Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.5 MEDIUM
CVE-2025-31982 — HCL BigFix Service Management (SM) had directories that were not linked or publicly visib…

HCL BigFix Service Management (SM) had directories that were not linked or publicly visible but could be accessed directly. This could allow an increased risk of information disclosure or misuse of s…

bigfix_service_management | Remote | Information Disclosure
May 06, 2026 May 06, 2026
May 06, 2026
May 06, 2026
4.6 MEDIUM
CVE-2025-31978 — HCL BigFix Service Management (SM) does not adequately sanitize or safely render

HCL BigFix Service Management (SM) does not adequately sanitize or safely render spreadsheet files (CSV, XLS, XLSX) before processing or distributing them. An attacker could populate data fields whic…

bigfix_service_management | Remote | Information Disclosure
May 06, 2026 May 07, 2026
May 06, 2026
May 07, 2026
7.5 HIGH
CVE-2025-31976 — HCL BigFix Service Management (SM) is vulnerable to insufficiently protected credentials

HCL BigFix Service Management (SM) is vulnerable to insufficiently protected credentials for a short duration while communicating with a backend, internal application which could allow an attacker to…

bigfix_service_management | Remote | Information Disclosure
May 06, 2026 May 07, 2026
May 06, 2026
May 07, 2026
5.3 MEDIUM
CVE-2025-31975 — HCL BigFix Service Management (SM) is affected by an Information Disclosure – Server Bann…

HCL BigFix Service Management (SM) is affected by an Information Disclosure – Server Banner issue was identified. Exposed server banners may reveal software versions and system details, potentially a…

bigfix_service_management | Remote | Information Disclosure
May 06, 2026 May 07, 2026
May 06, 2026
May 07, 2026
3.5 LOW
CVE-2025-31959 — HCL BigFix Service Management (SM) application fails to strip EXIF metadata from uploaded…

HCL BigFix Service Management (SM) application fails to strip EXIF metadata from uploaded images. This could lead to confidentiality and privacy risks if sensitive location information is unintentio…

bigfix_service_management | Remote | Information Disclosure
May 06, 2026 May 07, 2026
May 06, 2026
May 07, 2026
5.7 MEDIUM
CVE-2025-31957 — HCL BigFix Service Management (SM) is affected by a Cross‑Site Request Forgery (CSRF) vul…

HHCL BigFix Service Management (SM) is affected by a Cross‑Site Request Forgery (CSRF) vulnerability. This could lead to unauthorized changes or exposure of sensitive data.

bigfix_service_management | Remote | Cross-Site Request Forgery
May 06, 2026 May 07, 2026
May 06, 2026
May 07, 2026
5.4 MEDIUM
CVE-2026-36358 — Juzaweb CMS Cross-Site Scripting (XSS)

Cross Site Scripting vulnerability in Juzaweb CMS v.5.0.0 allows a remote attacker via execute arbitrary code via a crafted script to the Add Banner Ads function

Remote | Cross-Site Scripting
May 06, 2026 May 07, 2026
May 06, 2026
May 07, 2026
6.3 MEDIUM
CVE-2026-8026 — FlowiseAI Flowise API Response account.service.ts login information disclosure

A security flaw has been discovered in FlowiseAI Flowise up to 3.0.12. Affected is the function Login of the file packages/server/src/enterprise/services/account.service.ts of the component API Respo…

flowise | Remote | Information Disclosure
May 06, 2026 May 07, 2026
May 06, 2026
May 07, 2026
9.1 CRITICAL
CVE-2026-5081 — Apache::Session::Generate::ModUniqueId versions from 1.54 through 1.94 for Perl session i…

Apache::Session::Generate::ModUniqueId versions from 1.54 through 1.94 for Perl session ids are insecure. Apache::Session::Generate::ModUniqueId (added in version 1.54) uses the value of the UNIQUE_…

Remote | Cryptography
May 06, 2026 May 07, 2026
May 06, 2026
May 07, 2026
7.5 HIGH
CVE-2026-40562 — Gazelle versions through 0.49 for Perl allows HTTP Request Smuggling via Improper Header …

Gazelle versions through 0.49 for Perl allows HTTP Request Smuggling via Improper Header Precedence. Gazelle incorrectly prioritizes "Content-Length" over "Transfer-Encoding: chunked" when both head…

