Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.1 MEDIUM
CVE-2025-65954 — SimpleSAMLphp-casserver has an Open Redirect vulnerability via logout

SimpleSAMLphp-casserver is a CAS 1.0 and 2.0 compliant CAS server in the form of a SimpleSAMLphp module. In versions below 6.3.1 and 7.0.0, the logout endpoint accepts a url query parameter to redire…

May 18, 2026 May 27, 2026
May 18, 2026
May 27, 2026
10.0 HIGH
CVE-2026-8836 — lwIP snmpv3 USM snmp_msg.c snmp_parse_inbound_frame stack-based overflow

A vulnerability was found in lwIP up to 2.2.1. Affected is the function snmp_parse_inbound_frame of the file src/apps/snmp/snmp_msg.c of the component snmpv3 USM Handler. Performing a manipulation of…

lwip | Remote | Memory Corruption
May 18, 2026 May 18, 2026
May 18, 2026
May 18, 2026
6.1 MEDIUM
CVE-2026-45243 — Summarize < 0.15.1 Browser Extension Missing Authorization via Content Script

Summarize prior to 0.15.1 contains a missing authorization vulnerability in the content script window.postMessage bridge that allows malicious pages to perform unauthorized operations on automation a…

summarize | Remote | Authorization
May 18, 2026 May 19, 2026
May 18, 2026
May 19, 2026
7.1 HIGH
CVE-2026-45242 — Summarize < 0.15.1 Path Traversal via slidesDir Parameter

Summarize prior to 0.15.1 contains a path traversal vulnerability in the /v1/summarize daemon endpoint that allows authenticated callers to write files to arbitrary directories by supplying an absolu…

summarize | Remote | Path Traversal
May 18, 2026 May 19, 2026
May 18, 2026
May 19, 2026
6.1 MEDIUM
CVE-2026-45231 — DumbAssets 1.0.11 Stored Cross-Site Scripting via Asset Fields

DumbAssets through 1.0.11 contains a stored cross-site scripting vulnerability in asset fields including name, description, modelNumber, serialNumber, and tags that are stored without server-side san…

Remote | Cross-Site Scripting
May 18, 2026 May 18, 2026
May 18, 2026
May 18, 2026
9.8 CRITICAL
CVE-2026-45495 — Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

edge edge_chromium | Remote
May 18, 2026 May 26, 2026
May 18, 2026
May 26, 2026
6.1 MEDIUM
CVE-2026-45494 — Microsoft Edge (Chromium-based) Spoofing Vulnerability

Microsoft Edge (Chromium-based) Spoofing Vulnerability

edge edge_chromium | Remote
May 18, 2026 May 19, 2026
May 18, 2026
May 19, 2026
5.4 MEDIUM
CVE-2026-45492 — Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability

Improper input validation in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.

May 18, 2026 May 19, 2026
May 18, 2026
May 19, 2026
9.1 CRITICAL
CVE-2026-45230 — DumbAssets 1.0.11 Path Traversal File Deletion via /api/delete-file

DumbAssets through 1.0.11 contains a path traversal vulnerability in the POST /api/delete-file endpoint and filesToDelete array parameters that allows unauthenticated attackers to delete arbitrary fi…

Remote | Path Traversal
May 18, 2026 May 18, 2026
May 18, 2026
May 18, 2026
10.0 CRITICAL
CVE-2026-42822 — Azure Local Disconnected Operations (ALDO) Elevation of Privilege Vulnerability

Improper authentication in Azure Local Disconnected Operations allows an unauthorized attacker to elevate privileges over a network.

