Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.2 HIGH
CVE-2026-23998 — Fleet has a Windows MDM management endpoint authentication bypass

Fleet is open source device management software. Prior to version 4.81.0, a vulnerability in Fleet’s Windows MDM management endpoint could allow requests to be processed without proper client certifi…

fleet | Remote | Authentication
May 14, 2026 May 15, 2026
May 14, 2026
May 15, 2026
5.4 MEDIUM
CVE-2026-22707 — Strapi Upload Plugin MIME Validation Bypass via Content API

Strapi is an open source headless content management system. In Strapi versions prior to 5.33.3, the Upload plugin's Content API endpoints did not enforce the administrator-configured MIME type restr…

strapi | Remote | Misconfiguration
May 14, 2026 May 16, 2026
May 14, 2026
May 16, 2026
6.5 MEDIUM
CVE-2026-22706 — Strapi: Password Reset Does Not Revoke Existing Refresh Sessions

Strapi is an open source headless content management system. In Strapi versions prior to 5.33.3, changing or resetting a user's password did not invalidate the user's existing refresh-token sessions …

strapi | Remote | Authentication
May 14, 2026 May 16, 2026
May 14, 2026
May 16, 2026
9.3 CRITICAL
CVE-2026-22599 — Strapi Vulnerable to SQL Injection in Content Type Builder

Strapi is an open source headless content management system. In versions on the 4.x branch prior to 4.26.1 and on the 5.x branch prior to 5.33.2, a database-query injection vulnerability existed in t…

strapi | Remote | Injection
May 14, 2026 May 16, 2026
May 14, 2026
May 16, 2026
6.9 MEDIUM
CVE-2025-64526 — Strapi has a rate limit bypass on users-permissions plugin via attacker-controlled email …

Strapi is an open source headless content management system. In Strapi versions prior to 5.45.0, the rate-limit middleware in the users-permissions plugin derived its rate-limit key in part from `ctx…

strapi | Remote | Authentication
May 14, 2026 May 16, 2026
May 14, 2026
May 16, 2026
7.5 HIGH
CVE-2026-6332 — Clear Text Storage of Sensitive Information on EcoStruxure™ Machine Expert HVAC

CWE-312: Cleartext Storage of Sensitive Information vulnerability exists that could cause the disclosure of a sensitive information which could result in revealing protected source code and loss of …

ecostruxure_machine_expert_hvac | Remote | Information Disclosure
May 14, 2026 May 27, 2026
May 14, 2026
May 27, 2026
9.1 CRITICAL
CVE-2026-46470 — GStreamer gst-plugins-good Integer Division by Zero Denial of Service

An issue was discovered in GStreamer gst-plugins-good before 1.28.2. When parsing MP4 audio tracks, the isomp4 plugin's qtdemux_audio_caps function does not sufficiently validate atom data before per…

good_plug-ins gst-plugins-good | Remote | Denial of Service
May 14, 2026 May 19, 2026
May 14, 2026
May 19, 2026
5.5 MEDIUM
CVE-2026-46469 — GStreamer gst-plugins-good Integer Division by Zero Denial of Service

An issue was discovered in GStreamer gst-plugins-good before 1.28.2. When parsing MP4 audio tracks, the isomp4 plugin's qtdemux_parse_trak function does not sufficiently validate atom data before per…

good_plug-ins gst-plugins-good | Denial of Service
May 14, 2026 May 19, 2026
May 14, 2026
May 19, 2026
4.9 MEDIUM
CVE-2026-44544 — gittuf: Policy can be rolled back to prior valid version

gittuf is a platform-agnostic Git security system. Prior to 0.14.0, an attacker with push access to gittuf's Reference State Log (RSL) can roll back the current policy to any previous policy trusted …

Remote | Authorization
May 14, 2026 May 14, 2026
May 14, 2026
May 14, 2026
9.1 CRITICAL
CVE-2026-44542 — FileBrowser Quantum: Unauthenticated Path Traversal in Public Share Delete Allows Arbitra…

FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to 1.3.1-stable and 1.3.9-beta, attacker-controlled path input is joined with a trusted base path prior to sanitization, allo…

filebrowser_quantum | Remote | Path Traversal
May 14, 2026 May 15, 2026
May 14, 2026
May 15, 2026
5.7 MEDIUM
CVE-2026-44520 — Docling-Graph: SSRF via Missing Internal IP Validation in URLInputHandler

Docling-Graph turns documents into validated Pydantic objects, then builds a directed knowledge graph with explicit semantic relationships. Prior to 1.5.1, the URLInputHandler class in docling_graph/…

Remote | Server-Side Request Forgery
May 14, 2026 May 14, 2026
May 14, 2026
May 14, 2026
4.3 MEDIUM
CVE-2026-44283 — etcd: Read access via PrevKv in etcd transactions may bypass RBAC authorization checks

etcd is a distributed key-value store for the data of a distributed system. Prior to 3.4.44, 3.5.30, and 3.6.11, a vulnerability in etcd allows read access via PrevKv, or lease attachment in Put requ…

etcd | Remote | Authorization
May 14, 2026 May 15, 2026
May 14, 2026
May 15, 2026
8.1 HIGH
CVE-2026-42897 — Microsoft Exchange Server Cross-Site Scripting Vulnerability - [Actively Exploited]

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

May 14, 2026 May 15, 2026
May 14, 2026
May 15, 2026
6.9 MEDIUM
CVE-2026-42598 — Pode: Directory Traversal is possible on Static Routes

Pode is a Cross-Platform PowerShell web framework for creating REST APIs, Web Sites, and TCP/SMTP servers. From 2.4.0, to before 2.13.0, when requesting content from a Static Route, it was possible t…

Remote | Path Traversal
May 14, 2026 May 14, 2026
May 14, 2026
May 14, 2026
6.5 MEDIUM
CVE-2026-42572 — Hatchet: Cross-tenant information disclosure in `listTasksByDAGIds`

Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. Prior to 0.83.39, a missing authorization directive on the GET /api/v1/stable/dags/tasks endpoint …

hatchet | Remote | Authorization
May 14, 2026 May 27, 2026
May 14, 2026
May 27, 2026
7.5 HIGH
CVE-2026-42334 — Mongoose: Improper Sanitization of $nor in sanitizeFilter May Allow NoSQL Injection

Mongoose is a MongoDB object modeling tool designed to work in an asynchronous environment. Prior to 6.13.9, 7.8.9, 8.22.1, and 9.1.6, a vulnerability allows bypassing Mongoose’s sanitizeFilter query…

mongoose | Remote | Injection
May 14, 2026 May 15, 2026
May 14, 2026
May 15, 2026
6.5 MEDIUM
CVE-2026-41888 — Distribution: Tag deletion bypasses `storage.delete.enabled` configuration

Distribution is a toolkit to pack, ship, store, and deliver container content. Prior to 3.1.1, tag deletion via the DELETE /v2/<name>/manifests/<tag> endpoint bypasses the storage.delete.enabled: fal…

distribution | Remote | Misconfiguration
May 14, 2026 May 15, 2026
May 14, 2026
May 15, 2026
9.6 CRITICAL
CVE-2026-41615 — Microsoft Authenticator Information Disclosure Vulnerability

Exposure of sensitive information to an unauthorized actor in Microsoft Authenticator allows an unauthorized attacker to disclose information over a network.

May 14, 2026 May 15, 2026
May 14, 2026
May 15, 2026
8.8 HIGH
CVE-2025-15024 — RCE in Yordam Informatics' Library Automation System

Improper Control of Generation of Code ('Code Injection') vulnerability in Yordam Information Technology Consulting, Training and Electronic Systems Industry and Trade Inc. Library Automation System …

Remote | Injection
May 14, 2026 May 14, 2026
May 14, 2026
May 14, 2026
8.8 HIGH
CVE-2025-15023 — Improper Access Control in Yordam Informatics' Library Automation System

Incorrect Authorization vulnerability in Yordam Information Technology Consulting, Training and Electronic Systems Industry and Trade Inc. Library Automation System allows Exploiting Incorrectly Conf…

Remote | Authorization
May 14, 2026 May 14, 2026
May 14, 2026
May 14, 2026
Showing 20 of 7230 Results