Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.3 CRITICAL
CVE-2026-48700 — PCManFM-Qt File Path URI Execution

An issue was discovered in all versions of PCManFM-Qt starting from 1.1.0. When a regular file's path is passed as a URI in an org.freedesktop.FileManager1.ShowFolders D-Bus method call, PCManFM-Qt d…

| Authorization
May 22, 2026 May 24, 2026
May 22, 2026
May 24, 2026
8.1 HIGH
CVE-2026-40172 — authentik: Privilege Escalation via User PATCH: Superuser Group Assignment Bypasses enabl…

authentik is an open-source identity provider. In versions prior to 2025.12.5 and 2026.2.0-rc1 through 2026.2.2, the PATCH /api/v3/core/users/{pk}/ API allows a caller with change_user on a target us…

authentik | Remote | Authorization
May 22, 2026 May 22, 2026
May 22, 2026
May 22, 2026
7.1 HIGH
CVE-2026-40166 — authentik: Non-admin user can retrieve confidential OAuth client_secret via /api/v3/oauth…

authentik is an open-source identity provider. In versions prior to 2025.12.5 and 2026.2.0-rc1 through 2026.2.2, authenticated non-admin users with at least one OAuth2 access token can retrieve the c…

authentik | Remote | Information Disclosure
May 22, 2026 May 22, 2026
May 22, 2026
May 22, 2026
8.5 HIGH
CVE-2026-39970 — TypeBot: Stored Cross-Site Scripting (XSS) via SVG File Upload On Profile Picture Form

TypeBot is a chatbot builder tool. Versions 3.15.2 and prior contain a critical stored XSS vulnerability in the app.typebot.io profile picture upload form. The application fails to sanitize or restri…

typebot | Remote | Cross-Site Scripting
May 22, 2026 May 22, 2026
May 22, 2026
May 22, 2026
6.5 MEDIUM
CVE-2026-39969 — TypeBot: WhatsApp Webhook Endpoint Missing Signature Verification

TypeBot is a chatbot builder tool. In versions 3.16.0 and prior, the WhatsApp Cloud API webhook endpoint (POST /v1/workspaces/{workspaceId}/whatsapp/{credentialsId}/webhook) does not verify the x-hub…

typebot | Remote | Authentication
May 22, 2026 May 23, 2026
May 22, 2026
May 23, 2026
7.1 HIGH
CVE-2026-39968 — TypeBot: Cross-Workspace Credential Theft via Bot-Engine Preview Endpoint

TypeBot is a chatbot builder tool. In versions 3.15.2 and prior, the fix for GHSA-4xc5-wfwc-jw47 ("Credential Theft via Client-Side Script Execution and API Authorization Bypass") is incomplete. Whil…

typebot | Remote | Authorization
May 22, 2026 May 26, 2026
May 22, 2026
May 26, 2026
3.1 LOW
CVE-2026-39967 — TypeBot: Cross-Typebot Result Data Access via Missing typebotId Filter

TypeBot is a chatbot builder tool. In versions 3.15.2 and prior, the bot engine's the findResult query does not filter results by typebotId, allowing an authenticated user to load result data (user a…

typebot | Remote | Authentication
May 22, 2026 May 26, 2026
May 22, 2026
May 26, 2026
6.5 MEDIUM
CVE-2026-39966 — TypeBot: Async filter() bypasses authorization, allowing IDOR in getLinkedTypebots and le…

TypeBot is a chatbot builder tool. In versions 3.15.2, the getLinkedTypebots API endpoint returns full bot definitions to any authenticated user who references a target bot ID in a Typebot Link block…

typebot | Remote | Authorization
May 22, 2026 May 22, 2026
May 22, 2026
May 22, 2026
8.1 HIGH
CVE-2026-46727 — Apache Ruby Use-After-Free Remote Crash and Corruption Vulnerability

An issue was discovered in Ruby 4 before 4.0.5. A race condition leading to a use-after-free in the pthread-based getaddrinfo timeout handler (rb_getaddrinfo in ext/socket/raddrinfo.c) allows a remot…

ruby | Remote | Race Condition
May 22, 2026 May 26, 2026
May 22, 2026
May 26, 2026
6.2 MEDIUM
CVE-2026-42627 — Arm ArmNN Heap-Based Buffer Over-Read

