Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.5 HIGH
CVE-2025-71252 — "Modem IMS Remote Denial of Service Vulnerability"

In Modem IMS, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed.

android sc7731e sc9832e sc9863a t310 t610 +11 more | Denial of Service
May 06, 2026 May 11, 2026
May 06, 2026
May 11, 2026
7.5 HIGH
CVE-2025-71251 — Apache IMS Remote Denial of Service Vulnerability

In IMS, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed.

android sc7731e sc9832e sc9863a t310 t610 +11 more | Denial of Service
May 06, 2026 May 11, 2026
May 06, 2026
May 11, 2026
3.4 LOW
CVE-2026-44405 — Paramiko RSA Key SHA-1 Vulnerability

In Paramiko through 4.0.0 before a448945, rsakey.py allows the SHA-1 algorithm.

paramiko | Cryptography
May 06, 2026 May 07, 2026
May 06, 2026
May 07, 2026
7.6 HIGH
CVE-2026-40934 — jupyter-server authentication cookies remain valid after password reset due to static coo…

Jupyter Server is the backend for Jupyter web applications. In versions 2.17.0 and earlier, the secret used to sign authentication cookies is persisted to a static file at ~/.local/share/jupyter/runt…

jupyter_server | Remote | Authentication
May 05, 2026 May 11, 2026
May 05, 2026
May 11, 2026
7.6 HIGH
CVE-2026-40110 — jupyter-server CORS origin validation bypass via unanchored regex in allow_origin_pat

Jupyter Server is the backend for Jupyter web applications. In versions 2.17.0 and earlier, the Origin header validation uses Python's re.match() to check incoming origins against the allow_origin_pa…

jupyter_server | Remote | Misconfiguration
May 05, 2026 May 11, 2026
May 05, 2026
May 11, 2026
8.2 HIGH
CVE-2026-40075 — OpenMRS Core arbitrary file read via path traversal in ModuleResourcesServlet

OpenMRS Core is an open source electronic medical record system platform. In versions 2.7.8 and earlier and versions 2.8.0 through 2.8.5, the `/openmrs/moduleResources/{moduleid}` endpoint is vulnera…

openmrs | Remote | Path Traversal
May 05, 2026 May 12, 2026
May 05, 2026
May 12, 2026
9.8 CRITICAL
CVE-2026-28780 — Apache HTTP Server: buffer overflow in mod_proxy_ajp via ajp_msg_check_header()

Heap-based Buffer Overflow vulnerability in mod_proxy_ajp of Apache HTTP Server. If mod_proxy_ajp connects to a malicious AJP server this AJP server can send a malicious AJP message back to mod_proxy…

http_server | Remote | Memory Corruption
May 05, 2026 May 06, 2026
May 05, 2026
May 06, 2026
Showing 20 of 7127 Results