Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.7 HIGH
CVE-2026-39806 — HTTP/1 chunked decoder infinite loop on requests with trailer fields in bandit

Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability in mtrudel bandit allows unauthenticated remote denial of service via worker process exhaustion. 'Elixir.Bandit.HTTP1.Socket':do_…

bandit | Remote | Denial of Service
May 13, 2026 May 21, 2026
May 13, 2026
May 21, 2026
8.7 HIGH
CVE-2026-39803 — HTTP/1 chunked body reader ignores length cap in bandit

Allocation of Resources Without Limits or Throttling vulnerability in mtrudel bandit allows unauthenticated remote denial of service via memory exhaustion. The chunked clause of 'Elixir.Bandit.HTTP1…

bandit | Remote | Denial of Service
May 13, 2026 May 21, 2026
May 13, 2026
May 21, 2026
7.3 HIGH
CVE-2026-37430 — Qihang WMS Arbitrary Code Execution Vulnerability

An arbitrary file upload vulnerability in the ShopOrderImportController.java component of qihang-wms commit 75c15a allows attackers to execute arbitrary code via uploading a crafted file.

Remote | Misconfiguration
May 13, 2026 May 14, 2026
May 13, 2026
May 14, 2026
6.5 MEDIUM
CVE-2026-37429 — Qihang WMS SQL Injection

qihang-wms commit 75c15a was discovered to contain a SQL injection vulnerability via the datascope parameter in the SysUserMapper.xml file. This vulnerability allows attackers to access sensitive dat…

Remote | Injection
May 13, 2026 May 13, 2026
May 13, 2026
May 13, 2026
6.5 MEDIUM
CVE-2026-37428 — Qihang WMS SQL Injection Vulnerability

qihang-wms commit 75c15a was discovered to contain a SQL injection vulnerability via the datascope parameter in the SysDeptMapper.xml file. This vulnerability allows attackers to access sensitive dat…

Remote | Injection
May 13, 2026 May 13, 2026
May 13, 2026
May 13, 2026
7.2 HIGH
CVE-2026-6177 — Custom Twitter Feeds <= 2.5.4 - Unauthenticated Stored Cross-Site Scripting via Cached Tw…

The Custom Twitter Feeds plugin for WordPress is vulnerable to Stored Cross-Site Scripting in versions up to and including 2.5.4. This is due to insufficient output escaping in the CTF_Display_Elemen…

custom_twitter_feeds | Remote | Cross-Site Scripting
May 13, 2026 May 13, 2026
May 13, 2026
May 13, 2026
5.1 MEDIUM
CVE-2026-42961 — ELECOM Wireless LAN Access Point CSRF

ELECOM wireless LAN access point devices implement CSRF protection mechanism, but with inadequate handling of CSRF tokens. If a user views a malicious page while logged in, the user may be tricked to…

| Cross-Site Request Forgery
May 13, 2026 May 13, 2026
May 13, 2026
May 13, 2026
5.1 MEDIUM
CVE-2026-42950 — ELECOM Wireless LAN Access Point Language Parameter Validation Bypass

ELECOM wireless LAN access point devices do not check if language parameter has an appropriate value. If a user views a malicious page while logged in, the admin page on the user's web browser may be…

| Misconfiguration
May 13, 2026 May 13, 2026
May 13, 2026
May 13, 2026
4.8 MEDIUM
CVE-2026-42948 — ELECOM Wireless LAN Access Point Stored XSS

Stored cross-site scripting vulnerability exists in ELECOM wireless LAN access point devices. If one of the administrators input malicious data, an arbitrary script may be executed in another adminis…

| Cross-Site Scripting
May 13, 2026 May 13, 2026
May 13, 2026
May 13, 2026
9.8 CRITICAL
CVE-2026-42062 — ELECOM Wireless LAN Access Point OS Command Injection Vulnerability

