Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.4 CRITICAL
CVE-2026-41242 — protobufjs has an arbitrary code execution issue

protobufjs compiles protobuf definitions into JavaScript (JS) functions. In versions prior to 8.0.1 and 7.5.5, attackers can inject arbitrary code in the "type" fields of protobuf definitions, which …

protobufjs | Remote | Injection
Apr 18, 2026 Apr 18, 2026
Apr 18, 2026
Apr 18, 2026
9.8 CRITICAL
CVE-2026-40494 — SAIL has heap buffer overflow in TGA RLE decoder — raw packet path missing bounds check

SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. Prior to commit 45d48d1f2e8e0d73e80bc1fd5310cb57f4547302, the TGA codec's RLE de…

sail | Remote | Memory Corruption
Apr 18, 2026 Apr 18, 2026
Apr 18, 2026
Apr 18, 2026
9.8 CRITICAL
CVE-2026-40493 — SAIL has heap buffer overflow in PSD decoder — bpp mismatch in LAB 16-bit mode

SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. Prior to commit c930284445ea3ff94451ccd7a57c999eca3bc979, the PSD codec computes…

sail | Remote | Memory Corruption
Apr 18, 2026 Apr 18, 2026
Apr 18, 2026
Apr 18, 2026
9.8 CRITICAL
CVE-2026-40492 — SAIL has heap buffer overflow in XWD decoder — bits_per_pixel vs pixmap_depth type confus…

SAIL is a cross-platform library for loading and saving images with support for animation, metadata, and ICC profiles. Prior to commit 36aa5c7ec8a2bb35f6fb867a1177a6f141156b02, the XWD codec resolves…

sail | Remote | Memory Corruption
Apr 18, 2026 Apr 18, 2026
Apr 18, 2026
Apr 18, 2026
9.0 CRITICAL
CVE-2026-40572 — NovumOS has Arbitrary Memory Mapping via Syscall 15 (MemoryMapRange)

NovumOS is a custom 32-bit operating system written in Zig and x86 Assembly. In versions prior to 0.24, Syscall 15 (MemoryMapRange) allows Ring 3 user-mode processes to map arbitrary virtual address …

| Memory Corruption
Apr 18, 2026 Apr 18, 2026
Apr 18, 2026
Apr 18, 2026
9.3 CRITICAL
CVE-2026-40317 — NovumOS has Privilege Escalation in the Syscall Interface

NovumOS is a custom 32-bit operating system written in Zig and x86 Assembly. In versions prior to 0.24, Syscall 12 (JumpToUser) accepts an arbitrary entry point address from user-space registers with…

| Authentication
Apr 18, 2026 Apr 18, 2026
Apr 18, 2026
Apr 18, 2026
9.1 CRITICAL
CVE-2026-40582 — ChurchCRM: Authentication Bypass in `/api/public/user/login` Allows Bypass of 2FA and Acc…

ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the /api/public/user/login endpoint validates only the username and password before returning the user's API key, byp…

churchcrm | Remote | Authentication
Apr 18, 2026 Apr 18, 2026
Apr 18, 2026
Apr 18, 2026
9.1 CRITICAL
CVE-2026-40484 — ChurchCRM: Authenticated Remote Code Execution via Unrestricted PHP File Write in Databas…

ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the database backup restore functionality extracts uploaded archive contents and copies files from the Images/ direct…

churchcrm | Remote | Path Traversal
Apr 18, 2026 Apr 18, 2026
Apr 18, 2026
Apr 18, 2026
9.1 CRITICAL
CVE-2026-40324 — Hot Chocolate's Utf8GraphQLParser has Stack Overflow via Deeply Nested GraphQL Documents

Hot Chocolate is an open-source GraphQL server. Prior to versions 12.22.7, 13.9.16, 14.3.1, and 15.1.14, Hot Chocolate's recursive descent parser `Utf8GraphQLParser` has no recursion depth limit. A c…

Remote | Denial of Service
Apr 18, 2026 Apr 18, 2026
Apr 18, 2026
Apr 18, 2026
9.0 CRITICAL
CVE-2026-40478 — Improper neutralization of specific syntax patterns for unauthorized expressions in Thyme…

Thymeleaf is a server-side Java template engine for web and standalone environments. Versions 3.1.3.RELEASE and prior contain a security bypass vulnerability in the the expression execution mechanism…

thymeleaf | Remote | Injection
Apr 17, 2026 Apr 17, 2026
Apr 17, 2026
Apr 17, 2026
9.0 CRITICAL
CVE-2026-40477 — Improper restriction of the scope of accessible objects in Thymeleaf expressions

