Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.8 HIGH
CVE-2026-40068 — Claude Code arbitrary code execution via git worktree commondir trust dialog bypass

In versions 2.1.63 through 2.1.83 of Claude Code, the folder trust determination logic used the git worktree commondir file without validating its contents. An attacker could craft a malicious reposi…

claude_code claude_desktop | Remote | Misconfiguration
May 05, 2026 May 12, 2026
May 05, 2026
May 12, 2026
8.8 HIGH
CVE-2026-39852 — Quarkus authorization bypass via semicolon path normalization inconsistency

Quarkus is a Java framework for building cloud-native applications. In versions prior to 3.20.6.1, 3.27.3.1, 3.33.1.1, 3.35.1.1, 3.34.7, and 3.35.2, a path normalization inconsistency between the sec…

quarkus | Remote | Authorization
May 05, 2026 May 08, 2026
May 05, 2026
May 08, 2026
8.8 HIGH
CVE-2026-39849 — Pi-hole FTL remote code execution via newline injection in dns.interface configuration

Pi-hole FTL is the core engine of the Pi-hole network-level advertisement and tracker blocker. In versions before 6.6.1, the `dns.interface` configuration field in Pi-hole FTL accepted newline charac…

ftldns | Remote | Injection
May 05, 2026 May 12, 2026
May 05, 2026
May 12, 2026
6.5 MEDIUM
CVE-2026-39402 — lxc lxc-user-nic insufficient ownership validation allows cross-tenant OVS port deletion

lxc is a Linux container runtime. In the setuid helper lxc-user-nic, the delete path contains a logic flaw in the find_line() function that allows an unprivileged user to delete OVS-attached network …

lxc | Denial of Service
May 05, 2026 May 12, 2026
May 05, 2026
May 12, 2026
7.2 HIGH
CVE-2026-39383 — Gotenberg unauthenticated blind SSRF via unfiltered webhook URL

Gotenberg is an API-based document conversion tool. In version 8.29.1, an unauthenticated attacker with network access can force the server to make outbound HTTP POST requests to arbitrary internal o…

gotenberg | Remote | Server-Side Request Forgery
May 05, 2026 May 08, 2026
May 05, 2026
May 08, 2026
9.8 CRITICAL
CVE-2026-35579 — CoreDNS TSIG authentication bypass on gRPC, QUIC, DoH, and DoH3 transports

CoreDNS is a DNS server written in Go. In versions prior to 1.14.3, the gRPC, QUIC, DoH, and DoH3 transport implementations incorrectly handle TSIG authentication. For gRPC and QUIC, the server check…

coredns | Remote | Authentication
May 05, 2026 May 08, 2026
May 05, 2026
May 08, 2026
5.3 MEDIUM
CVE-2026-35527 — Incus blind SSRF via image import preflight HEAD request

Incus is an open source container and virtual machine manager. In versions prior to 7.0.0, the image import flow issues an outbound HEAD request to a user-supplied URL before validating the request a…

incus | Remote | Server-Side Request Forgery
May 05, 2026 May 07, 2026
May 05, 2026
May 07, 2026
Showing 20 of 7127 Results