May 18, 2026 May 21, 2026
May 18, 2026
May 21, 2026
5.7 MEDIUM
CVE-2026-32849 — NetBSD Signed Integer Overflow in cryptodev_op via cryptodev.c

NetBSD prior to commit ec8451e contains a signed integer overflow vulnerability in the cryptodev_op() function in sys/opencrypto/cryptodev.c where the local variable iov_len is declared as a signed i…

| Memory Corruption
May 18, 2026 May 18, 2026
May 18, 2026
May 18, 2026
5.7 MEDIUM
CVE-2026-32848 — NetBSD cryptodev Race Condition Double-Free via cryptodev_op()

NetBSD prior to commit ec8451e contains a race condition vulnerability in cryptodev_op() within the opencrypto subsystem that allows local attackers to trigger a double-free condition by concurrently…

| Race Condition
May 18, 2026 May 18, 2026
May 18, 2026
May 18, 2026
6.1 MEDIUM
CVE-2026-29965 — HSC MailInspector XSS

HSC MailInspector 5.3.3-7 is vulnerable to Cross Site Scripting (XSS) in the /police/WarningUrlPage.php endpoint due to improper neutralization of user-supplied input that uses alternate or obfuscate…

mailinspector | Remote | Cross-Site Scripting
May 18, 2026 May 19, 2026
May 18, 2026
May 19, 2026
6.1 MEDIUM
CVE-2026-29964 — HSC MailInspector Cross-Site Scripting (XSS)

HSC MailInspector v5.3.3-7 contains a Cross-Site Scripting (XSS) vulnerability in the /tap/tap.php endpoint due to improper neutralization of user-controlled input using alternate or obfuscated JavaS…

mailinspector | Remote | Cross-Site Scripting
May 18, 2026 May 19, 2026
May 18, 2026
May 19, 2026
7.5 HIGH
CVE-2026-29963 — HSC MailInspector Path Traversal Vulnerability

HSC MailInspector 5.3.3-7 has a Path Traversal vulnerability due to improper validation of user-supplied input in the /tap/dw.php endpoint. The text parameter is used to construct file paths without …

mailinspector | Remote | Path Traversal
May 18, 2026 May 19, 2026
May 18, 2026
May 19, 2026
7.5 HIGH
CVE-2026-29962 — HSC MailInspector PHP Remote File Disclosure Vulnerability

HSC MailInspector v5.3.3-7 contains a Local File Inclusion (LFI) vulnerability caused by improper control of user-supplied file paths. The endpoint /vendor/phpunit/phpunit.php processes user-controll…

mailinspector | Remote | Path Traversal
May 18, 2026 May 19, 2026
May 18, 2026
May 19, 2026
9.1 CRITICAL
CVE-2023-24215 — NOVUS AirGate 4G Unauthenticated Administrator Credential Disclosure

Incorrect access control in the /uci/get/ endpoint of NOVUS AirGate 4G firmware v1.1.16 allows unauthenticated attackers to obtain administrator credentials via a crafted POST request.

Remote | Authorization
May 18, 2026 May 19, 2026
May 18, 2026
May 19, 2026
7.1 HIGH
CVE-2026-8843 — Calling createIndex with certain index types can crash mongod

Creating a "2dsphere_bucket" index on a non-timeseries bucket collection will succeed, but any subsequent attempt to insert a document which triggers updating that index will crash the server. A simi…

Remote | Misconfiguration
May 18, 2026 May 18, 2026
May 18, 2026
May 18, 2026
10.0 CRITICAL
CVE-2026-45829 — ChromaDB Remote Code Injection Vulnerability

A pre-authentication, code injection vulnerability in version 1.0.0 or later of the ChromaDB Python project allows an unauthenticated attacker to run arbitrary code on the server by sending a malicio…

Remote | Injection
May 18, 2026 May 19, 2026
May 18, 2026
May 19, 2026
8.8 HIGH
CVE-2026-41085 — Thermo Fisher Scientific Torrent Suite Dx Privilege Escalation Vulnerability

Thermo Fisher Scientific Torrent Suite Dx through 5.14.2 has a privilege escalation vulnerability that may allow an authenticated user with limited access privileges to gain unauthorized administrato…

Remote
May 18, 2026 May 18, 2026
May 18, 2026
May 18, 2026
Showing 20 of 7020 Results