Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.1 HIGH
CVE-2026-42897 — Microsoft Exchange Server Cross-Site Scripting Vulnerability - [Actively Exploited]

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

May 14, 2026 May 15, 2026
May 14, 2026
May 15, 2026
6.9 MEDIUM
CVE-2026-42598 — Pode: Directory Traversal is possible on Static Routes

Pode is a Cross-Platform PowerShell web framework for creating REST APIs, Web Sites, and TCP/SMTP servers. From 2.4.0, to before 2.13.0, when requesting content from a Static Route, it was possible t…

Remote | Path Traversal
May 14, 2026 May 14, 2026
May 14, 2026
May 14, 2026
6.5 MEDIUM
CVE-2026-42572 — Hatchet: Cross-tenant information disclosure in `listTasksByDAGIds`

Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. Prior to 0.83.39, a missing authorization directive on the GET /api/v1/stable/dags/tasks endpoint …

hatchet | Remote | Authorization
May 14, 2026 May 27, 2026
May 14, 2026
May 27, 2026
7.5 HIGH
CVE-2026-42334 — Mongoose: Improper Sanitization of $nor in sanitizeFilter May Allow NoSQL Injection

Mongoose is a MongoDB object modeling tool designed to work in an asynchronous environment. Prior to 6.13.9, 7.8.9, 8.22.1, and 9.1.6, a vulnerability allows bypassing Mongoose’s sanitizeFilter query…

mongoose | Remote | Injection
May 14, 2026 May 15, 2026
May 14, 2026
May 15, 2026
6.5 MEDIUM
CVE-2026-41888 — Distribution: Tag deletion bypasses `storage.delete.enabled` configuration

Distribution is a toolkit to pack, ship, store, and deliver container content. Prior to 3.1.1, tag deletion via the DELETE /v2/<name>/manifests/<tag> endpoint bypasses the storage.delete.enabled: fal…

distribution | Remote | Misconfiguration
May 14, 2026 May 15, 2026
May 14, 2026
May 15, 2026
9.6 CRITICAL
CVE-2026-41615 — Microsoft Authenticator Information Disclosure Vulnerability

Exposure of sensitive information to an unauthorized actor in Microsoft Authenticator allows an unauthorized attacker to disclose information over a network.

May 14, 2026 May 15, 2026
May 14, 2026
May 15, 2026
8.8 HIGH
CVE-2025-15024 — RCE in Yordam Informatics' Library Automation System

Improper Control of Generation of Code ('Code Injection') vulnerability in Yordam Information Technology Consulting, Training and Electronic Systems Industry and Trade Inc. Library Automation System …

Remote | Injection
May 14, 2026 May 14, 2026
May 14, 2026
May 14, 2026
8.8 HIGH
CVE-2025-15023 — Improper Access Control in Yordam Informatics' Library Automation System

Incorrect Authorization vulnerability in Yordam Information Technology Consulting, Training and Electronic Systems Industry and Trade Inc. Library Automation System allows Exploiting Incorrectly Conf…

Remote | Authorization
May 14, 2026 May 14, 2026
May 14, 2026
May 14, 2026
3.8 LOW
CVE-2026-6923 — Nuvoton - CWE-1300: Improper Protection of Physical Side Channels

A side-channel attack, which requires a physical presence to the TPM, can lead to extraction of an Elliptic Curve Diffie-Hellman (ECDH) key.

| Cryptography
May 14, 2026 May 14, 2026
May 14, 2026
May 14, 2026
4.3 MEDIUM
CVE-2026-45448 — ntopng - CWE-601: URL Redirection to Untrusted Site ('Open Redirect')

CWE-601 URL redirection to untrusted site ('open redirect')

ntopng | Remote | Misconfiguration
May 14, 2026 May 14, 2026
May 14, 2026
May 14, 2026
8.8 HIGH
CVE-2026-44827 — Diffusers: None.py Trust Remote Code Bypass

