Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.7 HIGH
CVE-2026-6351 — Openfind|MailGates/MailAudit - CRLF Injection

MailGates/MailAudit developed by Openfind has a CRLF Injection vulnerability, allowing unauthenticated remote attackers to exploit this vulnerability to read system files.

Remote | Injection
Apr 16, 2026 Apr 16, 2026
Apr 16, 2026
Apr 16, 2026
7.4 HIGH
CVE-2026-41015 — Radare2 Unix Command Injection Vulnerability

radare2 before 9236f44, when configured on UNIX without SSL, allows command injection via a PDB name to rabin2 -PP. NOTE: although users are supposed to use the latest version from git (not a release…

| Injection
Apr 16, 2026 Apr 16, 2026
Apr 16, 2026
Apr 16, 2026
9.8 CRITICAL
CVE-2026-6350 — Openfind|MailGates/MailAudit - Stack-based Buffer Overflow

MailGates/MailAudit developed by Openfind has a Stack-based Buffer Overflow vulnerability, allowing unauthenticated remote attackers to control the program's execution flow and execute arbitrary code.

Remote | Memory Corruption
Apr 16, 2026 Apr 16, 2026
Apr 16, 2026
Apr 16, 2026
0.0 NA
CVE-2026-3885 — WP Shortcodes Plugin — Shortcodes Ultimate <= 7.4.9 - Authenticated (Contributor+) Stored…

The WP Shortcodes Plugin — Shortcodes Ultimate plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'su_box' shortcode in all versions up to, and including, 7.4.9 due to…

| Cross-Site Scripting
Apr 16, 2026 Apr 16, 2026
Apr 16, 2026
Apr 16, 2026
10.0 CRITICAL
CVE-2026-6349 — HGiga|iSherlock - OS Command Injection

The  iSherlock developed by HGiga  has an OS Command Injection vulnerability, allowing unauthenticated local attackers to inject arbitrary OS commands and execute them on the server.

Remote | Injection
Apr 16, 2026 Apr 16, 2026
Apr 16, 2026
Apr 16, 2026
4.9 MEDIUM
CVE-2026-40962 — FFmpeg CENC Subsample Buffer Overflow Vulnerability

FFmpeg before 8.1 has an integer overflow and resultant out-of-bounds write via CENC (Common Encryption) subsample data to libavformat/mov.c.

| Memory Corruption
Apr 16, 2026 Apr 16, 2026
Apr 16, 2026
Apr 16, 2026
3.3 LOW
CVE-2026-40505 — MuPDF mutool ANSI Injection via Metadata

MuPDF mutool does not sanitize PDF metadata fields before writing them to terminal output, allowing attackers to inject arbitrary ANSI escape sequences through crafted PDF metadata. Attackers can emb…

| Injection
Apr 16, 2026 Apr 16, 2026
Apr 16, 2026
Apr 16, 2026
9.8 CRITICAL
CVE-2026-40504 — Creolabs Gravity < 0.9.6 Heap Buffer Overflow via gravity_vm_exec

Creolabs Gravity before 0.9.6 contains a heap buffer overflow vulnerability in the gravity_vm_exec function that allows attackers to write out-of-bounds memory by crafting scripts with many string li…

Remote | Memory Corruption
Apr 16, 2026 Apr 16, 2026
Apr 16, 2026
Apr 16, 2026
6.4 MEDIUM
CVE-2026-3299 — WP YouTube Lyte <= 1.7.29 - Authenticated (Contributor+) Stored Cross-Site Scripting via …

The WP YouTube Lyte plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'lyte' shortcode in all versions up to, and including, 1.7.29 due to insufficient input sanitiza…

Remote | Cross-Site Scripting
Apr 16, 2026 Apr 16, 2026
Apr 16, 2026
Apr 16, 2026
5.4 MEDIUM
CVE-2026-3428 — ASUS Member Center TOC-TOU Privilege Escalation

A Download of Code Without Integrity Check vulnerability in the update modules in ASUS Member Center(华硕大厅) allows a local user to achieve privilege escalation to Administrator via exploitation of a T…

| Race Condition
Apr 16, 2026 Apr 16, 2026
Apr 16, 2026
Apr 16, 2026
5.4 MEDIUM
CVE-2026-1880 — "ASUS DriverHub Privilege Escalation Vulnerability"