Thymeleaf is a server-side Java template engine for web and standalone environments. Versions 3.1.3.RELEASE and prior contain a security bypass vulnerability in the expression execution mechanisms. A…

thymeleaf | Remote | Injection
Apr 17, 2026 Apr 17, 2026
Apr 17, 2026
Apr 17, 2026
9.8 CRITICAL
CVE-2026-40351 — FastGPT: NoSQL Injection in loginByPassword leads to Authentication Bypass

FastGPT is an AI Agent building platform. In versions prior to 4.14.9.5, the password-based login endpoint uses TypeScript type assertion without runtime validation, allowing an unauthenticated attac…

fastgpt | Remote | Injection
Apr 17, 2026 Apr 17, 2026
Apr 17, 2026
Apr 17, 2026
9.1 CRITICAL
CVE-2026-40258 — Gramps Web API has Zip Slip Path Traversal in Media Archive Import

The Gramps Web API is a Python REST API for the genealogical research software Gramps. Versions 1.6.0 through 3.11.0 have a path traversal vulnerability (Zip Slip) in the media archive import feature…

Remote | Path Traversal
Apr 17, 2026 Apr 17, 2026
Apr 17, 2026
Apr 17, 2026
9.4 CRITICAL
CVE-2026-23500 — Dolibarr: OS Command Injection (RCE) via MAIN_ODT_AS_PDF configuration

Dolibarr is an enterprise resource planning (ERP) and customer relationship management (CRM) software package. In versions prior to 23.0.0 , the ODT to PDF conversion process in odf.php concatenates …

dolibarr_erp\/crm | Remote | Injection
Apr 17, 2026 Apr 17, 2026
Apr 17, 2026
Apr 17, 2026
9.9 CRITICAL
CVE-2026-40342 — Firebird: Path Traversal + Arbitrary File Write Leads to Remote Code Execution

Firebird is an open-source relational database management system. In versions prior to 5.0.4, 4.0.7 and 3.0.14, the external engine plugin loader concatenates a user-supplied engine name into a files…

firebird | Remote | Path Traversal
Apr 17, 2026 Apr 17, 2026
Apr 17, 2026
Apr 17, 2026
9.8 CRITICAL
CVE-2026-35546 — Anviz Products Missing Authentication for Critical Function

Anviz CX2 Lite and CX7 are vulnerable to unauthenticated firmware uploads. This causes crafted archives to be accepted, enabling attackers to plant and execute code and obtain a reverse shell.

Remote | Authentication
Apr 17, 2026 Apr 17, 2026
Apr 17, 2026
Apr 17, 2026
9.3 CRITICAL
CVE-2026-32105 — xrdp: RDP MAC signature (dataSignature) never verified on receive — integrity bypass in n…

xrdp is an open source RDP server. In versions through 0.10.5, xrdp does not implement verification for the Message Authentication Code (MAC) signature of encrypted RDP packets when using the "Classi…

xrdp | Remote | Cryptography
Apr 17, 2026 Apr 17, 2026
Apr 17, 2026
Apr 17, 2026
9.1 CRITICAL
CVE-2026-40525 — OpenViking Authentication Bypass via VikingBot OpenAPI

OpenViking prior to commit c7bb167 contains an authentication bypass vulnerability in the VikingBot OpenAPI HTTP route surface where the authentication check fails open when the api_key configuration…

openviking | Remote | Authentication
Apr 17, 2026 Apr 17, 2026
Apr 17, 2026
Apr 17, 2026
9.3 CRITICAL
CVE-2026-6284 — Horner Automation Cscape and XL4, XL7 PLC Weak password requirements

An attacker with network access to the PLC is able to brute force discover passwords to gain unauthorized access to systems and services. The limited password complexity and no password input limiter…

cscape | Remote | Authentication
Apr 17, 2026 Apr 17, 2026
Apr 17, 2026
Apr 17, 2026
9.8 CRITICAL
CVE-2026-37749 — CodeAstro Simple Attendance Management System SQL Injection

A SQL injection vulnerability in CodeAstro Simple Attendance Management System v1.0 allows remote unauthenticated attackers to bypass authentication via the username parameter in index.php.

Remote | Injection
Apr 17, 2026 Apr 17, 2026
Apr 17, 2026
Apr 17, 2026
Showing 20 of 743 Results