In Arm ArmNN through 2026-03-27, an integer overflow in TensorShape::GetNumElements() in armnn/Tensor.cpp allows a crafted TFLite model file to bypass buffer size validation and trigger a heap-based …

| Memory Corruption
May 22, 2026 May 26, 2026
May 22, 2026
May 26, 2026
7.7 HIGH
CVE-2026-39965 — TypeBot: SSRF via Open Redirect Bypass in HTTP Request and Code Blocks

TypeBot is a chatbot builder tool. Versions 3.15.2 and prior contain an SSRF via Open Redirect Bypass as the HTTP Request block and Code block validate the initial request URL via validateHttpReqUrl(…

typebot | Remote | Server-Side Request Forgery
May 22, 2026 May 22, 2026
May 22, 2026
May 22, 2026
5.4 MEDIUM
CVE-2026-39964 — TypeBot: Stored XSS via javascript: URI in text bubble links — bot author executes JS on …

TypeBot is a chatbot builder tool. In versions prior to 3.16.0, the Typebot viewer (packages/embeds/js) renders anchor tags from rich text bubble content without filtering the javascript: URI scheme.…

typebot | Remote | Cross-Site Scripting
May 22, 2026 May 23, 2026
May 22, 2026
May 23, 2026
8.4 HIGH
CVE-2026-9255 — Tool Execution Without Authorization via Piped Stdin in Kiro CLI

Missing input source validation in the tool authorization prompt in Kiro CLI before 1.28.0 allows a local attacker to execute arbitrary tools, including shell commands, without user approval by craft…

kiro_cli kiro_cli | Authorization
May 22, 2026 Jun 04, 2026
May 22, 2026
Jun 04, 2026
5.9 MEDIUM
CVE-2026-42626 — HP ENVY 5000 series Printers TCP Connection Overflow

HP ENVY 5000 series printers VERBASPP1N003.2237A.00 do not properly manage concurrent TCP connections to port 9100 (JetDirect/RAW printing). An unauthenticated remote attacker on the same network can…

| Denial of Service
May 22, 2026 May 22, 2026
May 22, 2026
May 22, 2026
7.3 HIGH
CVE-2026-37470 — ClipBucket Remote Code Execution Vulnerability

An issue in ClipBucket v5 v.5.5.2 allows an attacker to execute arbitrary code via the Authentication interface, login page endpoint and HTTP response security headers components

Remote | Authentication
May 22, 2026 May 22, 2026
May 22, 2026
May 22, 2026
7.3 HIGH
CVE-2026-36228 — Easy Chat Server Buffer Overflow Vulnerability

Buffer Overflow vulnerability in Easy Chat Server 3.1 allows a remote attacker to obtain sensitive information and execute arbitrary code via the chat message functionality

Remote | Memory Corruption
May 22, 2026 May 22, 2026
May 22, 2026
May 22, 2026
6.5 MEDIUM
CVE-2026-36227 — Easy Chat Server Directory Traversal Vulnerability

Directory Traversal vulnerability in Easy Chat Server 3.1 allows a remote attacker to obtain sensitive information and execute arbitrary code via the UserName parameter

Remote | Path Traversal
May 22, 2026 May 22, 2026
May 22, 2026
May 22, 2026
6.1 MEDIUM
CVE-2026-36226 — Advantech WebAccess/SCADA Cross Site Scripting

Cross Site Scripting vulnerability in Advantech WebAccess/SCADA 8.0-2015.08.16 allows a remote attacker to obtain sensitive information via the decryption field in the Create New Project User compone…

Remote | Cross-Site Scripting
May 22, 2026 May 22, 2026
May 22, 2026
May 22, 2026
7.6 HIGH
CVE-2026-34207 — TypeBot: SSRF Protection Bypass via DNS-Resolved Hostnames in Webhook / HTTP Request Vali…

TypeBot is a chatbot builder tool. In versions prior to 3.16.0, SSRF protection for Webhook / HTTP Request blocks validates only the URL string, blocked hostname literals, and literal IP formats. It …

typebot | Remote | Server-Side Request Forgery
May 22, 2026 May 22, 2026
May 22, 2026
May 22, 2026
10.0 CRITICAL
CVE-2026-33712 — TypeBot: Unauthenticated SSRF via isolated-vm fetch in preview chat endpoint bypasses SSR…

Typebot is a chatbot builder tool. In versions 3.15.2 and prior, the preview chat endpoint (POST /api/v1/typebots/{typebotId}/preview/startChat) allows unauthenticated users to achieve Server-Side Re…

typebot | Remote | Server-Side Request Forgery
May 22, 2026 May 22, 2026
May 22, 2026
May 22, 2026
Showing 20 of 6714 Results