Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.2 MEDIUM
CVE-2026-43894 — jq: Wild stack write via signed-integer overflow in decNumber D2U() macro

jq is a command-line JSON processor. In 1.8.1 and earlier, when decNumberFromString is given a number literal of INT_MAX-1 (2147483646) digits, the D2U() macro overflows during signed-int arithmetic.…

| Memory Corruption
May 11, 2026 May 11, 2026
May 11, 2026
May 11, 2026
8.1 HIGH
CVE-2026-43640 — Bitwarden Server < 2026.4.1 Authentication Bypass via SCIM API Key

Bitwarden Server prior to v2026.4.1 does not require master-password re-authentication when retrieving or rotating an organization's SCIM API key, allowing an authenticated user with SCIM management …

Remote | Authentication
May 11, 2026 May 11, 2026
May 11, 2026
May 11, 2026
8.0 HIGH
CVE-2026-43639 — Bitwarden Server < 2026.4.0 Missing Authorization via Provider Clients

Bitwarden Server prior to v2026.4.0 contains a missing authorization vulnerability that allows a provider service user to add an arbitrary organization to their provider via `POST /providers/{provide…

Remote | Authorization
May 11, 2026 May 11, 2026
May 11, 2026
May 11, 2026
5.4 MEDIUM
CVE-2026-43638 — Bitwarden Server < 2026.4.1 Missing Authorization via Organization Cipher Import

Bitwarden Server prior to v2026.4.1 contains a missing authorization vulnerability that allows any authenticated user to write ciphers into an arbitrary organization via `POST /ciphers/import-organiz…

Remote | Authorization
May 11, 2026 May 11, 2026
May 11, 2026
May 11, 2026
2.3 LOW
CVE-2026-42865 — Inbox Zero: Cross-account cleaner email stream exposure

Inbox Zero is an AI personal assistant for email. Prior to 2.29.3, the cleaner email stream endpoint used a shared Redis subscription listener, which could deliver thread events for one authenticated…

Remote | Information Disclosure
May 11, 2026 May 11, 2026
May 11, 2026
May 11, 2026
8.5 HIGH
CVE-2026-42860 — Open edx Enterprise Service: SSRF via SAML metadata URL in sync_provider_data endpoint

The Open edx Enterprise Service app provides enterprise features to the Open edX platform. From 7.0.2 to 7.0.4, the sync_provider_data endpoint in SAMLProviderDataViewSet fetches SAML metadata from a…

Remote | Server-Side Request Forgery
May 11, 2026 May 11, 2026
May 11, 2026
May 11, 2026
8.1 HIGH
CVE-2026-42859 — Neat VNC: Buffer overflow due to oversized RSA public keys

Neat VNC is a VNC server library. Prior to 0.9.6, a pre-authentication stack buffer overflow exists in neatvnc in the RSA-AES security type handler. An unauthenticated remote attacker who can reach t…

Remote | Memory Corruption
May 11, 2026 May 11, 2026
May 11, 2026
May 11, 2026
8.5 HIGH
CVE-2026-42858 — Open edX Platform: Server-Side Request Forgery (SSRF) in SAML Provider Data Sync Endpoint

Open edX Platform enables the authoring and delivery of online learning at any scale. The sync_provider_data endpoint in SAMLProviderDataViewSet allows authenticated Enterprise Admin users to supply …

Remote | Server-Side Request Forgery
May 11, 2026 May 11, 2026
May 11, 2026
May 11, 2026
4.6 MEDIUM
CVE-2026-42857 — Open edX Platform: Stored CSS Injection in Email Notifications via Incomplete HTML Saniti…

Open edX Platform enables the authoring and delivery of online learning at any scale. The HTML sanitizer clean_thread_html_body() used for discussion notification emails fails to remove <style> tags …

Remote | Cross-Site Scripting
May 11, 2026 May 11, 2026
May 11, 2026
May 11, 2026
8.7 HIGH
CVE-2026-42856 — Network-AI: Missing authentication on MCP HTTP endpoint allows unauthenticated privileged…

Network-AI is a TypeScript/Node.js multi-agent orchestrator. Prior to 5.1.3, the MCP HTTP transport accepts JSON-RPC tools/call requests with no authentication, session, origin, or token check, and d…

