Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
4.3 MEDIUM
CVE-2026-42565 — @workos/authkit-session: Open Redirect via state-derived redirect target

@workos/authkit-session is a toolkit for building WorkOS AuthKit framework integrations. Prior to 0.5.1, an open redirect vulnerability exists in AuthService.handleCallback due to insufficient valida…

Remote | Misconfiguration
May 11, 2026 May 13, 2026
May 11, 2026
May 13, 2026
5.5 MEDIUM
CVE-2026-42050 — ImageMagick: Stack buffer overflow in XTileImage

ImageMagick is free and open-source software used for editing and manipulating digital images. Prior to 7.1.2-21 and 6.9.13-46, a malicious MIFF file could trigger an overflow when a user opens it in…

imagemagick | Memory Corruption
May 11, 2026 May 13, 2026
May 11, 2026
May 13, 2026
8.8 HIGH
CVE-2026-36734 — EDIMAX BR-6428nS Command Injection Vulnerability

EDIMAX BR-6428nS V3 1.15 is vulnerable to Command Injection. An authenticated attacker with access to the network can submit crafted input to the WLAN configuration functionality. Due to insufficient…

Remote | Injection
May 11, 2026 May 13, 2026
May 11, 2026
May 13, 2026
7.5 HIGH
CVE-2026-2614 — Arbitrary File Read via Prompt Tag Source Validation Bypass in mlflow/mlflow

A vulnerability in the `_create_model_version()` handler of `mlflow/server/handlers.py` in mlflow/mlflow versions 3.9.0 and earlier allows an unauthenticated remote attacker to read arbitrary files f…

mlflow | Remote | Path Traversal
May 11, 2026 May 27, 2026
May 11, 2026
May 27, 2026
7.3 HIGH
CVE-2022-4988 — Alien::FreeImage versions through 1.001 for Perl contains several vulnerable libraries

Alien::FreeImage versions through 1.001 for Perl contains several vulnerable libraries. Alien::FreeImage contains version 3.17.0 of the FreeImage library from 2017, which has known vulnerabilities s…

Remote | Supply Chain
May 11, 2026 May 13, 2026
May 11, 2026
May 13, 2026
Showing 20 of 7485 Results