Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.6 HIGH
CVE-2026-42079 — PPTAgent: Arbitrary Code Execution via Python eval() of LLM-Generated Code with Builtins …

PPTAgent is an agentic framework for reflective PowerPoint generation. Prior to commit 418491a, PPTAgent is vulnerable to arbitrary code execution via Python eval() of LLM-generated code with builtin…

| Injection
May 04, 2026 May 05, 2026
May 04, 2026
May 05, 2026
4.6 MEDIUM
CVE-2026-42078 — PPTAgent: Arbitrary File Write + Directory Creation via markdown_table_to_image

PPTAgent is an agentic framework for reflective PowerPoint generation. Prior to commit 418491a, PPTAgent is vulnerable to arbitrary file write and directory creation via markdown_table_to_image. This…

Remote | Path Traversal
May 04, 2026 May 05, 2026
May 04, 2026
May 05, 2026
5.2 MEDIUM
CVE-2026-42077 — Evolver: Prototype Pollution via `Object.assign()` in mailbox store operations

Evolver is a GEP-powered self-evolving engine for AI agents. Prior to version 1.69.3, a prototype pollution vulnerability in the mailbox store module allows attackers to modify the behavior of all Ja…

| Injection
May 04, 2026 May 07, 2026
May 04, 2026
May 07, 2026
9.8 CRITICAL
CVE-2026-42076 — Evolver: Command Injection via `execSync` in `_extractLLM()` function allows Remote Code …

Evolver is a GEP-powered self-evolving engine for AI agents. Prior to version 1.69.3, a command injection vulnerability in the _extractLLM() function allows attackers to execute arbitrary shell comma…

Remote | Injection
May 04, 2026 May 07, 2026
May 04, 2026
May 07, 2026
8.1 HIGH
CVE-2026-42075 — Evolver: Path Traversal via `--out` flag in `fetch` command allows Arbitrary File Write

Evolver is a GEP-powered self-evolving engine for AI agents. Prior to version 1.69.3, a path traversal vulnerability in the skill download (fetch) command allows attackers to write files to arbitrary…

Remote | Path Traversal
May 04, 2026 May 07, 2026
May 04, 2026
May 07, 2026
9.8 CRITICAL
CVE-2026-42027 — Apache OpenNLP: Arbitrary Class Instantiation via Model Manifest in ExtensionLoader

Arbitrary Class Instantiation via Model Manifest in Apache OpenNLP ExtensionLoader Versions Affected: before 2.5.9, before 3.0.0-M3 Description:  The ExtensionLoader.instantiateExtension(C…

opennlp | Remote | Misconfiguration
May 04, 2026 May 06, 2026
May 04, 2026
May 06, 2026
9.1 CRITICAL
CVE-2026-40682 — Apache OpenNLP: XXE via Dictionary Parsing in DictionaryEntryPersistor

XML External Entity (XXE) via Unsanitized Dictionary Parsing in Apache OpenNLP DictionaryEntryPersistor Versions Affected: before 2.5.9, before 3.0.0-M3 Description: The DictionaryEntryPersistor …

opennlp | Remote | XML External Entity
May 04, 2026 May 06, 2026
May 04, 2026
May 06, 2026
6.1 MEDIUM
CVE-2026-38669 — WordPress CMS Cross Site Scripting (XSS)

wCMS v.1.4 is vulnerable to Cross Site Scripting (XSS) when creating a new blog.

Remote | Cross-Site Scripting
May 04, 2026 May 05, 2026
May 04, 2026
May 05, 2026
7.5 HIGH
CVE-2026-37461 — Gobgp BGP UPDATE Message Out-of-Bounds Read Denial of Service Vulnerability

An out-of-bounds read in the ParseIP6Extended function (/bgp/bgp.go) of gobgp v4.3.0 allows attackers to cause a Denial of Service (DoS) via supplying a crafted BGP UPDATE message.

