Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.8 HIGH
CVE-2026-43909 — OpenImageIO: Signed integer overflow in SwapRGBABytes loop index leads to out-of-bounds r…

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.18.0 and 3.1.13.0, a signed 32-bit integer overflow in t…

openimageio | Remote | Memory Corruption
May 14, 2026 May 15, 2026
May 14, 2026
May 15, 2026
8.8 HIGH
CVE-2026-43908 — OpenImageIO: Signed integer overflow in ConvertCbYCrYToRGB leads to heap out-of-bounds wr…

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.18.0 and 3.1.13.0, a signed 32-bit integer overflow in t…

openimageio | Remote | Memory Corruption
May 14, 2026 May 15, 2026
May 14, 2026
May 15, 2026
8.3 HIGH
CVE-2026-43907 — OpenImageIO: Integer overflow in QueryRGBBufferSizeInternal leads to heap out-of-bounds w…

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.18.0 and 3.1.13.0, a signed integer overflow in QueryRGB…

openimageio | Remote | Memory Corruption
May 14, 2026 May 15, 2026
May 14, 2026
May 15, 2026
8.5 HIGH
CVE-2026-43906 — OpenImageIO: HEIF Heap overflow

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.18.0 and 3.1.13.0, a heap-based buffer overflow in the H…

openimageio | Memory Corruption
May 14, 2026 May 15, 2026
May 14, 2026
May 15, 2026
7.8 HIGH
CVE-2026-43905 — OpenImageIO: JPEG2000 (OpenJPH) signed integer overflow in buffer allocation

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.18.0 and 3.1.13.0, jpeg2000input.cpp:395 computes buffer…

openimageio | Memory Corruption
May 14, 2026 May 15, 2026
May 14, 2026
May 15, 2026
8.4 HIGH
CVE-2026-43904 — OpenImageIO: Softimage PIC RLE decoder heap buffer overflow — longCount not clamped to im…

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.18.0 and 3.1.13.0, softimageinput.cpp:469 (mixed RLE) an…

openimageio | Memory Corruption
May 14, 2026 May 16, 2026
May 14, 2026
May 16, 2026
8.4 HIGH
CVE-2026-43903 — OpenImageIO: SGI RLE decoder heap buffer overflow OIIO_DASSERT bounds checks are no-ops i…

OpenImageIO is a toolset for reading, writing, and manipulating image files of any image file format relevant to VFX / animation. Prior to 3.0.18.0 and 3.1.13.0, sgiinput.cpp:265,274 use OIIO_DASSERT…

openimageio | Memory Corruption
May 14, 2026 May 15, 2026
May 14, 2026
May 15, 2026
7.4 HIGH
CVE-2026-3290 — Timing limitations of the HRNG in RS9116 when power save mode is enabled results in predi…

Timing limitations of the HRNG in RS9116 when power save mode is enabled results in predictable values

| Cryptography
May 14, 2026 May 15, 2026
May 14, 2026
May 15, 2026
9.8 CRITICAL
CVE-2026-26191 — Fleet vulnerable to OS command injection in software packages

Fleet is open source device management software. Prior to version 4.81.0, a vulnerability in Fleet's software installer pipeline could allow a crafted software package to execute arbitrary commands a…

fleet | Remote | Injection
May 14, 2026 May 18, 2026
May 14, 2026
May 18, 2026
8.7 HIGH
CVE-2026-26062 — Fleet server may terminate unexpectedly when handling certain gRPC requests

Fleet is open source device management software. Prior to version 4.81.0, Fleet contained a denial-of-service (DoS) issue in the gRPC Launcher `PublishLogs` endpoint. In affected versions, certain un…

fleet | Remote | Denial of Service
May 14, 2026 May 18, 2026
May 14, 2026
May 18, 2026
8.2 HIGH
CVE-2026-24899 — Fleet Windows MDM Azure AD JWT Authentication Bypass

