Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.3 HIGH
CVE-2024-46507 — Yeti-Platform SSTI Code Execution

A SSTI (server side template injection) vulnerability in the custom template export function in yeti-platform yeti before 2.1.12 allows attackers to execute code on the application server.

yeti | Remote | Injection
May 08, 2026 May 08, 2026
May 08, 2026
May 08, 2026
7.3 HIGH
CVE-2024-45257 — BYOB Command Injection Vulnerability

A Command Injection issue in the payload build page in BYOB (Build Your Own Botnet) 2.0 allows attackers to execute arbitrary commands on the server via a crafted build parameter. This occurs in free…

Remote | Injection
May 08, 2026 May 08, 2026
May 08, 2026
May 08, 2026
5.4 MEDIUM
CVE-2024-33724 — SOPlanning Cross Site Scripting (XSS)

SOPlanning 1.52.00 is vulnerable to Cross Site Scripting (XSS) via the groupe_id parameter to process/groupe_save.php.

Remote | Cross-Site Scripting
May 08, 2026 May 08, 2026
May 08, 2026
May 08, 2026
6.3 MEDIUM
CVE-2024-33722 — SOPlanning SQL Injection

SOPlanning 1.52.00 is vulnerable to SQL Injection by an authenticated user via projets.php with statut[].

Remote | Injection
May 08, 2026 May 08, 2026
May 08, 2026
May 08, 2026
7.3 HIGH
CVE-2024-33288 — "PHP Prison Management System SQL Injection"

Prison Management System Using PHP v1.0 was discovered to contain a SQL injection vulnerability via the username on the Admin login page.

Remote | Injection
May 08, 2026 May 08, 2026
May 08, 2026
May 08, 2026
6.3 MEDIUM
CVE-2024-30167 — Atlona AT-OME-MS42 Remote Command Execution Vulnerability

/cgi-bin/time.cgi in Atlona AT-OME-MS42 Matrix Switcher 1.1.2 allow remote authenticated users to execute arbitrary commands as root via a POST request that carries a serverName parameter.

Remote | Injection
May 08, 2026 May 08, 2026
May 08, 2026
May 08, 2026
7.5 HIGH
CVE-2024-27686 — Mikrotik RouterOS SMB Denial of Service

Mikrotik RouterOS (x86) 6.40.5 through 6.49.10 (fixed in 7) allows a remote attacker to cause a denial of service (device crash) via crafted packet data to the SMB service on TCP port 445.

Remote | Denial of Service
May 08, 2026 May 08, 2026
May 08, 2026
May 08, 2026
5.3 MEDIUM
CVE-2023-47268 — PrusaSlicer Code Injection Vulnerability

In libslic3r/GCode/PostProcessor.cpp in Prusa PrusaSlicer through 2.6.1, a crafted 3mf project file can execute arbitrary code on a host where the project is sliced and G-code exported.

| Memory Corruption
May 08, 2026 May 08, 2026
May 08, 2026
May 08, 2026
7.8 HIGH
CVE-2026-8148 — NAVER MYBOX Explorer Windows Privilege Escalation Vulnerability

NAVER MYBOX Explorer for Windows before 3.0.11.160 allows a local attacker to escalate privileges to NT AUTHORITY\SYSTEM via registry manipulation due to improper privilege checks.

mybox | Authorization
May 08, 2026 May 08, 2026
May 08, 2026
May 08, 2026
9.0 HIGH
CVE-2026-8138 — Tenda CX12L SetPptpServerCfg” formSetPPTPServer stack-based overflow

A vulnerability was found in Tenda CX12L 16.03.53.12. This issue affects the function formSetPPTPServer of the file /goform/SetPptpServerCfg”. The manipulation results in stack-based buffer overflow.…

cx12l_firmware | Remote | Memory Corruption
May 08, 2026 May 08, 2026
May 08, 2026
May 08, 2026
9.0 HIGH
CVE-2026-8137 — Totolink X5000R formDdns sub_458E40 buffer overflow