ELECOM wireless LAN access point devices contain an OS command injection in processing of username parameter. If processing a crafted request, an arbitrary OS command may be executed. No authenticati…

| Injection
May 13, 2026 May 13, 2026
May 13, 2026
May 13, 2026
9.8 CRITICAL
CVE-2026-40621 — ELECOM Wireless LAN Access Point Unauthenticated Access Vulnerability

ELECOM wireless LAN access point devices do not require authentication to access some specific URLs. The affected product may be operated without authentication.

| Authentication
May 13, 2026 May 13, 2026
May 13, 2026
May 13, 2026
4.3 MEDIUM
CVE-2026-3426 — RTMKit Addons for Elementor <= 2.0.2 - Authenticated (Author+) Missing Authorization to W…

The RTMKit Addons for Elementor plugin for WordPress is vulnerable to unauthorized modification of data due to missing capability checks on the save_widget() and reset_all_widgets() functions in all …

romethemekit_for_elementor | Remote | Authorization
May 13, 2026 May 13, 2026
May 13, 2026
May 13, 2026
8.8 HIGH
CVE-2026-3425 — RTMKit Addons for Elementor <= 2.0.2 - Authenticated (Author+) Local File Inclusion via '…

The RTMKit Addons for Elementor plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.0.2 via the 'path' parameter of the 'get_content' AJAX action. This …

romethemekit_for_elementor | Remote | Path Traversal
May 13, 2026 May 13, 2026
May 13, 2026
May 13, 2026
8.6 HIGH
CVE-2026-35506 — ELECOM Wireless LAN Access Point OS Command Injection Vulnerability

ELECOM wireless LAN access point devices contain an OS command injection vulnerability in processing of ping_ip_addr parameter. If processing a crafted request sent by a logged-in user, an arbitrary …

| Injection
May 13, 2026 May 13, 2026
May 13, 2026
May 13, 2026
6.9 MEDIUM
CVE-2026-25107 — ELECOM Wireless LAN Access Point Device Cryptographic Key Weakness

ELECOM wireless LAN access point devices use a hard-coded cryptographic key when creating backups of configuration files. An attacker who knows the encryption key can tamper the configuration file of…

May 13, 2026 May 13, 2026
May 13, 2026
May 13, 2026
5.3 MEDIUM
CVE-2026-7168 — cross-proxy Digest auth state leak

Successfully using libcurl to do a transfer over a specific HTTP proxy (`proxyA`) with **Digest** authentication and then changing the proxy host to a second one (`proxyB`) for a second transfer, reu…

curl | Remote | Authentication
May 13, 2026 May 14, 2026
May 13, 2026
May 14, 2026
5.3 MEDIUM
CVE-2026-7009 — OCSP stapling bypass with Apple SecTrust

When curl is told to use the Certificate Status Request TLS extension, often referred to as *OCSP stapling*, to verify that the server certificate is valid, it fails to detect OCSP problems and inste…

curl | Remote | Cryptography
May 13, 2026 May 14, 2026
May 13, 2026
May 14, 2026
5.3 MEDIUM
CVE-2026-6429 — netrc credential leak with reused proxy connection

When asked to both use a `.netrc` file for credentials and to follow HTTP redirects, libcurl could leak the password used for the first host to the followed-to host under certain circumstances.

curl | Remote | Information Disclosure
May 13, 2026 May 14, 2026
May 13, 2026
May 14, 2026
7.5 HIGH
CVE-2026-6276 — stale custom cookie host causes cookie leak

Using libcurl, when a custom `Host:` header is first set for an HTTP request and a second request is subsequently done using the same *easy handle* but without the custom `Host:` header set, the seco…

curl | Remote | Misconfiguration
May 13, 2026 May 14, 2026
May 13, 2026
May 14, 2026
5.9 MEDIUM
CVE-2026-6253 — proxy credentials leak over redirect-to proxy

curl might erroneously pass on credentials for a first proxy to a second proxy. This can happen when the following conditions are true: 1. curl is setup to use specific different proxies for differ…

curl | Remote | Authentication
May 13, 2026 May 14, 2026
May 13, 2026
May 14, 2026
Showing 20 of 7244 Results