Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-33633 — Kitty has a Heap Buffer Overflow in its Graphics Protocol Handler

Kitty is a cross-platform GPU based terminal. Versions 0.46.2 and below contain a heap buffer overflow in load_image_data() that allows any process which can write to the terminal's stdin to crash ki…

| Memory Corruption
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
8.7 HIGH
CVE-2026-6009 — Jaspersoft Library Deserialisation Vulnerability

Java Deserialisation Vulnerability in Jaspersoft Reports Library leads to Remote Code Execution (RCE), potentially allowing code execution on the affected system

Remote | Injection
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
0.0 NA
CVE-2026-32134 — NanoMQ: NULL Pointer Dereference Crash in tcptran_pipe_peer During Session Restore

NanoMQ MQTT Broker (NanoMQ) is an all-around Edge Messaging Platform. In versions 0.24.10 and below, when NanoMQ handles high-concurrency reconnect traffic using a reconnect-collision payload, the br…

| Denial of Service
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
4.6 MEDIUM
CVE-2026-5511 — Information Disclosure via Diagnostic Interface Due to Improper Input Validation on TP-Li…

In the web management interface of Archer AX72 (SG) v1, the network diagnostic feature improperly handles invalid user input, resulting in limited exposure of diagnostic command usage information.  …

| Information Disclosure
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
9.3 CRITICAL
CVE-2026-47358 — Terrascan Server-Side Request Forgery (SSRF)

Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via external URL resolution in uploaded IaC templates when running in server mode. When Terrascan parses uploaded ARM …

| Server-Side Request Forgery
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
9.3 CRITICAL
CVE-2026-47357 — Terrascan Server-Side Request Forgery (SSRF)

Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via the remote_url parameter in the remote directory scan endpoint (POST /v1/{iac}/{iacVersion}/{cloud}/remote/dir/sca…

| Server-Side Request Forgery
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
8.7 HIGH
CVE-2026-47356 — Terrascan SSRF

Terrascan v1.18.3 and prior are vulnerable to Server-Side Request Forgery (SSRF) via the webhook_url parameter in the file scan endpoint (POST /v1/{iac}/{iacVersion}/{cloud}/local/file/scan) when run…

| Server-Side Request Forgery
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
0.0 NA
CVE-2026-36829 — Panabit PAP-XM320 Authentication Bypass Vulnerability

An authentication bypass vulnerability exists in the embedded HTTP server of Panabit PAP-XM320 up to and including v7.7. The server validates session cookies using a filesystem existence check based …

| Authentication
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
0.0 NA
CVE-2026-36828 — Panabit PAP-XM320 Command Injection Vulnerability

A command injection vulnerability exists in the /cgi-bin/tools/ajax_cmd endpoint of Panabit PAP-XM320 up to and including v7.7. The CGI component allows authenticated users to execute arbitrary shell…

| Injection
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
0.0 NA
CVE-2026-36827 — Panabit PAP-XM320 Command Injection Vulnerability

A command injection vulnerability exists in Panabit PAP-XM320 up to and including V7.7. The web management interface invokes the backend helper /usr/sbin/pappiw and passes user-controlled parameters …

| Injection
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
5.1 MEDIUM
CVE-2026-8605 — Use of Hard-coded Credentials in ScadaBR

In ScadaBR version 1.2.0, a Use of Hard-Coded Credentials vulnerability could allow an attacker to access the SCADA system as admin.

Remote | Authentication
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
8.6 HIGH
CVE-2026-8604 — Cross-Site request forgery (CSRF) in ScadaBR

In ScadaBR version 1.2.0, a CSRF vulnerability could allow an attacker to trigger any authenticated action through a victim's session by luring any logged-in user to a malicious webpage.

Remote | Cross-Site Request Forgery
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
8.7 HIGH
CVE-2026-8603 — Improper neutralization of special elements used in an OS command ('OS command injection'…

In ScadaBR version 1.2.0, an OS Command Injection vulnerability could allow an attacker to execute commands as root on the SCADA system.

Remote | Injection
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
8.8 HIGH
CVE-2026-8602 — Missing authentication for critical function in ScadaBR

In ScadaBR version 1.2.0, a Missing Authentication for Critical Function vulnerability could allow an unauthenticated attacker to send a HTTP GET requests to the SCADA system and inject arbitrary sen…

Remote | Authentication
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
9.6 CRITICAL
CVE-2026-47107 — Windmill < 1.703.2 Incorrect Default Permissions in nsjail Configuration

Windmill prior to 1.703.2 contains an incorrect default permissions vulnerability in nsjail sandbox configuration files where /etc is bind-mounted without read-write restrictions, allowing authentica…

Remote | Misconfiguration
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
6.2 MEDIUM
CVE-2026-8706 — Sensitive user data could be leaked to other applications through Reader mode

Firefox for iOS hosted Reader mode on an unauthenticated local web server, allowing another application on the same device to request arbitrary URLs and receive the response rendered with the signed-…

| Server-Side Request Forgery
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
8.4 HIGH
CVE-2026-5804 — Motorola Factory Test Auth Bypass

An improper authentication vulnerability was discovered in the Motorola Factory Test component (com.motorola.motocit). The application contained a reference to a writable file descriptor in external …

| Authentication
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
0.0 NA
CVE-2026-37281 — Hitarth-gg Zenshin OS Command Injection

An OS command injection vulnerability in the /stream-to-vlc Express route in hitarth-gg Zenshin before 2.7.0 allows remote attackers to execute arbitrary commands via the url parameter.

| Injection
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
0.0 NA
CVE-2026-31072 — Apache APScheduler Python RCE via Insecure Deserialization

The JSONSerializer and CBORSerializer in APScheduler (all versions including 3.10.x and 4.0.0a5) are vulnerable to Remote Code Execution (RCE) via Insecure Deserialization. The unmarshal_object funct…

| Injection
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
0.0 NA
CVE-2026-31071 — LalanaChami Pharmacy Management System Unauthenticated API Endpoint Vulnerability

API endpoints in LalanaChami Pharmacy Management System (commit 5c3d028) lack authentication middleware. Unauthenticated remote attackers can exploit this to dump all user records (including bcrypt p…

| Authentication
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
Showing 20 of 6359 Results