Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.8 CRITICAL

Vulnerability in the Oracle Hospitality OPERA 5 Property Services product of Oracle Hospitality Applications (component: Opera). Supported versions that are affected are 5.6.19.24, 5.6.22, 5.6.25.19…

May 28, 2026 May 29, 2026
May 28, 2026
May 29, 2026
8.6 HIGH
CVE-2026-9039 — Initialization of a resource with an insecure default in XCharge C6

A configuration weakness in the device’s remote management service allows an authenticated session to be established over a communication channel intended solely for vehicle-charger signaling. The se…

| Misconfiguration
May 28, 2026 May 29, 2026
May 28, 2026
May 29, 2026
8.6 HIGH
CVE-2026-9038 — Stack-based buffer overflow in XCharge C6

A stack-based buffer overflow vulnerability in the charging controller’s signal-processing logic allows an attacker with physical access to the charging interface to supply message fields that exceed…

| Memory Corruption
May 28, 2026 May 29, 2026
May 28, 2026
May 29, 2026
9.3 CRITICAL
CVE-2026-9037 — Download of code without integrity check in XCharge C6

A firmware update mechanism in the affected charging controller fails to validate the authenticity of firmware packages delivered through the device's management interface. Because cryptographic sign…

Remote | Authentication
May 28, 2026 May 29, 2026
May 28, 2026
May 29, 2026
6.9 MEDIUM
CVE-2026-49130 — Music Player Daemon < 0.24.11 CRLF Injection via XspfPlaylistPlugin.cxx

Music Player Daemon (MPD) before version 0.24.11 contains a CRLF injection vulnerability in the xspf_char_data function within the XSPF playlist plugin that allows attackers to embed literal CR/LF by…

Remote | Injection
May 28, 2026 May 29, 2026
May 28, 2026
May 29, 2026
6.9 MEDIUM
CVE-2026-49129 — Music Player Daemon < 0.24.11 SSRF via CurlInputPlugin

Music Player Daemon (MPD) before version 0.24.11 contains a server-side request forgery vulnerability in CurlInputPlugin where CURLOPT_FOLLOWLOCATION is set without CURLOPT_REDIR_PROTOCOLS_STR, allow…

Remote | Server-Side Request Forgery
May 28, 2026 May 29, 2026
May 28, 2026
May 29, 2026
8.7 HIGH
CVE-2026-49128 — Music Player Daemon < 0.24.11 Path Traversal via LocalStorage URI Handling

Music Player Daemon (MPD) before version 0.24.11 contains a path traversal vulnerability in LocalStorage::MapFSOrThrow and LocalStorage::MapUTF8 within the local storage plugin, where the on-disk pat…

Remote | Path Traversal
May 28, 2026 May 29, 2026
May 28, 2026
May 29, 2026
8.8 HIGH
CVE-2026-49127 — Music Player Daemon < 0.24.11 Stack Buffer Overflow via pcm_unpack_24be

Music Player Daemon (MPD) before version 0.24.11 contains a stack buffer overflow vulnerability in the pcm_unpack_24be function in src/pcm/Pack.cxx that allows unauthenticated attackers to corrupt st…

Remote | Memory Corruption
May 28, 2026 May 29, 2026
May 28, 2026
May 29, 2026
5.4 MEDIUM
CVE-2026-42401 — Improper Neutralization of Input During Web Page Generation in Kibana Leading to Stored H…

Improper Neutralization of Input During Web Page Generation (CWE-79) in Kibana can lead to stored HTML injection. A user with write access to an Elasticsearch index could persist crafted markup which…

kibana | Remote | Cross-Site Scripting
May 28, 2026 May 29, 2026
May 28, 2026
May 29, 2026
8.5 HIGH
CVE-2026-33590 — Insecure default permissions in Portainer CE

Insecure default settings of Portainer CE grant regular (non-admin) users privileges that allow host filesystem access and host-level code execution. An authenticated non-administrative user with end…

Remote | Authorization
May 28, 2026 May 29, 2026
May 28, 2026
May 29, 2026
6.5 MEDIUM
CVE-2026-33464 — Uncontrolled Resource Consumption in Kibana Leading to Denial of Service

Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to a denial of service via Excessive Allocation (CAPEC-130). An authenticated user holding a low-privileged role can submit a specially …

kibana | Remote | Denial of Service
May 28, 2026 May 29, 2026
May 28, 2026
May 29, 2026
5.3 MEDIUM
CVE-2026-33463 — Operation on a Resource after Expiration or Termination in Kibana Leading to Unauthorized…

Operation on a Resource after Expiration or Termination (CWE-672) in Kibana can lead to unauthorized information disclosure. A logic error in how expiration timestamps were validated allowed a time-b…

kibana | Remote | Authorization
May 28, 2026 May 29, 2026
May 28, 2026
May 29, 2026
7.3 HIGH
CVE-2026-33462 — Path Traversal in Kibana Leading to Unauthorized Deletion of User Accounts

A path traversal vulnerability was identified in Kibana's dashboard management functionality. An authenticated user with limited permissions could create a dashboard with a specially crafted identifi…

kibana | Remote | Path Traversal
May 28, 2026 May 29, 2026
May 28, 2026
May 29, 2026
8.7 HIGH
CVE-2026-32847 — DeepCode 1.2.0 Path Traversal via SPA Catch-All Route in main.py

DeepCode through commit c991dc2 contains a path traversal vulnerability in the SPA catch-all route in new_ui/backend/main.py that allows unauthenticated attackers to read arbitrary files by supplying…

deepcode | Remote | Path Traversal
May 28, 2026 Jun 03, 2026
May 28, 2026
Jun 03, 2026
8.8 HIGH
CVE-2026-4944 — Hardcoded trust_remote_code=True in vllm-project/vllm Bypasses User Security Control

vllm-project/vllm version 0.14.1 contains a vulnerability where the `trust_remote_code=True` parameter is hardcoded in two model implementation files (`vllm/model_executor/models/nemotron_vl.py` and …

vllm | Remote | Misconfiguration
May 28, 2026 May 29, 2026
May 28, 2026
May 29, 2026
3.3 LOW
CVE-2026-47337 — NULL pointer dereference in Ubuntu Linux AppArmor IPv4/IPv6 socket mediation

Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a possible NULL pointer dereference in the handling of AF_INET/AF_INET6 socket mediation. The bug can be triggered by an unprivileged local u…

ubuntu_linux | Memory Corruption
May 28, 2026 May 29, 2026
May 28, 2026
May 29, 2026
3.3 LOW
CVE-2026-47336 — Use of uninitialized value in Ubuntu Linux AppArmor IPv4/IPv6 socket mediation rules

Ubuntu Linux 6.8 contains SAUCE patches with a possible use of an uninitialized variable in AppArmor AF_INET/AF_INET6 socket mediation code. The bug can be triggered by an unprivileged local user and…

ubuntu_linux | Misconfiguration
May 28, 2026 May 29, 2026
May 28, 2026
May 29, 2026
5.5 MEDIUM
CVE-2026-47335 — NULL pointer dereference in Ubuntu Linux AppArmor notification handling

Ubuntu Linux 6.8 contains SAUCE patches with a possible NULL pointer dereference in the handling of AppArmor notifications. The bug can be triggered by an unprivileged local user. This can lead to a …

ubuntu_linux | Denial of Service
May 28, 2026 May 29, 2026
May 28, 2026
May 29, 2026
5.5 MEDIUM
CVE-2026-47334 — Deadlock or kernel panic in Ubuntu Linux AppArmor notification handling

Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which incorrectly sleep while holding a spinlock in notification handling code. The bug can be triggered by an unprivileged local user an…

ubuntu_linux | Race Condition
May 28, 2026 May 29, 2026
May 28, 2026
May 29, 2026
7.8 HIGH
CVE-2026-47333 — Out-of-bounds read in Ubuntu Linux AppArmor notification handling

Ubuntu Linux 6.8, 6.17 and 7.0 contain AppArmor SAUCE patches which can potentially incorrectly compute the size of an internal buffer, leading to a heap memory out-of-bounds read in notification han…

ubuntu_linux | Memory Corruption
May 28, 2026 May 29, 2026
May 28, 2026
May 29, 2026
Showing 20 of 7227 Results