Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
10.0 CRITICAL
CVE-2026-48172 — LiteSpeed cPanel Plugin Privilege Escalation Vulnerability - [Actively Exploited]

LiteSpeed User-End cPanel Plugin before 2.4.5 allows privilege escalation (possibly to root), as exploited in the wild in May 2026. Detection is best done via a command line of grep -rE "cpanel_jsona…

litespeed_cpanel_plugin litespeed_whm_plugin | CISA KEV Remote | Authorization
May 21, 2026 May 26, 2026
May 21, 2026
May 26, 2026
4.3 MEDIUM
CVE-2026-1881 — Broadstreet <= 1.52.2 - Authenticated (Subscriber+) Private Post Meta Disclosure via get_…

The Broadstreet plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.52.2 via the get_sponsored_meta AJAX action due to missing validation on…

broadstreet | Remote | Authorization
May 21, 2026 May 21, 2026
May 21, 2026
May 21, 2026
6.5 MEDIUM
CVE-2026-9149 — Libsolv: heap buffer overflow in libsolv repo_add_solv via negative maxsize from crafted …

A flaw was found in libsolv. This heap buffer overflow vulnerability occurs when a victim processes a specially crafted `.solv` file containing negative size values in the `repo_add_solv` function. T…

May 21, 2026 Jun 02, 2026
May 21, 2026
Jun 02, 2026
8.7 HIGH
CVE-2026-40165 — authentik: SAML NameID XML Comment Injection Enables Authentication Bypass via Identifier…

authentik is an open-source identity provider. Versions 2025.12.4 and prior, and versions 2026.2.0-rc1 through 2026.2.2 were vulnerable to Authentication Bypass through SAML NameID XML Comment Inject…

authentik | Remote | Authentication
May 21, 2026 May 21, 2026
May 21, 2026
May 21, 2026
6.5 MEDIUM
CVE-2026-9150 — Libsolv: stack-based buffer overflow in libsolv's debian metadata parser when handling sh…

A flaw was found in libsolv. This stack-based buffer overflow vulnerability occurs in libsolv's Debian metadata parser when processing specially crafted Debian repository metadata. An attacker could …

May 20, 2026 Jun 02, 2026
May 20, 2026
Jun 02, 2026
4.6 MEDIUM
CVE-2026-47782 — Siber Systems, Inc. RoboForm Android Intent URL Injection Vulnerability

Android App "RoboForm Password Manager" provided by Siber Systems, Inc. handles Android intents without sufficient URL validation, user confirmation nor notification. If a URL to some malicious web p…

| Misconfiguration
May 20, 2026 May 21, 2026
May 20, 2026
May 21, 2026
9.1 CRITICAL
CVE-2026-47372 — Crypt::SaltedHash versions through 0.09 for Perl generate insecure random values for salts

Crypt::SaltedHash versions through 0.09 for Perl generate insecure random values for salts. These versions use the built-in rand function, which is predictable and unsuitable for cryptography.

Remote | Cryptography
May 20, 2026 May 21, 2026
May 20, 2026
May 21, 2026
6.5 MEDIUM
CVE-2026-40102 — Plane: ORM Field Reference Injection via `segment` Parameter in Saved Analytics

Plane is an open-source project management tool. In versions 1.3.0 and below, SavedAnalyticEndpoint passes the user-controlled segment query parameter directly to a Django F() expression without vali…

plane | Remote | Injection
May 20, 2026 May 21, 2026
May 20, 2026
May 21, 2026
4.3 MEDIUM
CVE-2026-40094 — nimiq-blockchain: network-libp2p untrusted peer can crash address book via empty peer con…

nimiq-blockchain provides persistent block storage for Nimiq's Rust implementation. In versions 1.3.0 and prior, network-libp2p discovery accepts signed PeerContact updates from untrusted peers and s…

nimiq_proof-of-stake | Remote | Denial of Service
May 20, 2026 May 21, 2026
May 20, 2026
May 21, 2026
7.5 HIGH
CVE-2026-40092 — nimiq-keys: Unchecked Ed25519 signature length in TaggedPublicKey::verify causes remote n…

nimiq-blockchain provides persistent block storage for Nimiq's Rust implementation. In versions 1.3.0 and below, a malicious network peer can crash any Nimiq full node by publishing a crafted Kademli…

nimiq_proof-of-stake | Remote | Denial of Service
May 20, 2026 May 21, 2026
May 20, 2026
May 21, 2026
5.4 MEDIUM
CVE-2026-39960 — MantisBT is Vulnerable to Stored XSS through Custom Field Textarea Values

Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.1 and below contain flawed logic that causes improper escaping of a textarea custom field's contents in the Update Issue p…

mantisbt | Remote | Cross-Site Scripting
May 20, 2026 May 21, 2026
May 20, 2026
May 21, 2026
8.5 HIGH
CVE-2026-8632 — HP Linux Imaging and Printing Software – Potential Escalation of Privilege and Arbitrary …

A potential security vulnerability has been identified in the HP Linux Imaging and Printing Software. This potential vulnerability may allow escalation of privileges and/or arbitrary code execution v…

May 20, 2026 May 21, 2026
May 20, 2026
May 21, 2026
9.8 CRITICAL
CVE-2026-8631 — HP Linux Imaging and Printing Software – Potential Escalation of Privilege and Arbitrary …

A potential security vulnerability has been identified in the HP Linux Imaging and Printing Software. This potential vulnerability may allow escalation of privileges and/or arbitrary code execution v…

May 20, 2026 May 21, 2026
May 20, 2026
May 21, 2026
7.5 HIGH
CVE-2026-47373 — Crypt::SaltedHash versions through 0.09 for Perl is susceptible to timing attacks

Crypt::SaltedHash versions through 0.09 for Perl is susceptible to timing attacks. These versions use Perl's built-in eq comparison. Discrepencies in timing could be used to guess the underlying has…

Remote | Cryptography
May 20, 2026 May 21, 2026
May 20, 2026
May 21, 2026
8.4 HIGH
CVE-2026-9144 — Taiko AG1000-01A Rev 7.3/8 Stored XSS via Web Configuration Interface

Taiko AG1000-01A SMS Alert Gateway Rev 7.3 and Rev 8 contains a stored cross-site scripting vulnerability in the embedded web configuration interface that allows authenticated attackers to execute pe…

Remote | Cross-Site Scripting
May 20, 2026 May 21, 2026
May 20, 2026
May 21, 2026
9.8 CRITICAL
CVE-2026-9141 — Taiko AG1000-01A Rev 7.3/8 Authentication Bypass via Web Interface

Taiko AG1000-01A SMS Alert Gateway Rev 7.3 and Rev 8 contains an authentication bypass vulnerability in the embedded web configuration interface that allows unauthenticated attackers to access intern…

Remote | Authentication
May 20, 2026 May 21, 2026
May 20, 2026
May 21, 2026
9.8 CRITICAL
CVE-2026-9139 — Taiko AG1000-01A Rev 7.3/8 Hard-coded Credentials via login.zhtml

Taiko AG1000-01A SMS Alert Gateway Rev 7.3 and Rev 8 contains a hard-coded credential vulnerability in the embedded web configuration interface where authentication is implemented entirely in client-…

Remote | Authentication
May 20, 2026 May 21, 2026
May 20, 2026
May 21, 2026
7.5 HIGH
CVE-2026-9137 — CSP Report Endpoint Log Flooding in MISP via Incorrect Size Limit

The CSP report endpoint in MISP intended to limit logged CSP reports to 1 KB but incorrectly allowed reports up to 1 MB before truncation. On deployments where the endpoint is reachable by untrusted …

misp | Remote | Denial of Service
May 20, 2026 Jun 02, 2026
May 20, 2026
Jun 02, 2026
8.3 HIGH
CVE-2026-9136 — Unauthorized ShadowAttribute modification in MISP via client-supplied identifier

A vulnerability was identified in the ShadowAttribute proposal creation workflow. The add action accepted user-controlled ShadowAttribute request data without removing the id field before saving the …

misp | Remote | Authorization
May 20, 2026 Jun 02, 2026
May 20, 2026
Jun 02, 2026
8.3 HIGH
CVE-2026-9133 — Arbitrary file read in rabbitmq-aws plugin

Active debug code exists in the ARN resolver of amazon-mq rabbitmq-aws before version 0.2.1. A debug ARN scheme (arn:aws-debug:file) accepted by the PUT /api/aws/arn/validate validation endpoint migh…

rabbitmq_aws | Remote | Information Disclosure
May 20, 2026 May 21, 2026
May 20, 2026
May 21, 2026
Showing 20 of 6714 Results