Fleet is open source device management software. Prior to version 4.82.0, a vulnerability in Fleet's Windows MDM enrollment flow allows authentication tokens from any Azure AD tenant to be accepted. …

fleet | Remote | Authentication
May 14, 2026 May 26, 2026
May 14, 2026
May 26, 2026
6.9 MEDIUM
CVE-2026-24000 — Fleet has a rate limiting bypass via untrusted client IP headers

Fleet is open source device management software. Prior to version 4.80.1, Fleet trusted client-supplied IP address headers when determining the source IP for incoming requests. This allowed authentic…

fleet | Remote | Misconfiguration
May 14, 2026 May 15, 2026
May 14, 2026
May 15, 2026
8.8 HIGH
CVE-2026-8621 — Crabbox < v0.12.0 Authentication Bypass via Header Spoofing

Crabbox prior to v0.12.0 contains an authentication bypass vulnerability that allows non-admin shared-token callers to impersonate other owners or organizations by spoofing identity headers. Attacker…

Remote | Authentication
May 14, 2026 May 15, 2026
May 14, 2026
May 15, 2026
9.0 CRITICAL
CVE-2026-45375 — SiYuan: Bazaar marketplace renders unescaped package `name` and `version` metadata, allow…

SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, SiYuan's Bazaar (community marketplace) renders the name and version fields of a package's plugin.json (and the equivale…

siyuan | Remote | Cross-Site Scripting
May 14, 2026 May 16, 2026
May 14, 2026
May 16, 2026
7.2 HIGH
CVE-2026-45371 — SiYuan: SiYuan publish-mode Reader can mutate Conf and SQL index via 8 ungated APIs

SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, SiYuan publish-mode Reader can mutate Conf and SQL index via 8 ungated APIs. POST /api/graph/getGraph, POST /api/graph/g…

siyuan | Remote | Authentication
May 14, 2026 May 15, 2026
May 14, 2026
May 15, 2026
4.3 MEDIUM
CVE-2026-45148 — SiYuan: Broken access control in SiYuan publish-mode Readers can enumerate metadata

SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, broken access control in the searchAsset, searchTag, searchWidget, and searchTemplate publish-mode Readers can enumerate…

siyuan | Remote | Authorization
May 14, 2026 May 15, 2026
May 14, 2026
May 15, 2026
4.3 MEDIUM
CVE-2026-45147 — SiYuan: Broken access control in SiYuan `/api/tag/getTag` — Reader role can mutate `Conf.…

SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, POST /api/tag/getTag is registered with model.CheckAuth only, omitting both model.CheckAdminRole and model.CheckReadonly…

siyuan | Remote | Authentication
May 14, 2026 May 14, 2026
May 14, 2026
May 14, 2026
9.4 CRITICAL
CVE-2026-44670 — SiYuan: Stored XSS via Attribute View name to Electron renderer RCE in SiYuan

SiYuan is an open-source personal knowledge management system. Prior to 3.7.0, the kernel stores Attribute View (AV / database) names without any HTML escape, then a render template uses raw strings.…

siyuan | Remote | Cross-Site Scripting
May 14, 2026 May 15, 2026
May 14, 2026
May 15, 2026
8.1 HIGH
CVE-2026-44633 — Live Helper Chat: REST API chat update accepts arbitrary chat fields across department bo…

Live Helper Chat is an open-source application that enables live support websites. In 4.84v, the Live Helper Chat REST API chat update endpoint allows a REST user with lhchat/use to update a chat in …

live_helper_chat | Remote | Authorization
May 14, 2026 May 15, 2026
May 14, 2026
May 15, 2026
9.4 CRITICAL
CVE-2026-44592 — Gradient: Unauthenticated worker on /proto → arbitrary NAR write / cache poisoning

Gradient is a nix-based continuous integration system. In 1.1.0, when GRADIENT_DISCOVERABLE=true (the default, and the NixOS module default), anyone who can reach /proto can register as a worker with…

Remote | Authentication
May 14, 2026 May 15, 2026
May 14, 2026
May 15, 2026
Showing 20 of 7160 Results