Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
4.3 MEDIUM
CVE-2026-45448 — ntopng - CWE-601: URL Redirection to Untrusted Site ('Open Redirect')

CWE-601 URL redirection to untrusted site ('open redirect')

Remote | Misconfiguration
May 14, 2026 May 14, 2026
May 14, 2026
May 14, 2026
0.0 NA
CVE-2026-44516 — Valtimo: Sensitive data exposure through HTTP request/response logging in LoggingRestClie…

Valtimo is an open-source business process automation platform. From 12.4.0 to 12.33.0 and 13.26.0, the LoggingRestClientCustomizer in the web module automatically intercepts all outgoing HTTP calls …

| Information Disclosure
May 14, 2026 May 14, 2026
May 14, 2026
May 14, 2026
0.0 NA
CVE-2026-42555 — Valtimo: SpEL injection via StandardEvaluationContext allows Remote Code Execution by adm…

Valtimo is an open-source business process automation platform. com.ritense.valtimo:document from 12.0.0 to before 12.32.0, com.ritense.valtimo:case from 13.0.0 to before 13.23.0, and com.ritense.val…

| Injection
May 14, 2026 May 14, 2026
May 14, 2026
May 14, 2026
0.0 NA
CVE-2026-44348 — PoDoFo: Double-free vulnerability in compute_hash_to_sign()

PoDoFo is a C++17 PDF manipulation library. From 1.0.0 to before 1.0.4, a double-free vulnerability exists in compute_hash_to_sign() in src/podofo/private/OpenSSLInternal_Ripped.cpp. If EVP_DigestFin…

| Memory Corruption
May 14, 2026 May 14, 2026
May 14, 2026
May 14, 2026
0.0 NA
CVE-2026-44515 — Nextcloud News: Authenticated blind SSRF via feed URL

Nextcloud News is an RSS/Atom feed reader. Prior to 28.3.0-beta.1, Nextcloud News allows authenticated users to add feeds by providing a feed URL (via the web interface or the API). In affected versi…

| Server-Side Request Forgery
May 14, 2026 May 14, 2026
May 14, 2026
May 14, 2026
0.0 NA
CVE-2026-44827 — Diffusers: None.py Trust Remote Code Bypass

Diffusers is the a library for pretrained diffusion models. Prior to 0.38.0, diffusers 0.37.0 allows remote code execution without the trust_remote_code=True safeguard when loading pipelines from Hu…

| Supply Chain
May 14, 2026 May 14, 2026
May 14, 2026
May 14, 2026
0.0 NA
CVE-2026-44513 — Diffusers: `trust_remote_code` bypass via `custom_pipeline` and local custom components

Diffusers is the a library for pretrained diffusion models. Prior to 0.38.0, a trust_remote_code bypass in DiffusionPipeline.from_pretrained allows arbitrary remote code execution despite the user p…

| Supply Chain
May 14, 2026 May 14, 2026
May 14, 2026
May 14, 2026
0.0 NA
CVE-2026-44514 — Kubetail: Cross-Site WebSocket Hijacking allows attacker to read Kubernetes logs from aut…

Kubetail is a real-time logging dashboard for Kubernetes. Prior to 0.14.0, Kubetail's dashboard exposes WebSocket endpoints that did not adequately validate the Origin header on connection upgrade. A…

| Authentication
May 14, 2026 May 14, 2026
May 14, 2026
May 14, 2026
5.1 MEDIUM
CVE-2025-62305 — HCL AION is affected by a vulnerability where certain operations may trigger out-of-band …

HCL AION is affected by a vulnerability where certain operations may trigger out-of-band interactions, potentially resulting in unintended disclosure of sensitive information. Such behaviour may allo…

| Information Disclosure
May 14, 2026 May 14, 2026
May 14, 2026
May 14, 2026
0.0 NA
CVE-2026-44511 — Katalyst Koi: Session cookies can be replayed after user logout

Katalyst Koi is a framework for building Rails admin functionality. Prior to 4.20.0 and 5.6.0, admin session cookies were not invalidated when an admin user logged out. An attacker with access to a v…

| Authentication
May 14, 2026 May 14, 2026
May 14, 2026
May 14, 2026
8.6 HIGH
CVE-2026-44504 — Aegra: Cross-user run injection in /threads/{thread_id}/runs (IDOR)

