Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.5 MEDIUM
CVE-2026-28493 — ImageMagick has a Integer Overflow leading to out of bounds write in SIXEL decoder

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to versions 7.1.2-16, an integer overflow vulnerability exists in the SIXEL decoer. The vulnerabil…

imagemagick | Remote | Memory Corruption
Mar 10, 2026 Mar 12, 2026
Mar 10, 2026
Mar 12, 2026
4.3 MEDIUM
CVE-2026-28433 — Misskey lacks resource ownership validation

Misskey is an open source, federated social media platform. All Misskey servers running versions 10.93.0 and later, but prior to 2026.3.1, contain a vulnerability that allows importing other users' d…

misskey | Remote | Authorization
Mar 10, 2026 Mar 13, 2026
Mar 10, 2026
Mar 13, 2026
7.5 HIGH
CVE-2026-28432 — HTTP signature verification can be bypassed

Misskey is an open source, federated social media platform. All Misskey servers prior to 2026.3.1 contain a vulnerability that allows bypassing HTTP signature verification. Although this is a vulnera…

misskey | Remote | Misconfiguration
Mar 10, 2026 Mar 13, 2026
Mar 10, 2026
Mar 13, 2026
9.2 CRITICAL
CVE-2026-28431 — Misskey lacks proper authorization checks and input validation

Misskey is an open source, federated social media platform. All Misskey servers running versions 8.45.0 and later, but prior to 2026.3.1, contain a vulnerability that allows bad actors access to data…

misskey | Remote | Authorization
Mar 10, 2026 Mar 13, 2026
Mar 10, 2026
Mar 13, 2026
8.8 HIGH
CVE-2026-26982 — Ghostty affected by arbitrary command execution via control characters in paste and drag-…

Ghostty is a cross-platform terminal emulator. Ghostty allows control characters such as 0x03 (Ctrl+C) in pasted and dropped text. These can be used to execute arbitrary commands in some shell enviro…

ghostty | Remote | Injection
Mar 10, 2026 Mar 13, 2026
Mar 10, 2026
Mar 13, 2026
6.0 MEDIUM
CVE-2026-1776 — Camaleon CMS AWS Uploader Authenticated Path Traversal Arbitrary File Read

Camaleon CMS versions 2.4.5.0 through 2.9.0, prior to commit f54a77e, contain a path traversal vulnerability in the AWS S3 uploader implementation that allows authenticated users to read arbitrary fi…

camaleon_cms | Remote | Path Traversal
Mar 10, 2026 Mar 11, 2026
Mar 10, 2026
Mar 11, 2026
Showing 20 of 6626 Results