CVE Vulnerability Database

Search and browse 437 known security vulnerabilities. Filter by severity, vendor, product, and year.

437 vulnerabilities found
CVE-2026-48850
3.7 low

PuTTY 0.72 before 0.84 has a double free in RSA KEX.

Putty Putty May 25, 2026
CVE-2026-9485
3.5 low

A vulnerability was identified in SourceCodester Student Grades Management System 1.0. Affected by this issue is some unknown functionality of the file students.php. The manipulation of the argument Remarks leads to cross site scripting. Remote exploitation of the attack is possible. The exploit is

May 25, 2026
CVE-2026-48847
3.7 low

Roundcube Webmail 1.6.x before 1.6.16, and 1.7.x before 1.7.1 allows pre-authentication arbitrary file deletion via redis/memcache session poisoning bypass.

May 25, 2026
CVE-2026-9471
3.5 low

A vulnerability was detected in yashpokharna2555 StudentManagementSystem cb2f558ddf8d19396de0f92abf2d224d46a0a203. This impacts an unknown function of the file /student.php. Performing a manipulation of the argument FIRST_NAME results in cross site scripting. The attack can be initiated remotely. Th

May 25, 2026
CVE-2026-9414
3.5 low

A security flaw has been discovered in SourceCodester Indian Invoicing System up to 0.x/1.0. The impacted element is an unknown function of the file /Invoicing/add_order.php of the component Invoice Template Render Database-Backed. The manipulation of the argument customer_name results in cross site

May 25, 2026
CVE-2026-48832
3.5 low

action/cookie.php in ecrire in SPIP before 4.4.15 is prone to an open redirect vulnerability.

May 24, 2026
CVE-2026-7837
3.7 low

A time-of-check time-of-use (TOCTOU) condition in the ad_flush function in Netatalk 3.0.0 through 4.4.2 involves root-privileged file operations, which may allow a remote attacker to cause limited data modification under specific race conditions.

May 21, 2026
CVE-2026-44075
3.7 low

A missing break statement in DSI OpenSession processing in Netatalk 1.5.0 through 4.4.2 causes a DSIOPT_ATTNQUANT switch case to fall through into DSIOPT_SERVQUANT, resulting in unintended session option handling that may allow a remote attacker to cause a minor service disruption via crafted DSI se

May 21, 2026
CVE-2026-44074
3.7 low

Netatalk 2.1.0 through 4.4.2 combines multiple errno values using bitwise OR, resulting in incorrect error codes when multiple error conditions occur simultaneously, which may allow a remote attacker to cause a minor service disruption via conditions that trigger incorrect error-handling paths.

May 21, 2026
CVE-2026-44071
3.7 low

Netatalk 3.1.2 through 4.4.2 is compiled without FORTIFY_SOURCE, which disables built-in buffer overflow detection at runtime, potentially allowing a remote attacker to cause a minor denial of service via memory errors that would otherwise be caught and safely terminated by runtime protection.

May 21, 2026
CVE-2026-44057
3.1 low

A dead bounds check in the Spotlight RPC unmarshaller in Netatalk 3.0.0 through 4.4.2 results in an unreachable code path that provides no effective bounds protection, which may allow a remote authenticated attacker to obtain limited information via crafted Spotlight RPC requests.

May 21, 2026
CVE-2026-7836
3.1 low

An incorrect calculation in the hextoint macro in Netatalk 2.0.0 through 4.4.2 due to improper uppercase character handling allows a remote authenticated attacker to cause limited data modification via crafted hexadecimal input.

May 21, 2026
CVE-2026-7835
3.1 low

A format string argument mismatch in Netatalk 3.0.3 through 4.4.2 allows a remote authenticated attacker to cause a minor denial of service via crafted input that triggers incorrect format string processing.

May 21, 2026
CVE-2026-44072
3.0 low

Netatalk 2.2.1 through 4.4.2 calls system() after a failed chdir() without properly handling the error condition, which allows a local privileged user to execute unintended commands or cause a minor service disruption under specific conditions.

May 21, 2026
CVE-2026-44070
3.1 low

An unbounded memory reallocation in the charset conversion code in Netatalk 2.0.0 through 4.4.2 allows a remote authenticated attacker to cause a minor denial of service via crafted character conversion requests.

May 21, 2026
CVE-2026-44069
3.9 low

An integer underflow in the volxlate function in Netatalk 3.0.0 through 4.4.2 allows a local privileged user to obtain limited information, modify limited data, or cause a minor service disruption via crafted volume translation input.

May 21, 2026
CVE-2026-47782
3.3 low

Android App "RoboForm Password Manager" provided by Siber Systems, Inc. handles Android intents without sufficient URL validation, user confirmation nor notification. If a URL to some malicious web page is given through an intent, RoboForm may silently download files without user confirmation nor no

May 20, 2026
CVE-2025-31985
3.7 low

HCL BigFix Service Management (SM) is affected by a security misconfiguration due to a missing or insecure “X-Content-Type-Options” header. This could allow browsers to perform MIME-type sniffing, potentially causing malicious content to be interpreted and executed incorrectly.

Hcltech Bigfix Service Management May 20, 2026
CVE-2026-45232
3.1 low

Rsync versions before 3.4.3 contain an off-by-one out-of-bounds stack write vulnerability in the establish_proxy_connection() function in socket.c that allows network attackers to corrupt stack memory by sending a malformed HTTP proxy response. Attackers can exploit this by positioning themselves be

Samba Rsync May 20, 2026
CVE-2026-8492
2.7 low

Modification of Assumed-Immutable Data (MAID) vulnerability in Drupal Translate Drupal with GTranslate allows Resource Location Spoofing. This issue affects Translate Drupal with GTranslate: from 0.0.0 before 3.0.5.

May 19, 2026
CVE-2026-8491
3.7 low

Improper Check for Unusual or Exceptional Conditions vulnerability in Drupal Node View Permissions allows Forceful Browsing. This issue affects Node View Permissions: from 0.0.0 before 1.7.0, from 2.0.0 before 2.0.1.

May 19, 2026
CVE-2026-33565
3.3 low

in OpenHarmony v6.0 and prior versions allow a local attacker cause DOS.

May 19, 2026
CVE-2026-28751
3.3 low

in OpenHarmony v6.0 and prior versions allow a local attacker cause DOS.

May 19, 2026
CVE-2026-27781
3.3 low

in OpenHarmony v6.0 and prior versions allow a local attacker cause DOS.

May 19, 2026