Aegra is a drop-in replacement for LangSmith Deployments. Prior to 0.9.7, with multiple authenticated users on a shared instance are vulnerable to a cross-tenant IDOR. Any authenticated attacker, giv…

Remote | Authorization
May 14, 2026 May 14, 2026
May 14, 2026
May 14, 2026
7.0 HIGH
CVE-2026-44503 — Kiota abstractions RedirectHandler leaks Cookie/Proxy-Authorization headers on cross-host…

The RedirectHandler middleware in microsoft/kiota-java (com.microsoft.kiota:microsoft-kiota-http-okHttp v1.9.0) and other Kiota libraries fails to strip sensitive HTTP headers when following 3xx redi…

Remote | Misconfiguration
May 14, 2026 May 14, 2026
May 14, 2026
May 14, 2026
4.3 MEDIUM
CVE-2026-44501 — DataHub OIDC REDIRECT_URL Cookie Deserialization Vulnerability

DataHub is an open-source metadata platform. Prior to 1.5.0.3, The DataHub frontend (datahub-frontend-react) deserializes attacker-controlled Java objects from the REDIRECT_URL HTTP cookie during the…

Remote | Injection
May 14, 2026 May 14, 2026
May 14, 2026
May 14, 2026
5.9 MEDIUM
CVE-2026-42597 — Gotenberg: Chromium URL conversion routes read arbitrary files under /tmp via file:// sch…

Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.32.0, the /forms/chromium/convert/url and /forms/chromium/screenshot/url routes accept url=file:///tmp/... from anonymous callers…

Remote | Path Traversal
May 14, 2026 May 14, 2026
May 14, 2026
May 14, 2026
9.4 CRITICAL
CVE-2026-42596 — Gotenberg: Unauthenticated SSRF via default deny-list bypass in downloadFrom and webhook

Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.31.0, the default deny-lists used by Gotenberg's downloadFrom feature and webhook feature are bypassable. Because the filter is r…

Remote | Server-Side Request Forgery
May 14, 2026 May 14, 2026
May 14, 2026
May 14, 2026
8.6 HIGH
CVE-2026-42595 — Gotenberg: Server-Side Request Forgery via Chromium URL Endpoint with Redirect-Based Deny…

Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.32.0, Gotenberg's Chromium URL-to-PDF endpoint (/forms/chromium/convert/url) has no default protection against HTTP/HTTPS-based S…

Remote | Server-Side Request Forgery
May 14, 2026 May 14, 2026
May 14, 2026
May 14, 2026
7.5 HIGH
CVE-2026-42594 — Gotenberg: Unauthenticated denial of service via echo.Context pool reuse in webhook async…

Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.32.0, the webhook middleware spawns a goroutine that holds a reference to the request's echo.Context after the synchronous handle…

Remote | Memory Corruption
May 14, 2026 May 14, 2026
May 14, 2026
May 14, 2026
5.3 MEDIUM
CVE-2026-42593 — Gotenberg: Arbitrary PDF read via stampExpression and watermarkExpression in merge, split…

Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.32.0, pdfengines/merge, pdfengines/split, libreoffice/convert, chromium/convert/url, chromium/convert/html, and chromium/convert/…

Remote | Path Traversal
May 14, 2026 May 14, 2026
May 14, 2026
May 14, 2026
5.3 MEDIUM
CVE-2026-42592 — Gotenberg: DNS rebinding bypasses SSRF validation on Chromium URL conversion routes

Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.32.0, FilterOutboundURL resolves the hostname, checks the resolved IPs against the private-address deny-list, and returns only th…

Remote | Server-Side Request Forgery
May 14, 2026 May 14, 2026
May 14, 2026
May 14, 2026
8.2 HIGH
CVE-2026-42591 — Gotenberg: Server-Side Request Forgery (SSRF) in github.com/gotenberg/gotenberg/v8

Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.32.0, the LibreOffice conversion endpoint (/forms/libreoffice/convert) passes uploaded documents directly to LibreOffice without …

Remote | Server-Side Request Forgery
May 14, 2026 May 14, 2026
May 14, 2026
May 14, 2026
Showing 20 of 6417 Results