Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.8 HIGH
CVE-2026-48116 — AnythingLLM: RCE via ripgrep --pre argument injection in filesystem-search-files agent sk…

AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. Prior to 1.13.0, the filesystem-search-files agent skill passes its LLM-con…

anythingllm | Remote | Injection
May 28, 2026 May 30, 2026
May 28, 2026
May 30, 2026
4.3 MEDIUM
CVE-2026-47713 — AnythingLLM: Legacy mobile device tokens bypass multi-user workspace scoping after mode m…

AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. Prior to 1.13.0, an approved mobile device token created in single-user mod…

anythingllm | Remote | Authentication
May 28, 2026 Jun 03, 2026
May 28, 2026
Jun 03, 2026
5.3 MEDIUM
CVE-2026-45410 — Time-based user enumeration in TREK authentication endpoint

TREK is a collaborative travel planner. Prior to 3.0.18, early return on missing user during login flow allowed an attacker to enumerate valid user accounts via response timing discrepancy. When an e…

trek | Remote | Authentication
May 28, 2026 May 29, 2026
May 28, 2026
May 29, 2026
2.5 LOW
CVE-2026-45403 — AnythingLLM: filesystem-copy-file follows nested symlinks and copies files from outside t…

AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. Prior to 1.13.0, the AnythingLLM agent filesystem copy tool validates only …

anythingllm | Path Traversal
May 28, 2026 Jun 02, 2026
May 28, 2026
Jun 02, 2026
4.7 MEDIUM
CVE-2026-45366 — typescript-utcp: SSRF via attacker-controlled OpenAPI servers[0].url in HTTP communicatio…

typescript-utcp is a typescript implementation of UTCP. Prior to 1.1.2, the @utcp/http package is vulnerable to a blind Server-Side Request Forgery (SSRF) caused by a trust-boundary inconsistency bet…

Remote | Server-Side Request Forgery
May 28, 2026 Jun 01, 2026
May 28, 2026
Jun 01, 2026
7.3 HIGH
CVE-2026-45364 — Better Auth: Rate limiter keys IPv6 addresses individually and is bypassable via prefix r…

Better Auth is an authentication and authorization library for TypeScript. Prior to 1.4.17 and 1.5.0-beta.9, Better Auth's HTTP rate limiter keyed each request by the exact textual IP address it rece…

better_auth | Remote | Authentication
May 28, 2026 Jun 01, 2026
May 28, 2026
Jun 01, 2026
8.1 HIGH
CVE-2026-45344 — LinkAce: Setup database password newline injection enables pre-auth RCE on uninitialized …

LinkAce is a self-hosted archive to collect website links. Prior to 2.5.6, the setup database configuration flow on uninitialized LinkAce instances accepts attacker-controlled database credential fie…

linkace | Remote | Injection
May 28, 2026 Jun 01, 2026
May 28, 2026
Jun 01, 2026
8.5 HIGH
CVE-2026-45343 — LinkAce - Stored XSS via Unsanitized SSO User's Name Rendered in Admin Audit Log Allows S…

LinkAce is a self-hosted archive to collect website links. Prior to 2.5.6, LinkAce contains a stored cross-site scripting vulnerability that allows a low-privilege user to execute arbitrary JavaScrip…

linkace | Remote | Cross-Site Scripting
May 28, 2026 May 30, 2026
May 28, 2026
May 30, 2026
7.1 HIGH
CVE-2026-45342 — LinkAce: IDOR in Update Policies Allows Any Authenticated User to Overwrite Other Users' …

LinkAce is a self-hosted archive to collect website links. Prior to 2.5.6, LinkAce contains an Insecure Direct Object Reference vulnerability in the authorization policy layer that allows any authent…

linkace | Remote | Authorization
May 28, 2026 May 29, 2026
May 28, 2026
May 29, 2026
5.4 MEDIUM
CVE-2026-45023 — AutoGP: Credit system bypassed via direct block execution in POST /api/blocks/{block_id}/…

AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Prior to 0.6.59, POST /api/blocks/{block_id}/execute endpoint executes block…

autogpt_platform | Remote | Authentication
May 28, 2026 May 29, 2026
May 28, 2026
May 29, 2026
8.1 HIGH
CVE-2026-44973 — Billy: Path traversal vulnerabilities

Billy is an interface filesystem abstraction for Go. Prior to 5.9.0, multiple path traversal issues exist across different components of go-billy. Insufficient path sanitization and boundary enforcem…

Remote | Path Traversal
May 28, 2026 May 29, 2026
May 28, 2026
May 29, 2026
5.5 MEDIUM
CVE-2026-44885 — Portainer: Path traversal in backup archive extraction allows arbitrary file write

Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. From 2.33.0 to before …

portainer | Remote | Path Traversal
May 28, 2026 Jun 01, 2026
May 28, 2026
Jun 01, 2026
6.5 MEDIUM
CVE-2026-44884 — Portainer: Missing authorization on custom template file endpoint exposes template content

Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. From 2.33.0 to before …

portainer | Remote | Authorization
May 28, 2026 Jun 01, 2026
May 28, 2026
Jun 01, 2026
7.7 HIGH
CVE-2026-44883 — Portainer: JWT accepted in URL query leaks tokens to logs and referers

Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. From 2.33.0 to before …

portainer | Remote | Authentication
May 28, 2026 Jun 02, 2026
May 28, 2026
Jun 02, 2026
8.1 HIGH
CVE-2026-44882 — Portainer: Kubernetes middleware continues after token validation failure, bypassing endp…

Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. From 2.33.0 to before …

portainer | Remote | Authorization
May 28, 2026 Jun 01, 2026
May 28, 2026
Jun 01, 2026
9.9 CRITICAL
CVE-2026-44881 — Portainer: Arbitrary File Read via Git Symlink Injection in Stack Auto-Update

Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. From 2.33.0 to before …

portainer | Remote | Path Traversal
May 28, 2026 Jun 01, 2026
May 28, 2026
Jun 01, 2026
8.5 HIGH
CVE-2026-44850 — Portainer: Bind-mount restriction bypass via HostConfig.Mounts

Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. From 2.33.0 to before …

portainer | Remote | Misconfiguration
May 28, 2026 Jun 01, 2026
May 28, 2026
Jun 01, 2026
9.4 CRITICAL
CVE-2026-44849 — Portainer: Endpoint security bypass via Swarm service create/update

Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. From 2.33.0 to before …

portainer | Remote | Authorization
May 28, 2026 Jun 01, 2026
May 28, 2026
Jun 01, 2026
9.4 CRITICAL
CVE-2026-44848 — Portainer: Missing authorization on Docker plugin endpoints allows host RCE

Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. From 2.33.0 to before …

portainer | Remote | Authorization
May 28, 2026 Jun 01, 2026
May 28, 2026
Jun 01, 2026
8.7 HIGH
CVE-2026-39929 — Lakeside SysTrack Agent LsiAgent.exe Out-of-Bounds Read via UDP

Lakeside SysTrack Agent versions prior to 11.2.1.28, 11.3.0.38, 11.4.0.24, 11.5.0.15 contain an out-of-bounds read vulnerability in the Command ID 30 UDP packet handler that allows remote attackers t…

Remote | Denial of Service
May 28, 2026 Jun 01, 2026
May 28, 2026
Jun 01, 2026
Showing 20 of 7227 Results