Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.5 HIGH
CVE-2026-8370 — Automic Automation Agent Unix privilege escalation

Execution with unnecessary privileges vulnerability in Broadcom Automic Automation Agent Unix on Linux x64, Linux Power 64 BE, Linux Power 64 LE, zLinux (zSeries), AIX, Solaris x64, Solaris Sparc 64 …

| Authorization
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
6.5 MEDIUM
CVE-2026-8096 — Kirki <= 6.0.6 - Missing Authorization to Authenticated (Subscriber+) Sensitive Form Subm…

The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 6.0.6. This is due to the plugin not p…

Remote | Authorization
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
7.5 HIGH
CVE-2026-8073 — Kirki <= 6.0.6 - Unauthenticated Limited Arbitrary File Read and Deletion via downloadZIP

The Kirki – Freeform Page Builder, Website Builder & Customizer plugin for WordPress is vulnerable to arbitrary file deletion due to insufficient file path validation and missing capability check in …

Remote | Path Traversal
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
8.2 HIGH
CVE-2026-41470 — LIVE555 < 2026.04.22 RTSP Server Authorization Bypass via Session Token

LIVE555 before 2026.04.22 contains an authorization bypass vulnerability in RTSP session command handling that allows attackers to replay valid Session tokens from unauthenticated connections. Attack…

Remote | Authorization
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
2.1 LOW
CVE-2026-34154 — Discourse has a subscription access bypass in its discourse-subscriptions plugin

Discourse is an open-source discussion platform. In versions prior to 2026.1.4, 2026.3.1, 2026.4.1 and 2026.5.0-latest.1, a vulnerability in the discourse-subscriptions plugin allows users to gain a…

Remote | Authorization
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
6.8 MEDIUM
CVE-2026-33741 — EspoCRM: Stored XSS via SVG attachment loading same-origin JavaScript

EspoCRM is an open source customer relationship management application. Versions 9.3.3 and below allow authenticated users to upload SVG attachments through normal attachment-capable fields and later…

Remote | Cross-Site Scripting
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
9.9 CRITICAL
CVE-2026-33642 — Kitty has a Heap Buffer Over-Read/Write via Integer Overflow in compose_rectangles Bounds…

Kitty is a cross-platform GPU based terminal. In versions 0.46.2 and below, the handle_compose_command() function in kitty/graphics.c performs bounds validation on composition offsets using unsigned …

Remote | Memory Corruption
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
0.0 NONE
CVE-2026-33637 — Faraday: Protocol-relative URI objects still bypass host scoping (possible incomplete fix…

Faraday is an HTTP client library abstraction layer that provides a common interface over many adapters. Versions 2.0.0 through 2.14.1 still allow protocol-relative host override when the request tar…

Remote | Server-Side Request Forgery
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
6.5 MEDIUM
CVE-2026-32738 — libheif has a Heap OOB Read/SEGV Crash via Zero samples_per_chunk

libheif is a HEIF and AVIF file format decoder and encoder. In versions 1.21.2 and below, a crafted 792-byte HEIF sequence file with samples_per_chunk=0 in the stsc box causes an unsigned integer und…

Remote | Denial of Service
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
5.1 MEDIUM
CVE-2026-8605 — Use of Hard-coded Credentials in ScadaBR

In ScadaBR version 1.2.0, a Use of Hard-Coded Credentials vulnerability could allow an attacker to access the SCADA system as admin.

Remote | Authentication
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
8.6 HIGH
CVE-2026-8604 — Cross-Site request forgery (CSRF) in ScadaBR

In ScadaBR version 1.2.0, a CSRF vulnerability could allow an attacker to trigger any authenticated action through a victim's session by luring any logged-in user to a malicious webpage.

Remote | Cross-Site Request Forgery
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
8.7 HIGH
CVE-2026-8603 — Improper neutralization of special elements used in an OS command ('OS command injection'…

In ScadaBR version 1.2.0, an OS Command Injection vulnerability could allow an attacker to execute commands as root on the SCADA system.

Remote | Injection
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
8.8 HIGH
CVE-2026-8602 — Missing authentication for critical function in ScadaBR

In ScadaBR version 1.2.0, a Missing Authentication for Critical Function vulnerability could allow an unauthenticated attacker to send a HTTP GET requests to the SCADA system and inject arbitrary sen…

Remote | Authentication
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
8.7 HIGH
CVE-2026-6009 — Jaspersoft Library Deserialisation Vulnerability

Java Deserialisation Vulnerability in Jaspersoft Reports Library leads to Remote Code Execution (RCE), potentially allowing code execution on the affected system

Remote | Injection
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
9.6 CRITICAL
CVE-2026-47107 — Windmill < 1.703.2 Incorrect Default Permissions in nsjail Configuration

Windmill prior to 1.703.2 contains an incorrect default permissions vulnerability in nsjail sandbox configuration files where /etc is bind-mounted without read-write restrictions, allowing authentica…

Remote | Misconfiguration
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
7.5 HIGH
CVE-2026-33633 — Kitty has a Heap Buffer Overflow in its Graphics Protocol Handler

Kitty is a cross-platform GPU based terminal. Versions 0.46.2 and below contain a heap buffer overflow in load_image_data() that allows any process which can write to the terminal's stdin to crash ki…

Remote | Memory Corruption
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
5.9 MEDIUM
CVE-2026-32134 — NanoMQ: NULL Pointer Dereference Crash in tcptran_pipe_peer During Session Restore

NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. In versions 0.24.10 and below, when NanoMQ handles high-concurrency reconnect traffic using a reconnect-collision payload, the br…

Remote | Denial of Service
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
7.5 HIGH
CVE-2025-61081 — BYD Atto3 Authentication Key Disclosure

In BYD Atto3, an attacker can obtain an authentication key through Brute Force attack, which is permanently available. The authentication key enables flash to the Electronic Parking Break (EPB) and S…

| Authentication
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
4.6 MEDIUM
CVE-2026-5511 — Information Disclosure via Diagnostic Interface Due to Improper Input Validation on TP-Li…

In the web management interface of Archer AX72 (SG) v1, the network diagnostic feature improperly handles invalid user input, resulting in limited exposure of diagnostic command usage information.  …

| Information Disclosure
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
9.3 CRITICAL
CVE-2026-47358 — Terrascan Server-Side Request Forgery (SSRF)

Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via external URL resolution in uploaded IaC templates when running in server mode. When Terrascan parses uploaded ARM …

| Server-Side Request Forgery
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
Showing 20 of 6367 Results