Security Intelligence
Feed

Real-time CVE tracking, exploit analysis, and vulnerability intelligence curated for security professionals.

279 New today
66,699 Total advisories
Live Monitoring

Daily Security Trends (Last 14 Days)

464
Jun 17
3
Jun 18
352
Jun 19
56
Jun 20
104
Jun 21
317
Jun 22
294
Jun 23
355
Jun 24
376
Jun 25
386
Jun 26
53
Jun 27
318
Jun 28
279
Jun 29
Jun 30
Critical
High
Medium
Low

Recent Advisories

Severity ID Title Vendor Product Date Type
HIGH 7.5 CVE-2026-46604

Panic decoding image with out-of-bounds strip offset in x/image/tiff in golang.org/x/image_CVE-2026-46604

The TIFF decoder can panic when decoding an invalid image with an out-of-bounds strip offset.

golang.org/x/image golang.org/x/image/tiff CVE
MEDIUM 5.4 CVE-2026-50767

CVE-2026-50767_CVE-2026-50767

A stored cross-site scripting (XSS) vulnerability in the item type administration page of Koha Library Management System through 25.11 allows an au...

n/a n/a n/a CVE
MEDIUM 5.4 CVE-2026-50766

CVE-2026-50766_CVE-2026-50766

A stored cross-site scripting (XSS) vulnerability in the OPAC item detail page of Koha Library Management System through 25.11 allows an authentica...

n/a n/a n/a CVE
MEDIUM 6.1 CVE-2026-50765

CVE-2026-50765_CVE-2026-50765

Cross-Site Scripting (XSS) vulnerability in the patron restriction type administration page of Koha Library Management System through 25.11 allows ...

n/a n/a n/a CVE
MEDIUM 5.5 CVE-2026-36908

CVE-2026-36908_CVE-2026-36908

A stack overflow in the AP4_Array::EnsureCapacity component of axiomatic-systems Bento4 before v1.8.9allows attackers to cause a Denial of Service ...

n/a n/a n/a CVE
MEDIUM 5.5 CVE-2026-36907

CVE-2026-36907_CVE-2026-36907

A stack overflow in the AP4_StsdAtom::AP4_StsdAtom component of axiomatic-systems Bento4 before v1.8.9allows attackers to cause a Denial of Service...

n/a n/a n/a CVE
MEDIUM 4.8 CVE-2026-9677

Shariff for WordPress <= 1.0.11 - Admin+ Stored Cross-Site Scripting_CVE-2026-9677

The Shariff for WordPress Shariff for WordPress plugin through 1.0.11 does not sanitize or escape the shariff_infourl setting before outputting it ...

Unknown Shariff for WordPress CVE
HIGH 8.1 CVE-2026-10820

ProfilePress < 4.16.17 - Subscriber+ Subscription Cancellation via IDOR_CVE-2026-10820

The Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content WordPress plugin before 4.16.17 does no...

Unknown Paid Membership Plugin, Ecommerce, User Registration Form, Login Form, User Profile & Restrict Content CVE
HIGH 7 CVE-2026-49417

Multiple vulnerabilities in the sound(4) mmap path_CVE-2026-49417

Second, the audio buffer backing a mapping could be freed when the device was closed even though the mapping remained valid. The freed memory coul...

FreeBSD FreeBSD 15.0-RELEASE CVE