Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
10.0 CRITICAL
CVE-2026-42822 — Azure Local Disconnected Operations (ALDO) Elevation of Privilege Vulnerability

Improper authentication in Azure Local Disconnected Operations allows an unauthorized attacker to elevate privileges over a network.

May 18, 2026 May 21, 2026
May 18, 2026
May 21, 2026
9.1 CRITICAL
CVE-2023-24215 — NOVUS AirGate 4G Unauthenticated Administrator Credential Disclosure

Incorrect access control in the /uci/get/ endpoint of NOVUS AirGate 4G firmware v1.1.16 allows unauthenticated attackers to obtain administrator credentials via a crafted POST request.

Remote | Authorization
May 18, 2026 May 19, 2026
May 18, 2026
May 19, 2026
10.0 CRITICAL
CVE-2026-45829 — ChromaDB Remote Code Injection Vulnerability

A pre-authentication, code injection vulnerability in version 1.0.0 or later of the ChromaDB Python project allows an unauthenticated attacker to run arbitrary code on the server by sending a malicio…

chromadb | Remote | Injection
May 18, 2026 May 19, 2026
May 18, 2026
May 19, 2026
9.4 CRITICAL
CVE-2026-41948 — Dify v1.14.1 Path Traversal via Plugin Daemon Internal API Access

Dify version 1.14.1 and prior contain a path traversal vulnerability that allows authenticated users to manipulate requests forwarded to the Plugin Daemon's internal REST API by exploiting insufficie…

dify dify | Remote | Path Traversal
May 18, 2026 May 26, 2026
May 18, 2026
May 26, 2026
9.3 CRITICAL
CVE-2026-41947 — Dify < 1.14.2 Authorization Bypass via Trace Configuration Endpoints

Dify before version 1.14.2 contains an authorization bypass vulnerability that allows authenticated editor users to set and enable trace configurations for any application regardless of tenant owners…

dify dify | Remote | Authorization
May 18, 2026 May 26, 2026
May 18, 2026
May 26, 2026
9.8 CRITICAL
CVE-2026-7304 — CVE-2026-7304

SGLangs multimodal generation runtime is vulnerable to unauthenticated remote code execution when the --enable-custom-logit-processor option is enabled, as Python objects loaded via dill.loads() will…

sglang | Remote | Authentication
May 18, 2026 May 19, 2026
May 18, 2026
May 19, 2026
9.1 CRITICAL
CVE-2026-7302 — CVE-2026-7302

SGLangs multimodal generation runtime is vulnerable to an unauthenticated path traversal vulnerability, allowing an attacker to write arbitrary files anywhere the server process has write access, by …

sglang | Remote | Path Traversal
May 18, 2026 May 19, 2026
May 18, 2026
May 19, 2026
9.8 CRITICAL
CVE-2026-7301 — CVE-2026-7301

SGLangs multimodal generation runtime scheduler's ROUTER socket binds to 0.0.0.0 by default and contains a sink that calls pickle.loads() on incoming messages, enabling RCE when exposed to the intern…

sglang | Remote | Information Disclosure
May 18, 2026 May 19, 2026
May 18, 2026
May 19, 2026
9.3 CRITICAL
CVE-2026-4320 — Authorization Bypass in ICMS Content Management by Creartia Internet Consulting

Authorization Bypass vulnerability in Creartia's ICMS software could allow an attacker to gain unauthorized access to protected features by manipulating the HTTP redirect headers of the login process…

Remote | Authorization
May 18, 2026 May 18, 2026
May 18, 2026
May 18, 2026
Showing 20 of 749 Results