Remote | Authentication
May 11, 2026 May 11, 2026
May 11, 2026
May 11, 2026
6.5 MEDIUM
CVE-2026-42316 — KQL injection via kusto.tables.topics.mapping in kafka-sink-azure-kusto

kafka-sink-azure-kusto Kafka Connect plugin is the official Microsoft sink for Azure Data Explorer (Kusto). Prior to 5.2.3, kafka-sink-azure-kusto did not sanitize user-controlled values inside the k…

Remote | Injection
May 11, 2026 May 11, 2026
May 11, 2026
May 11, 2026
8.1 HIGH
CVE-2026-42315 — pyLoad: Path Traversal via Package Folder Name in set_package_data

pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, when passing a folder name in the set_package_data() API function call inside the data object with key "_…

pyload | Remote | Path Traversal
May 11, 2026 May 11, 2026
May 11, 2026
May 11, 2026
6.5 MEDIUM
CVE-2026-42314 — pyLoad: Path Traversal via Package Folder Name

pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, package folder names are sanitized using insufficient string replacement. The pattern ....// becomes .._ …

pyload | Remote | Path Traversal
May 11, 2026 May 11, 2026
May 11, 2026
May 11, 2026
8.3 HIGH
CVE-2026-42313 — pyload-ng: non-admin SETTINGS users can redirect all outbound traffic through an attacker…

pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, the set_config_value() API method (@permission(Perms.SETTINGS)) in src/pyload/core/api/__init__.py gates …

pyload | Remote | Authorization
May 11, 2026 May 11, 2026
May 11, 2026
May 11, 2026
6.8 MEDIUM
CVE-2026-42312 — pyload-ng: non-admin SETTINGS users can disable outbound TLS peer verification

pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, the set_config_value() API method (@permission(Perms.SETTINGS)) in src/pyload/core/api/__init__.py gates …

pyload | Remote | Misconfiguration
May 11, 2026 May 11, 2026
May 11, 2026
May 11, 2026
8.0 HIGH
CVE-2026-41431 — Zen Browser MAR updater ships with signature verification removed — unsigned updates acce…

Zen is a firefox-based browser. Prior to 1.19.9b, Zen Browser ships a Mozilla Application Resource (MAR) updater (org.mozilla.updater) that has had all MAR signature verification stripped from the Fi…

Remote | Supply Chain
May 11, 2026 May 11, 2026
May 11, 2026
May 11, 2026
6.4 MEDIUM
CVE-2026-41257 — jq: Signed-int overflow in `stack_reallocate` (jq VM stack)

jq is a command-line JSON processor. In 1.8.1 and earlier, the jq bytecode VM's data stack tracks its allocation size in a signed int. When the stack grows beyond ≈1 GiB (via deeply nested generator …

| Memory Corruption
May 11, 2026 May 11, 2026
May 11, 2026
May 11, 2026
5.5 MEDIUM
CVE-2026-41256 — jq: Embedded NUL truncates top-level jq programs loaded with -f

jq is a command-line JSON processor. In 1.8.1 and earlier, Top-level jq programs loaded from a file with -f are truncated at the first embedded NUL byte on current upstream HEAD. A crafted filter fil…

| Misconfiguration
May 11, 2026 May 11, 2026
May 11, 2026
May 11, 2026
5.7 MEDIUM
CVE-2026-41250 — XSS in taiga-front

Taiga is a project management platform for startups and agile developers. Prior 6.9.1, Taiga front is vulnerable to stored XSS. This vulnerability is fixed in 6.9.1.

Remote | Cross-Site Scripting
May 11, 2026 May 11, 2026
May 11, 2026
May 11, 2026
5.4 MEDIUM
CVE-2026-40612 — jq: Stack overflow via unbounded recursion in jv_contains

jq is a command-line JSON processor. In 1.8.1 and earlier, jv_contains recurses into nested arrays/objects with no depth limit. With a sufficiently nested input structure (built programmatically with…

| Denial of Service
May 11, 2026 May 11, 2026
May 11, 2026
May 11, 2026
Showing 20 of 5787 Results