An Incorrect Permission Assignment for Critical Resource vulnerability in the ASUS DriverHub update process allows privilege escalation due to improper protection of required execution resources duri…

| Authorization
Apr 16, 2026 Apr 16, 2026
Apr 16, 2026
Apr 16, 2026
9.3 CRITICAL
CVE-2026-6348 — Simopro Technology|WinMatrix - Missing Authentication

WinMatrix agent developed by Simopro Technology has a Missing Authentication vulnerability, allowing authenticated local attackers to execute arbitrary code with SYSTEM privileges on the local machin…

| Authentication
Apr 16, 2026 Apr 16, 2026
Apr 16, 2026
Apr 16, 2026
8.1 HIGH
CVE-2026-40960 — Luanti 5 Deserialization Vulnerability

Luanti 5 before 5.15.2 sometimes allows unintended access to an insecure environment. If at least one mod is listed as secure.trusted_mods or secure.http_mods, then a crafted mod can intercept the re…

| Authorization
Apr 16, 2026 Apr 16, 2026
Apr 16, 2026
Apr 16, 2026
9.3 CRITICAL
CVE-2026-40959 — Luanti Lua Sandbox Escape

Luanti 5 before 5.15.2, when LuaJIT is used, allows a Lua sandbox escape via a crafted mod.

| Misconfiguration
Apr 16, 2026 Apr 16, 2026
Apr 16, 2026
Apr 16, 2026
7.1 HIGH
CVE-2026-40503 — OpenHarness Path Traversal Information Disclosure via /memory show

OpenHarness prior to commit dd1d235 contains a path traversal vulnerability that allows remote gateway users with chat access to read arbitrary files by supplying path traversal sequences to the /mem…

Remote | Path Traversal
Apr 16, 2026 Apr 16, 2026
Apr 16, 2026
Apr 16, 2026
8.8 HIGH
CVE-2026-40502 — OpenHarness Remote Administrative Command Injection via Gateway Handler

OpenHarness prior to commit dd1d235 contains a command injection vulnerability that allows remote gateway users with chat access to invoke sensitive administrative commands by exploiting insufficient…

Remote | Injection
Apr 16, 2026 Apr 16, 2026
Apr 16, 2026
Apr 16, 2026
5.4 MEDIUM
CVE-2026-5363 — Use of weak cryptographic key in TP-Link Archer C7

Inadequate Encryption Strength vulnerability in TP-Link Archer C7 v5 and v5.8 (uhttpd modules) allows Password Recovery Exploitation. The web interface encrypts the admin password client-side using R…

| Cryptography
Apr 16, 2026 Apr 16, 2026
Apr 16, 2026
Apr 16, 2026
9.8 CRITICAL
CVE-2026-4880 — Barcode Scanner (+Mobile App) <= 1.11.0 - Unauthenticated Privilege Escalation via Insecu…

The Barcode Scanner (+Mobile App) – Inventory manager, Order fulfillment system, POS (Point of Sale) plugin for WordPress is vulnerable to privilege escalation via insecure token-based authentication…

Remote | Authentication
Apr 16, 2026 Apr 16, 2026
Apr 16, 2026
Apr 16, 2026
2.9 LOW
CVE-2026-40947 — Yubico YubiKey DLL Search Path Vulnerability

Yubico libfido2 before 1.17.0, python-fido2 before 2.2.0, and yubikey-manager before 5.9.1 have an unintended DLL search path.

| Misconfiguration
Apr 16, 2026 Apr 16, 2026
Apr 16, 2026
Apr 16, 2026
7.5 HIGH
CVE-2026-40245 — Free5GC: UDR nudr-dr influenceData/subs-to-notify leaks SUPI in error response body witho…

Free5GC is an open-source Linux Foundation project for 5th generation (5G) mobile core networks. Versions 4.2.1 and below contain an information disclosure vulnerability in the UDR (Unified Data Repo…

udm | Remote | Information Disclosure
Apr 16, 2026 Apr 16, 2026
Apr 16, 2026
Apr 16, 2026
Showing 20 of 6528 Results