Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-8212 — OSGeo gdal SWapi.c SWSDfldsrch heap-based overflow

A flaw has been found in OSGeo gdal up to 3.13.0dev-4. Affected by this vulnerability is the function SWSDfldsrch of the file frmts/hdf4/hdf-eos/SWapi.c. Executing a manipulation can lead to heap-bas…

| Memory Corruption
May 09, 2026 May 09, 2026
May 09, 2026
May 09, 2026
6.5 MEDIUM
CVE-2026-45184 — Kdenlive Proxy Parameter Injection Vulnerability

Kdenlive before 26.04.1 allows dangerous proxy parameters when an attacker-controlled project file is used.

| Misconfiguration
May 09, 2026 May 09, 2026
May 09, 2026
May 09, 2026
6.5 MEDIUM
CVE-2026-45181 — Hex-Rays IDA Pro Unrestricted Plugin Directory Access Vulnerability

Hex-Rays IDA Pro 9.2 and 9.3 before 9.3sp2 does not block Clang dependency-file generation (via argument injection), which allows attackers to place their code into a plugins directry if the victim u…

| Injection
May 09, 2026 May 09, 2026
May 09, 2026
May 09, 2026
0.0 NA
CVE-2026-8211 — codelibs Fess JSP File AdminDesignAction.java update code injection

A vulnerability was detected in codelibs Fess up to 15.5.1. Affected by this issue is the function update of the file org/codelibs/fess/app/web/admin/design/AdminDesignAction.java of the component JS…

| Injection
May 09, 2026 May 09, 2026
May 09, 2026
May 09, 2026
2.2 LOW
CVE-2026-45182 — GrapheneOS Quic VPN IP Disclosure

GrapheneOS before 2026050400 allows attackers to discover the real IP address of a VPN user as a consequence of a registerQuicConnectionClosePayload optimization, because an application can let syste…

| Information Disclosure
May 09, 2026 May 09, 2026
May 09, 2026
May 09, 2026
5.3 MEDIUM
CVE-2026-8210 — aandrew-me tgpt Update helper.go helper.Update command injection

A security vulnerability has been detected in aandrew-me tgpt up to 2.11.1 on Linux/macOS. Affected by this vulnerability is the function helper.Update of the file helper.go of the component Update H…

| Injection
May 09, 2026 May 09, 2026
May 09, 2026
May 09, 2026
3.7 LOW
CVE-2026-8196 — JeecgBoot mLogin Endpoint LoginController.java authorization

A flaw has been found in JeecgBoot 3.9.1. The impacted element is an unknown function of the file jeecg-module-system/jeecg-system-biz/src/main/java/org/jeecg/modules/system/controller/LoginControlle…

Remote | Authorization
May 09, 2026 May 09, 2026
May 09, 2026
May 09, 2026
5.0 MEDIUM
CVE-2026-8195 — JeecgBoot SVG File CommonController.java cross site scripting

A vulnerability was detected in JeecgBoot up to 3.9.1. The affected element is an unknown function of the file jeecg-module-system/jeecg-system-biz/src/main/java/org/jeecg/modules/system/controller/C…

Remote | Cross-Site Scripting
May 09, 2026 May 09, 2026
May 09, 2026
May 09, 2026
5.0 MEDIUM
CVE-2026-8194 — osTicket Dispatcher class.dispatcher.php cross-site request forgery

A security vulnerability has been detected in osTicket up to 1.18.3. Impacted is an unknown function of the file include/class.dispatcher.php of the component Dispatcher. The manipulation of the argu…

Remote | Cross-Site Request Forgery
May 09, 2026 May 09, 2026
May 09, 2026
May 09, 2026
8.1 HIGH
CVE-2026-42606 — AzuraCast: Password Reset Poisoning via Untrusted X-Forwarded-Host Header Leads to Accoun…

AzuraCast is a self-hosted, all-in-one web radio management suite. Prior to version 0.23.6, the ApplyXForwarded middleware unconditionally trusts the client-supplied X-Forwarded-Host HTTP header with…

Remote | Information Disclosure
May 09, 2026 May 09, 2026
May 09, 2026
May 09, 2026
8.8 HIGH
CVE-2026-42605 — AzuraCast: Path Traversal in `currentDirectory` Parameter Enables Remote Code Execution v…

