Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.1 HIGH
CVE-2026-42315 — pyLoad: Path Traversal via Package Folder Name in set_package_data

pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, when passing a folder name in the set_package_data() API function call inside the data object with key "_…

pyload | Remote | Path Traversal
May 11, 2026 May 11, 2026
May 11, 2026
May 11, 2026
6.5 MEDIUM
CVE-2026-42314 — pyLoad: Path Traversal via Package Folder Name

pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, package folder names are sanitized using insufficient string replacement. The pattern ....// becomes .._ …

pyload | Remote | Path Traversal
May 11, 2026 May 11, 2026
May 11, 2026
May 11, 2026
8.3 HIGH
CVE-2026-42313 — pyload-ng: non-admin SETTINGS users can redirect all outbound traffic through an attacker…

pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, the set_config_value() API method (@permission(Perms.SETTINGS)) in src/pyload/core/api/__init__.py gates …

pyload | Remote | Authorization
May 11, 2026 May 11, 2026
May 11, 2026
May 11, 2026
6.8 MEDIUM
CVE-2026-42312 — pyload-ng: non-admin SETTINGS users can disable outbound TLS peer verification

pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, the set_config_value() API method (@permission(Perms.SETTINGS)) in src/pyload/core/api/__init__.py gates …

pyload | Remote | Misconfiguration
May 11, 2026 May 11, 2026
May 11, 2026
May 11, 2026
8.0 HIGH
CVE-2026-41431 — Zen Browser MAR updater ships with signature verification removed — unsigned updates acce…

Zen is a firefox-based browser. Prior to 1.19.9b, Zen Browser ships a Mozilla Application Resource (MAR) updater (org.mozilla.updater) that has had all MAR signature verification stripped from the Fi…

Remote | Supply Chain
May 11, 2026 May 11, 2026
May 11, 2026
May 11, 2026
6.4 MEDIUM
CVE-2026-41257 — jq: Signed-int overflow in `stack_reallocate` (jq VM stack)

jq is a command-line JSON processor. In 1.8.1 and earlier, the jq bytecode VM's data stack tracks its allocation size in a signed int. When the stack grows beyond ≈1 GiB (via deeply nested generator …

| Memory Corruption
May 11, 2026 May 11, 2026
May 11, 2026
May 11, 2026
5.5 MEDIUM
CVE-2026-41256 — jq: Embedded NUL truncates top-level jq programs loaded with -f

jq is a command-line JSON processor. In 1.8.1 and earlier, Top-level jq programs loaded from a file with -f are truncated at the first embedded NUL byte on current upstream HEAD. A crafted filter fil…

| Misconfiguration
May 11, 2026 May 11, 2026
May 11, 2026
May 11, 2026
5.7 MEDIUM
CVE-2026-41250 — XSS in taiga-front

Taiga is a project management platform for startups and agile developers. Prior 6.9.1, Taiga front is vulnerable to stored XSS. This vulnerability is fixed in 6.9.1.

Remote | Cross-Site Scripting
May 11, 2026 May 11, 2026
May 11, 2026
May 11, 2026
5.4 MEDIUM
CVE-2026-40612 — jq: Stack overflow via unbounded recursion in jv_contains

jq is a command-line JSON processor. In 1.8.1 and earlier, jv_contains recurses into nested arrays/objects with no depth limit. With a sufficiently nested input structure (built programmatically with…

| Denial of Service
May 11, 2026 May 11, 2026
May 11, 2026
May 11, 2026
0.0 NA
CVE-2026-3609 — XIGNCODE3 xhunter1.sys kernel driver contains a Privilege Escalation Vulnerability

Wellbia's XIGNCODE3 xhunter1.sys kernel driver Privilege Escalation Vulnerability provides access to IRP_MJ_REITS command interface, which allows any user process to request a PROCESS_ALL_ACCESS. Cr…

| Authorization
May 11, 2026 May 11, 2026
May 11, 2026
May 11, 2026
5.1 MEDIUM
CVE-2026-3048 — Nexus Repository 3 - Improper LDAP Referral Handling

An authenticated administrator who configures or tests LDAP connectivity in Sonatype Nexus Repository Manager versions 3.0.0 through 3.91.1 may be able to initiate unintended server-side connections …

Remote | Server-Side Request Forgery
May 11, 2026 May 11, 2026
May 11, 2026
May 11, 2026
5.4 MEDIUM
CVE-2026-38569 — HireFlow Cross Site Scripting (XSS)

HireFlow v1.2 is vulnerable to Cross Site Scripting (XSS) in candidate_detail.html via the Resume or Feedback Comment fields via POST /candidates/add or POST /feedback/add.

Remote | Cross-Site Scripting
May 11, 2026 May 11, 2026
May 11, 2026
May 11, 2026
8.1 HIGH
CVE-2026-38568 — HireFlow Improper Authorization Vulnerability

HireFlow v1.2 is vulnerable to Incorrect Access Control. The application does not enforce object-level authorization on the /candidate/<id> and /interview/<id> endpoints. The route handlers retrieve …

Remote | Authorization
May 11, 2026 May 11, 2026
May 11, 2026
May 11, 2026
0.0 NA
CVE-2026-38567 — HireFlow SQL Injection Vulnerability

HireFlow v1.2 is vulnerable to SQL injection in the /login and /search endpoints. User-supplied input is concatenated directly into SQL queries without parameterization. An unauthenticated attacker c…

| Injection
May 11, 2026 May 11, 2026
May 11, 2026
May 11, 2026
0.0 NA
CVE-2026-38566 — HireFlow CSRF Vulnerability

HireFlow v1.2 does not implement CSRF token validation on any state-changing POST endpoint. All forms (password change at /profile, candidate deletion at /candidates/delete/<id>, feedback submission …

| Cross-Site Request Forgery
May 11, 2026 May 11, 2026
May 11, 2026
May 11, 2026
0.0 NA
CVE-2026-36983 — D-Link DCS-932L Command Injection Vulnerability

D-Link DCS-932L v2.18.01 is vulnerable to Command Injection in the function sub_42EF14 of the file /bin/alphapd. The manipulation of the argument LightSensorControl leads to command injection.

| Injection
May 11, 2026 May 11, 2026
May 11, 2026
May 11, 2026
0.0 NA
CVE-2026-36962 — MuuCMF SQL Injection

SQL Injection in MuuCMF T6 v1.9.4.20260115 allows an unauthenticated attacker to compromise the entire database, achieve unauthorized administrative access, and potentially gain remote code execution…

| Injection
May 11, 2026 May 11, 2026
May 11, 2026
May 11, 2026
0.0 NONE
CVE-2026-34095 — action=raw with Special:Mypage subpage title responds with "Content-Type: text/html" on c…

Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Actions/ActionEntryPoint.Php, includes/Request/FauxResponse.Php. This issue affects …

Remote
May 11, 2026 May 11, 2026
May 11, 2026
May 11, 2026
2.0 LOW
CVE-2026-34094 — Customized help link for page protection indicator is relative to subpage name, because t…

Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Page/Article.Php. This issue affects MediaWiki: from * before 1.43.7, 1.44.4, 1.45.2.

Remote
May 11, 2026 May 11, 2026
May 11, 2026
May 11, 2026
1.1 LOW
CVE-2026-34093 — Special:UserRights allows viewing user rights from private wiki

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Specials/SpecialUserRights.P…

Remote | Information Disclosure
May 11, 2026 May 11, 2026
May 11, 2026
May 11, 2026
Showing 20 of 5777 Results