A vulnerability has been found in Totolink X5000R 9.1.0u.6369_B20230113. This vulnerability affects the function sub_458E40 of the file /boafrm/formDdns. The manipulation of the argument submit-url l…

x5000r_firmware | Remote | Memory Corruption
May 08, 2026 May 08, 2026
May 08, 2026
May 08, 2026
5.8 MEDIUM
CVE-2026-42279 — solidtime: Time entry update endpoint allows cross-organization modification of a known t…

solidtime is an open-source time-tracking app. In version 0.12.0, the PUT /api/v1/organizations/{organization}/time-entries/{timeEntry} API accepts a route-bound timeEntry from another organization w…

solidtime | Remote | Authorization
May 08, 2026 May 08, 2026
May 08, 2026
May 08, 2026
8.8 HIGH
CVE-2026-42278 — UltraDAG: Smart Account Spending Policy Bypass via Pockets

UltraDAG is a minimal DAG-BFT blockchain in Rust. Prior to commit fb6ef59, the UltraDAG StateEngine implementation of SmartTransferTx contains a critical logic flaw in its policy enforcement pipeline…

ultradag | Remote | Authorization
May 08, 2026 May 09, 2026
May 08, 2026
May 09, 2026
6.5 MEDIUM
CVE-2026-42277 — Onyx: IDOR in /chat/file/{file_id} allows any authenticated user to download other users …

Onyx is an open-source AI platform. Prior to versions 3.0.9, 3.1.6, and 3.2.6, the GET /chat/file/{file_id} endpoint allows any authenticated user to download any other user's uploaded files by provi…

Remote | Authorization
May 08, 2026 May 08, 2026
May 08, 2026
May 08, 2026
4.3 MEDIUM
CVE-2026-42276 — Onyx: IDOR in /chat/stop-chat-session allows any authenticated user to interrupt other us…

Onyx is an open-source AI platform. Prior to versions 3.0.9, 3.1.6, and 3.2.6, the POST /chat/stop-chat-session/{chat_session_id} endpoint lets any authenticated user stop any other user's active cha…

Remote | Authorization
May 08, 2026 May 08, 2026
May 08, 2026
May 08, 2026
0.0 NA
CVE-2023-42346 — Alkacon OpenCms XXE External Host Reference Vulnerability

Alkacon OpenCms before 16 allows XXE when the <!DOCTYPE> refers to an external host.

| XML External Entity
May 08, 2026 May 08, 2026
May 08, 2026
May 08, 2026
6.1 MEDIUM
CVE-2023-42345 — Alkacon OpenCms Cross Site Scripting (XSS)

A Cross Site Scripting vulnerability in Alkacon OpenCms before 16 exists via updateModelGroups.jsp.

Remote | Cross-Site Scripting
May 08, 2026 May 08, 2026
May 08, 2026
May 08, 2026
7.3 HIGH
CVE-2023-42344 — Alkacon OpenCms XML External Entity (XXE) Information Disclosure

Alkacon OpenCms before 10.5.1 allows remote unauthenticated attackers to obtain sensitive information via a cmis-online/query XXE attack on a Chemistry servlet.

Remote | XML External Entity
May 08, 2026 May 08, 2026
May 08, 2026
May 08, 2026
6.1 MEDIUM
CVE-2023-42343 — Alkacon OpenCms Cross Site Scripting Vulnerability

A Cross Site Scripting vulnerability in Alkacon OpenCms before 10.5.1 exists via cmis-online/type.

Remote | Cross-Site Scripting
May 08, 2026 May 08, 2026
May 08, 2026
May 08, 2026
6.5 MEDIUM
CVE-2022-45899 — Nokia Broadcast Message Center (BMC) Root OS Command Injection Vulnerability

Nokia Broadcast Message Center (BMC) before 13.1 allows an unauthenticated remote attacker to do OS command injection as root via shell metacharacters in the Log Scanner Search Pattern field.

Remote | Injection
May 08, 2026 May 08, 2026
May 08, 2026
May 08, 2026
Showing 20 of 5725 Results