Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2025-65954 — SimpleSAMLphp-casserver has an Open Redirect vulnerability via logout

SimpleSAMLphp-casserver is a CAS 1.0 and 2.0 compliant CAS server in the form of a SimpleSAMLphp module. In versions below 6.3.1 and 7.0.0, the logout endpoint accepts a url query parameter to redire…

| Information Disclosure
May 18, 2026 May 18, 2026
May 18, 2026
May 18, 2026
7.8 HIGH
CVE-2026-47092 — Claude HUD 0.0.12 Arbitrary Command Execution via COMSPEC Environment Variable

Claude HUD through 0.0.12, patched in commit 234d9aa, contains a command injection vulnerability that allows local attackers to execute arbitrary commands by manipulating the COMSPEC environment vari…

| Injection
May 18, 2026 May 18, 2026
May 18, 2026
May 18, 2026
4.8 MEDIUM
CVE-2026-47091 — Claude HUD 0.0.12 Path Traversal via transcript_path

Claude HUD through 0.0.12, patched in commit 234d9aa, contains a path traversal vulnerability that allows attackers to read arbitrary files by supplying an unvalidated transcript_path value via stdin…

| Path Traversal
May 18, 2026 May 18, 2026
May 18, 2026
May 18, 2026
4.6 MEDIUM
CVE-2026-47090 — Claude HUD 0.0.12 Terminal Injection via OSC 8 Hyperlinks

Claude HUD through 0.0.12, patched in commit 234d9aa, constructs OSC 8 terminal hyperlink escape sequences using raw cwd and branchUrl values without stripping control characters or encoding embedded…

| Misconfiguration
May 18, 2026 May 18, 2026
May 18, 2026
May 18, 2026
4.6 MEDIUM
CVE-2026-21789 — HCL Connections is vulnerable to broken access control

HCL Connections contains a broken access control vulnerability that may allow unauthorized user to update data in certain scenarios.

Remote | Authorization
May 18, 2026 May 18, 2026
May 18, 2026
May 18, 2026
10.0 HIGH
CVE-2026-8836 — lwIP snmpv3 USM snmp_msg.c snmp_parse_inbound_frame stack-based overflow

A vulnerability was found in lwIP up to 2.2.1. Affected is the function snmp_parse_inbound_frame of the file src/apps/snmp/snmp_msg.c of the component snmpv3 USM Handler. Performing a manipulation of…

Remote | Memory Corruption
May 18, 2026 May 18, 2026
May 18, 2026
May 18, 2026
6.1 MEDIUM
CVE-2026-45243 — Summarize < 0.15.1 Browser Extension Missing Authorization via Content Script

Summarize prior to 0.15.1 contains a missing authorization vulnerability in the content script window.postMessage bridge that allows malicious pages to perform unauthorized operations on automation a…

Remote | Authorization
May 18, 2026 May 18, 2026
May 18, 2026
May 18, 2026
7.1 HIGH
CVE-2026-45242 — Summarize < 0.15.1 Path Traversal via slidesDir Parameter

Summarize prior to 0.15.1 contains a path traversal vulnerability in the /v1/summarize daemon endpoint that allows authenticated callers to write files to arbitrary directories by supplying an absolu…

Remote | Path Traversal
May 18, 2026 May 18, 2026
May 18, 2026
May 18, 2026
6.1 MEDIUM
CVE-2026-45231 — DumbAssets 1.0.11 Stored Cross-Site Scripting via Asset Fields

DumbAssets through 1.0.11 contains a stored cross-site scripting vulnerability in asset fields including name, description, modelNumber, serialNumber, and tags that are stored without server-side san…

Remote | Cross-Site Scripting
May 18, 2026 May 18, 2026
May 18, 2026
May 18, 2026
6.8 MEDIUM
CVE-2026-45246 — Summarize < 0.15.1 Insecure File Permissions Information Disclosure

Summarize prior to 0.15.1 contains an insecure file permission vulnerability in the refresh-free configuration rewrite path that allows local users to read sensitive credentials by exploiting default…

| Misconfiguration
May 18, 2026 May 18, 2026
May 18, 2026
May 18, 2026
7.4 HIGH
CVE-2026-45245 — Summarize < 0.15.1 Unauthorized Daemon Request via Untrusted Events

Summarize prior to 0.15.1 contains a vulnerability in the hover summary feature that allows malicious pages to dispatch synthetic mouseover events over attacker-controlled links, causing the extensio…

Remote | Server-Side Request Forgery
May 18, 2026 May 18, 2026
May 18, 2026
May 18, 2026
5.4 MEDIUM
CVE-2026-45244 — Summarize < 0.15.1 Unapproved Browser Automation Execution

Summarize prior to 0.15.1 contains a missing authorization vulnerability that allows attackers to execute browser automation actions without per-call user approval when the extension automation featu…

Remote | Authorization
May 18, 2026 May 18, 2026
May 18, 2026
May 18, 2026
8.8 HIGH
CVE-2026-45495 — Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

May 18, 2026 May 18, 2026
May 18, 2026
May 18, 2026
5.4 MEDIUM
CVE-2026-45494 — Microsoft Edge (Chromium-based) Spoofing Vulnerability

Microsoft Edge (Chromium-based) Spoofing Vulnerability

May 18, 2026 May 18, 2026
May 18, 2026
May 18, 2026
5.4 MEDIUM
CVE-2026-45492 — Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability

Improper input validation in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.

May 18, 2026 May 18, 2026
May 18, 2026
May 18, 2026
9.1 CRITICAL
CVE-2026-45230 — DumbAssets 1.0.11 Path Traversal File Deletion via /api/delete-file

DumbAssets through 1.0.11 contains a path traversal vulnerability in the POST /api/delete-file endpoint and filesToDelete array parameters that allows unauthenticated attackers to delete arbitrary fi…

Remote | Path Traversal
May 18, 2026 May 18, 2026
May 18, 2026
May 18, 2026
10.0 CRITICAL
CVE-2026-42822 — Azure Local Disconnected Operations (ALDO) Elevation of Privilege Vulnerability

Improper authentication in Azure Local Disconnected Operations allows an unauthorized attacker to elevate privileges over a network.

May 18, 2026 May 18, 2026
May 18, 2026
May 18, 2026
5.7 MEDIUM
CVE-2026-32849 — NetBSD Signed Integer Overflow in cryptodev_op via cryptodev.c

NetBSD prior to commit ec8451e contains a signed integer overflow vulnerability in the cryptodev_op() function in sys/opencrypto/cryptodev.c where the local variable iov_len is declared as a signed i…

| Memory Corruption
May 18, 2026 May 18, 2026
May 18, 2026
May 18, 2026
5.7 MEDIUM
CVE-2026-32848 — NetBSD cryptodev Race Condition Double-Free via cryptodev_op()

NetBSD prior to commit ec8451e contains a race condition vulnerability in cryptodev_op() within the opencrypto subsystem that allows local attackers to trigger a double-free condition by concurrently…

| Race Condition
May 18, 2026 May 18, 2026
May 18, 2026
May 18, 2026
0.0 NA
CVE-2026-29965 — HSC MailInspector XSS

HSC MailInspector 5.3.3-7 is vulnerable to Cross Site Scripting (XSS) in the /police/WarningUrlPage.php endpoint due to improper neutralization of user-supplied input that uses alternate or obfuscate…

| Cross-Site Scripting
May 18, 2026 May 18, 2026
May 18, 2026
May 18, 2026
Showing 20 of 6200 Results