Remote | Misconfiguration
May 06, 2026 May 07, 2026
May 06, 2026
May 07, 2026
8.7 HIGH
CVE-2026-6210 — Type confusion and heap-buffer-overflow in Qt SVG marker handling causing application cra…

A type confusion vulnerability in Qt SVG allows an attacker to cause an application crash via a crafted SVG image. When processing SVG marker references, the renderer retrieves a node by its id at…

Remote | Memory Corruption
May 06, 2026 May 07, 2026
May 06, 2026
May 07, 2026
0.0 NA
CVE-2026-43283 — net: ethernet: ec_bhf: Fix dma_free_coherent() dma handle

In the Linux kernel, the following vulnerability has been resolved: net: ethernet: ec_bhf: Fix dma_free_coherent() dma handle dma_free_coherent() in error path takes priv->rx_buf.alloc_len as the d…

linux_kernel | Memory Corruption
May 06, 2026 May 06, 2026
May 06, 2026
May 06, 2026
0.0 NA
CVE-2026-43282 — RDMA/ionic: Fix potential NULL pointer dereference in ionic_query_port

In the Linux kernel, the following vulnerability has been resolved: RDMA/ionic: Fix potential NULL pointer dereference in ionic_query_port The function ionic_query_port() calls ib_device_get_netdev…

linux_kernel | Memory Corruption
May 06, 2026 May 06, 2026
May 06, 2026
May 06, 2026
0.0 NA
CVE-2026-43281 — mailbox: Prevent out-of-bounds access in fw_mbox_index_xlate()

In the Linux kernel, the following vulnerability has been resolved: mailbox: Prevent out-of-bounds access in fw_mbox_index_xlate() Although it is guided that `#mbox-cells` must be at least 1, there…

linux_kernel | Memory Corruption
May 06, 2026 May 06, 2026
May 06, 2026
May 06, 2026
0.0 NA
CVE-2026-43280 — drm/xe: Add bounds check on pat_index to prevent OOB kernel read in madvise

In the Linux kernel, the following vulnerability has been resolved: drm/xe: Add bounds check on pat_index to prevent OOB kernel read in madvise When user provides a bogus pat_index value through th…

linux_kernel | Memory Corruption
May 06, 2026 May 06, 2026
May 06, 2026
May 06, 2026
0.0 NA
CVE-2026-43279 — ALSA: usb-audio: Add sanity check for OOB writes at silencing

In the Linux kernel, the following vulnerability has been resolved: ALSA: usb-audio: Add sanity check for OOB writes at silencing At silencing the playback URB packets in the implicit fb mode befor…

linux_kernel | Memory Corruption
May 06, 2026 May 06, 2026
May 06, 2026
May 06, 2026
0.0 NA
CVE-2026-43278 — dm: clear cloned request bio pointer when last clone bio completes

In the Linux kernel, the following vulnerability has been resolved: dm: clear cloned request bio pointer when last clone bio completes Stale rq->bio values have been observed to cause double-initia…

linux_kernel | Memory Corruption
May 06, 2026 May 07, 2026
May 06, 2026
May 07, 2026
0.0 NA
CVE-2026-43277 — APEI/GHES: ensure that won't go past CPER allocated record

In the Linux kernel, the following vulnerability has been resolved: APEI/GHES: ensure that won't go past CPER allocated record The logic at ghes_new() prevents allocating too large records, by chec…

linux_kernel | Memory Corruption
May 06, 2026 May 06, 2026
May 06, 2026
May 06, 2026
0.0 NA
CVE-2026-43276 — net: mana: Fix double destroy_workqueue on service rescan PCI path

In the Linux kernel, the following vulnerability has been resolved: net: mana: Fix double destroy_workqueue on service rescan PCI path While testing corner cases in the driver, a use-after-free cra…

linux_kernel | Memory Corruption
May 06, 2026 May 06, 2026
May 06, 2026
May 06, 2026
0.0 NA
CVE-2026-43275 — scsi: ufs: core: Flush exception handling work when RPM level is zero

In the Linux kernel, the following vulnerability has been resolved: scsi: ufs: core: Flush exception handling work when RPM level is zero Ensure that the exception event handling work is explicitly…

linux_kernel | Race Condition
May 06, 2026 May 06, 2026
May 06, 2026
May 06, 2026
Showing 20 of 5892 Results