Remote | Denial of Service
May 04, 2026 May 07, 2026
May 04, 2026
May 07, 2026
8.8 HIGH
CVE-2026-29514 — NetBox 4.3.5 - 4.5.4 RCE via RenderTemplateMixin

NetBox versions 4.3.5 through 4.5.4 contain a remote code execution vulnerability in the RenderTemplateMixin.get_environment_params() method that allows authenticated users with exporttemplate or con…

Remote | Authentication
May 04, 2026 May 05, 2026
May 04, 2026
May 05, 2026
9.8 CRITICAL
CVE-2026-26956 — vm2: WASM Sandbox Escape (Node 25 only)

vm2 is an open source vm/sandbox for Node.js. In version 3.10.4, vm2 is vulnerable to full sandbox escape with arbitrary code execution. Attacker code inside VM.run() obtains host process object and …

vm2 | Remote | Misconfiguration
May 04, 2026 May 08, 2026
May 04, 2026
May 08, 2026
10.0 CRITICAL
CVE-2026-26332 — vm2: Sandbox Escape

vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.0, SuppressedError allows attackers to escape the sandbox and run arbitrary code. This issue has been patched in version 3.11.0.

vm2 | Remote | Supply Chain
May 04, 2026 May 06, 2026
May 04, 2026
May 06, 2026
9.8 CRITICAL
CVE-2026-25293 — Incorrect authorization in PLC FW

Buffer overflow due to incorrect authorization in PLC FW

qca7005_firmware qca7005 | Remote | Authorization
May 04, 2026 May 06, 2026
May 04, 2026
May 06, 2026
7.8 HIGH
CVE-2026-25266 — Exposed dangerous function in windows host

Memory corruption while processing IOCTL command when device is in power-save state.

May 04, 2026 May 06, 2026
May 04, 2026
May 06, 2026
9.8 CRITICAL
CVE-2026-24781 — vm2: Sandbox Breakout Through Inspect

vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.0, VM2 suffers from a sandbox breakout vulnerability through the inspect function. This allows attackers to write code which can es…

vm2 | Remote | Injection
May 04, 2026 May 08, 2026
May 04, 2026
May 08, 2026
9.8 CRITICAL
CVE-2026-24120 — vm2: Sandbox Breakout Through Promise Species

vm2 is an open source vm/sandbox for Node.js. Prior to version 3.10.5, the fix for CVE-2023-37466 is insufficient and can be circumvented allowing attackers to write code which can escape from the VM…

vm2 | Remote | Misconfiguration
May 04, 2026 May 08, 2026
May 04, 2026
May 08, 2026
9.8 CRITICAL
CVE-2026-24118 — VM2 Sandbox Breakout Through __lookupGetter__

vm2 is an open source vm/sandbox for Node.js. Prior to version 3.11.0, VM2 suffers from a sandbox breakout vulnerability. This allows attackers to write code which can escape from the VM2 sandbox and…

vm2 | Remote | Misconfiguration
May 04, 2026 May 08, 2026
May 04, 2026
May 08, 2026
7.8 HIGH
CVE-2026-24082 — Use After Free in Automotive GPU

Memory Corruption when copying data from a freed source while executing performance counter deselect operation.

May 04, 2026 May 06, 2026
May 04, 2026
May 06, 2026
7.8 HIGH
CVE-2025-47408 — Untrusted Pointer Dereference in Power Optimization Firmware

Memory corruption when another driver calls an IOCTL with invalid input/output buffer.

May 04, 2026 May 06, 2026
May 04, 2026
May 06, 2026
7.8 HIGH
CVE-2025-47407 — Time-of-check Time-of-use (TOCTOU) Race Condition in DSP Service

Memory corruption while creating a process on the digital signal processor due to allocation failure at the kernel level.

May 04, 2026 May 06, 2026
May 04, 2026
May 06, 2026
Showing 20 of 5684 Results