Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.5 MEDIUM
CVE-2026-6214 — Forminator Forms <= 1.53.0 - Missing Authorization to Authenticated (Subscriber+) Schedul…

The Forminator Forms plugin for WordPress is vulnerable to Missing Authorization in versions up to and including 1.53.0. This is due to the listen_for_saving_export_schedule() function in library/cla…

Remote | Authorization
May 07, 2026 May 07, 2026
May 07, 2026
May 07, 2026
3.7 LOW
CVE-2026-44603 — Tor Tor Out-of-Bounds Read Vulnerability

Tor before 0.4.9.7 has an out-of-bounds read by one byte via a malformed BEGIN cell, aka TROVE-2026-007.

Remote | Memory Corruption
May 07, 2026 May 07, 2026
May 07, 2026
May 07, 2026
3.7 LOW
CVE-2026-44602 — Tor DNS NULL Pointer Dereference

Tor before 0.4.9.7 has a NULL pointer dereference when a CERT cell is received out of order, aka TROVE-2026-006.

Remote | Memory Corruption
May 07, 2026 May 07, 2026
May 07, 2026
May 07, 2026
3.7 LOW
CVE-2026-44601 — Tor Circuit Double Close Crash Vulnerability

Tor before 0.4.9.7, when circuit queue memory pressure exists, can experience a client crash because of a double close of a circuit, aka TROVE-2026-009.

Remote | Denial of Service
May 07, 2026 May 07, 2026
May 07, 2026
May 07, 2026
6.3 MEDIUM
CVE-2026-42217 — OpenEXR: Shift exponent overflow in `readVariableLengthInteger()` (`ImfIDManifest.cpp`)

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From versions 3.0.0 to before 3.2.9, 3.3.0 to before 3…

Remote | Memory Corruption
May 07, 2026 May 07, 2026
May 07, 2026
May 07, 2026
8.8 HIGH
CVE-2026-42216 — OpenEXR: Out-of-bounds read in `IDManifest::init()` during prefix expansion

OpenEXR provides the specification and reference implementation of the EXR file format, an image storage format for the motion picture industry. From versions 3.0.0 to before 3.2.9, 3.3.0 to before 3…

Remote | Memory Corruption
May 07, 2026 May 07, 2026
May 07, 2026
May 07, 2026
6.8 MEDIUM
CVE-2026-42194 — Incomplete fix for CVE-2026-32812: SSRF in admidio

Admidio is an open-source user management solution. Prior to version 5.0.9, the incomplete SSRF fix in Admidio's fetch_metadata.php validates the resolved IP address but passes the original hostname-…

Remote | Server-Side Request Forgery
May 07, 2026 May 07, 2026
May 07, 2026
May 07, 2026
5.3 MEDIUM
CVE-2026-41891 — CI4MS: Deactivated User Session Bypass (active=0)

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. From version 0.26.0 to before version 0.31.8.0, the auth …

Remote | Authorization
May 07, 2026 May 07, 2026
May 07, 2026
May 07, 2026
6.9 MEDIUM
CVE-2026-41890 — CI4MS: Arbitrary Database Table Drop via Theme deleteProcess

CI4MS is a CodeIgniter 4-based CMS skeleton that delivers a production-ready, modular architecture with RBAC authorization and theme support. From version 0.31.1.0 to before version 0.31.8.0, the del…

Remote | Authorization
May 07, 2026 May 07, 2026
May 07, 2026
May 07, 2026
8.7 HIGH
CVE-2026-41675 — xmldom: XML node injection through unvalidated processing instruction serialization

xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) `DOMParser` and `XMLSerializer` module. In @xmldom/xmldom prior to versions 0.9.10 and 0.8.13 and xmldom version 0.6.0 and prior,…

Remote | XML External Entity
May 07, 2026 May 07, 2026
May 07, 2026
May 07, 2026
8.7 HIGH
CVE-2026-41674 — xmldom: XML injection through unvalidated DocumentType serialization

xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) `DOMParser` and `XMLSerializer` module. In @xmldom/xmldom prior to versions 0.9.10 and 0.8.13 and xmldom version 0.6.0 and prior,…

