Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.7 HIGH
CVE-2026-41524 — Ajax30/BraveCMS-2.0: Stored XSS in Page / Article Content

Brave CMS is an open-source CMS. Prior to commit 6c56603, page and article body content entered through the CKEditor rich-text editor is stored verbatim in the database and subsequently rendered with…

bravecms | Remote | Cross-Site Scripting
May 08, 2026 May 08, 2026
May 08, 2026
May 08, 2026
5.4 MEDIUM
CVE-2026-41487 — Langfuse: Improper role-based-access control in Langfuse LLM connection management allowe…

Langfuse is an open source large language model engineering platform. From version 3.68.0 to before version 3.167.0, there is a role-based-access control flaw in the LLM connection update flow. An a…

langfuse | Remote | Authorization
May 08, 2026 May 13, 2026
May 08, 2026
May 13, 2026
6.5 MEDIUM
CVE-2026-41308 — Password Pusher: JSON API `/p.json` file upload alias bypasses file-push authentication

Password Pusher is an open source application to communicate sensitive information over the web. Prior to versions 1.69.3 and 2.4.2, a security issue in OSS PasswordPusher allowed unauthenticated cre…

password_pusher password_pusher | Remote | Authentication
May 08, 2026 Jun 05, 2026
May 08, 2026
Jun 05, 2026
7.5 HIGH
CVE-2026-38361 — Fohrloop Dash-Uploader Remote Code Execution Vulnerability

An issue in fohrloop dash-uploader v.0.1.0 through v.0.7.0a2 allows a remote attacker to execute arbitrary code via the dash_uploader/httprequesthandler.py, dash_uploader/upload.py in the Upload func…

dash-uploader | Remote | Injection
May 08, 2026 May 12, 2026
May 08, 2026
May 12, 2026
9.8 CRITICAL
CVE-2026-37431 — Beauty Parlour Management System SQL Injection

Beauty Parlour Management System v1.1 was discovered to contain a SQL injection vulnerability via the aptnumber parameter in the /appointment-detail.php endpoint. This vulnerability allows attackers …

Remote | Injection
May 08, 2026 May 08, 2026
May 08, 2026
May 08, 2026
8.6 HIGH
CVE-2025-67486 — Dolibarr has an Authenticated Remote Code Execution via eval() injection in user extrafie…

Dolibarr is an enterprise resource planning (ERP) and customer relationship management (CRM) software package. Versions 22.0.2 and earlier contains an authenticated remote code execution vulnerabilit…

dolibarr_erp\/crm | Remote | Injection
May 08, 2026 May 12, 2026
May 08, 2026
May 12, 2026
Showing 20 of 6906 Results