AzuraCast is a self-hosted, all-in-one web radio management suite. Prior to version 0.23.6, the currentDirectory request parameter in the Flow.js media upload endpoint (POST /api/station/{station_id}…

Remote | Path Traversal
May 09, 2026 May 09, 2026
May 09, 2026
May 09, 2026
9.3 CRITICAL
CVE-2026-42601 — ArchiveBox Vulnerable to RCE via unvalidated per-crawl config overrides in AddView

ArchiveBox is an open source self-hosted web archiving system. In versions 0.8.6rc0 and prior, the /add/ endpoint (AddView in core/views.py) accepts a config JSON field that gets merged into the craw…

Remote | Injection
May 09, 2026 May 09, 2026
May 09, 2026
May 09, 2026
6.5 MEDIUM
CVE-2026-42576 — apko `DiscoverKeys` has a panic on non-rsa jwks key that causes crash during key discovery

apko allows users to build and publish OCI container images built from apk packages. Prior to version 1.2.7, DiscoverKeys in pkg/apk/apk/implementation.go unconditionally type-asserts JWKS keys as *r…

Remote | Misconfiguration
May 09, 2026 May 09, 2026
May 09, 2026
May 09, 2026
7.5 HIGH
CVE-2026-42575 — apko doesn't verify downloaded apk packages against APKINDEX checksum (package substituti…

apko allows users to build and publish OCI container images built from apk packages. Prior to version 1.2.7, apko verifies the signature on APKINDEX.tar.gz but never compares individually downloaded …

Remote | Misconfiguration
May 09, 2026 May 09, 2026
May 09, 2026
May 09, 2026
7.5 HIGH
CVE-2026-42574 — apko dirFS has a symlink-following path traversal that allows multiple entry points to es…

apko allows users to build and publish OCI container images built from apk packages. From version 0.14.8 to before version 1.2.5, a crafted .apk could install a TypeSymlink tar entry whose target poi…

Remote | Path Traversal
May 09, 2026 May 09, 2026
May 09, 2026
May 09, 2026
9.0 CRITICAL
CVE-2026-42571 — Privilege Escalation Attack affecting Pelican Web UI

Pelican is a platform for creating data federations. From versions 7.21.0 to before 7.21.5, 7.22.0 to before 7.22.3, 7.23.0 to before 7.23.3, and 7.24.0 to before 7.24.2, there is a a privilege escal…

Remote | Authorization
May 09, 2026 May 09, 2026
May 09, 2026
May 09, 2026
9.4 CRITICAL
CVE-2026-42569 — phpvms: /importer authorization bypass causing full database wipe

phpVMS is a PHP application to run and simulate an airline. Prior to version 7.0.6, a critical vulnerability in phpVMS allowed unauthenticated access to a legacy import feature. This issue has been p…

Remote | Authentication
May 09, 2026 May 09, 2026
May 09, 2026
May 09, 2026
8.3 HIGH
CVE-2026-42562 — Plainpad: Privilege Escalation via Writable Admin Field in Profile Update (Access Control)

Plainpad is a self hosted note taking app. Prior to version 1.1.1, Plainpad allows a low-privilege authenticated user to self-escalate to administrator by submitting admin=true in PUT /api.php/v1/use…

Remote | Authorization
May 09, 2026 May 09, 2026
May 09, 2026
May 09, 2026
6.3 MEDIUM
CVE-2026-42333 — quarkus-openapi-generator has overly broad path-parameter matching that sends authenticat…

Quarkus OpenAPI Generator is Quarkus' extensions for generation of Rest Clients and server stubs generation. Prior to versions 2.11.1-lts, 2.16.0-lts, and 2.17.0, the generated authentication filter …

Remote | Authentication
May 09, 2026 May 09, 2026
May 09, 2026
May 09, 2026
5.8 MEDIUM
CVE-2026-42258 — net-imap: Command Injection via unvalidated Symbol inputs

Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.4.24, 0.5.14, and 0.6.4, symbol arguments to commands are vulnerable to a CRLF Injection…

| Injection
May 09, 2026 May 09, 2026
May 09, 2026
May 09, 2026
Showing 20 of 5599 Results