Remote | XML External Entity
May 07, 2026 May 07, 2026
May 07, 2026
May 07, 2026
8.7 HIGH
CVE-2026-41673 — xmldom: Denial of service via uncontrolled recursion in XML serialization

xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) `DOMParser` and `XMLSerializer` module. In @xmldom/xmldom prior to versions 0.9.10 and 0.8.13 and xmldom version 0.6.0 and prior,…

Remote | Denial of Service
May 07, 2026 May 07, 2026
May 07, 2026
May 07, 2026
8.7 HIGH
CVE-2026-41672 — xmldom: XML node injection through unvalidated comment serialization

xmldom is a pure JavaScript W3C standard-based (XML DOM Level 2 Core) `DOMParser` and `XMLSerializer` module. In @xmldom/xmldom prior to versions 0.9.10 and 0.8.13 and xmldom version 0.6.0 and prior,…

Remote | XML External Entity
May 07, 2026 May 07, 2026
May 07, 2026
May 07, 2026
6.8 MEDIUM
CVE-2026-41671 — Admidio: OIDC Token Introspection Endpoint Returns Active for All Tokens Without Validati…

Admidio is an open-source user management solution. Prior to version 5.0.9, the OIDC token introspection endpoint (/modules/sso/index.php/oidc/introspect) always returns {"active": true} for every re…

Remote | Authentication
May 07, 2026 May 07, 2026
May 07, 2026
May 07, 2026
8.2 HIGH
CVE-2026-41670 — Admidio: SAML Response Sent to Unvalidated Assertion Consumer Service URL from AuthnReque…

Admidio is an open-source user management solution. Prior to version 5.0.9, the SAML IdP implementation in Admidio's SSO module uses the AssertionConsumerServiceURL value directly from incoming SAML …

Remote | Authentication
May 07, 2026 May 07, 2026
May 07, 2026
May 07, 2026
8.2 HIGH
CVE-2026-41669 — Admidio: SAML Signature Validation Result Ignored — Forged AuthnRequests and LogoutReques…

Admidio is an open-source user management solution. Prior to version 5.0.9, the Admidio SAML Identity Provider implementation discards the return value of its validateSignature() method at both call …

Remote | Authentication
May 07, 2026 May 07, 2026
May 07, 2026
May 07, 2026
3.5 LOW
CVE-2026-41663 — Admidio: CSRF on Admin Preferences Triggers Unauthorized Backup, .htaccess Write, and Ema…

Admidio is an open-source user management solution. Prior to version 5.0.9, several administrative operations in Admidio's preferences module (database backup, test email, htaccess generation) fire v…

Remote | Cross-Site Request Forgery
May 07, 2026 May 07, 2026
May 07, 2026
May 07, 2026
5.2 MEDIUM
CVE-2026-41662 — Admidio: Missing Minimum Administrator Check in Role Membership Removal

Admidio is an open-source user management solution. Prior to version 5.0.9, Role::stopMembership() does not verify whether removing a user from the administrator role leaves zero administrators. The …

Remote | Authorization
May 07, 2026 May 07, 2026
May 07, 2026
May 07, 2026
6.1 MEDIUM
CVE-2026-41661 — Admidio: Reflected XSS in msg_window.php via Square Bracket to HTML Tag Conversion

Admidio is an open-source user management solution. Prior to version 5.0.9, an unauthenticated attacker can execute arbitrary JavaScript in any Admidio user's browser through a reflected XSS in syste…

Remote | Cross-Site Scripting
May 07, 2026 May 07, 2026
May 07, 2026
May 07, 2026
7.1 HIGH
CVE-2026-41660 — Admidio: Inverted 2FA Reset Authorization Check Lets Group Leaders Strip Admin TOTP

Admidio is an open-source user management solution. Prior to version 5.0.9, a logic error in Admidio's two-factor authentication reset inverts the authorization check. Non-admin users cannot remove t…

Remote | Authorization
May 07, 2026 May 07, 2026
May 07, 2026
May 07, 2026
Showing 20 of 5957 Results