026
Source: NVD