Diffusers is the a library for pretrained diffusion models. Prior to 0.38.0, diffusers 0.37.0 allows remote code execution without the trust_remote_code=True safeguard when loading pipelines from Hu…

diffusers | Remote | Supply Chain
May 14, 2026 May 19, 2026
May 14, 2026
May 19, 2026
7.6 HIGH
CVE-2026-44516 — Valtimo: Sensitive data exposure through HTTP request/response logging in LoggingRestClie…

Valtimo is an open-source business process automation platform. From 12.4.0 to 12.33.0 and 13.26.0, the LoggingRestClientCustomizer in the web module automatically intercepts all outgoing HTTP calls …

Remote | Information Disclosure
May 14, 2026 May 14, 2026
May 14, 2026
May 14, 2026
2.3 LOW
CVE-2026-44515 — Nextcloud News: Authenticated blind SSRF via feed URL

Nextcloud News is an RSS/Atom feed reader. Prior to 28.3.0-beta.1, Nextcloud News allows authenticated users to add feeds by providing a feed URL (via the web interface or the API). In affected versi…

news | Remote | Server-Side Request Forgery
May 14, 2026 May 14, 2026
May 14, 2026
May 14, 2026
6.5 MEDIUM
CVE-2026-44514 — Kubetail: Cross-Site WebSocket Hijacking allows attacker to read Kubernetes logs from aut…

Kubetail is a real-time logging dashboard for Kubernetes. Prior to 0.14.0, Kubetail's dashboard exposes WebSocket endpoints that did not adequately validate the Origin header on connection upgrade. A…

Remote | Authentication
May 14, 2026 May 14, 2026
May 14, 2026
May 14, 2026
8.8 HIGH
CVE-2026-44513 — Diffusers: `trust_remote_code` bypass via `custom_pipeline` and local custom components

Diffusers is the a library for pretrained diffusion models. Prior to 0.38.0, a trust_remote_code bypass in DiffusionPipeline.from_pretrained allows arbitrary remote code execution despite the user p…

diffusers | Remote | Supply Chain
May 14, 2026 May 19, 2026
May 14, 2026
May 19, 2026
7.4 HIGH
CVE-2026-44511 — Katalyst Koi: Session cookies can be replayed after user logout

Katalyst Koi is a framework for building Rails admin functionality. Prior to 4.20.0 and 5.6.0, admin session cookies were not invalidated when an admin user logged out. An attacker with access to a v…

Remote | Authentication
May 14, 2026 May 14, 2026
May 14, 2026
May 14, 2026
2.5 LOW
CVE-2026-44348 — PoDoFo: Double-free vulnerability in compute_hash_to_sign()

PoDoFo is a C++17 PDF manipulation library. From 1.0.0 to before 1.0.4, a double-free vulnerability exists in compute_hash_to_sign() in src/podofo/private/OpenSSLInternal_Ripped.cpp. If EVP_DigestFin…

podofo | Memory Corruption
May 14, 2026 May 14, 2026
May 14, 2026
May 14, 2026
5.8 MEDIUM
CVE-2026-44312 — css_parser allows to MITM included https css urls

css_parser is a Ruby CSS parser. Prior to 2.1.0 and 1.22.0, the CSS Parser gem does not validate HTTPS connections, allowing a Man-in-the-Middle (MITM) attacker to inject or modify CSS content when s…

Remote | Misconfiguration
May 14, 2026 May 15, 2026
May 14, 2026
May 15, 2026
9.1 CRITICAL
CVE-2026-42555 — Valtimo: SpEL injection via StandardEvaluationContext allows Remote Code Execution by adm…

Valtimo is an open-source business process automation platform. com.ritense.valtimo:document from 12.0.0 to before 12.32.0, com.ritense.valtimo:case from 13.0.0 to before 13.23.0, and com.ritense.val…

Remote | Injection
May 14, 2026 May 14, 2026
May 14, 2026
May 14, 2026
8.6 HIGH
CVE-2026-20224 — Cisco Catalyst SD-WAN Manager XML External Entity Injection Vulnerability

A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an unauthenticated, remote attacker to read arbitrary files that are stored in an affected system.…

catalyst_sd-wan_manager | Remote | XML External Entity
May 14, 2026 May 14, 2026
May 14, 2026
May 14, 2026
Showing 20 of 7172 Results