Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.3 CRITICAL
CVE-2026-47202 — Kavita: Pre-Auth Account Takeover

Kavita is a cross platform reading server. Prior to 0.9.0.2, an Improper Token validation flaw permits a remote and unauthenticated threat actor to request a JWT for any user including admins given k…

kavita | Remote | Authentication
May 26, 2026 May 26, 2026
May 26, 2026
May 26, 2026
9.9 CRITICAL
CVE-2026-46624 — Twenty: SQL Injection via the timeZone field

Twenty is an open source CRM. From 1.7.7 through 1.16.7, a critical Remote Code Execution (RCE) vulnerability exists in Twenty CRM via a chained SQL Injection and PostgreSQL COPY TO PROGRAM attack. I…

twenty | Remote | Injection
May 26, 2026 May 27, 2026
May 26, 2026
May 27, 2026
5.9 MEDIUM
CVE-2026-44776 — Kavita: IDOR in /api/Download/*

Kavita is a cross platform reading server. Prior to 0.9.0, the download, size-check, and chapter metadata endpoints do not enforce library-level authorization. A low-privileged user who knows or gues…

kavita | Remote | Authorization
May 26, 2026 May 26, 2026
May 26, 2026
May 26, 2026
6.9 MEDIUM
CVE-2026-44775 — Kavita: No authentication at /api/Reader/image

Kavita is a cross platform reading server. Prior to 0.9.0, the ReaderController.GetImage endpoint is decorated with [AllowAnonymous], allowing completely unauthenticated access to page images from an…

kavita | Remote | Authentication
May 26, 2026 May 26, 2026
May 26, 2026
May 26, 2026
4.3 MEDIUM
CVE-2026-44749 — Information Disclosure vulnerability in SAP Gateway

The SAP Gateway allows attackers to inject content into error messages, potentially leading to disclosure of request artefacts (e.g., regex patterns) and revealing underlying URI parsing logic. Leadi…

gateway | Remote | Injection
May 26, 2026 May 26, 2026
May 26, 2026
May 26, 2026
7.2 HIGH
CVE-2026-44730 — OpenCTI: Privilege escalation via graphQL API abusable by organization admins, due to inc…

OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. Prior to 6.9.7, an organization admin can escalate their privileges by adding a user from a differ…

opencti | Remote | Authorization
May 26, 2026 May 27, 2026
May 26, 2026
May 27, 2026
8.2 HIGH
CVE-2026-44728 — Improper Control of Generation of Code when compiling specifically crafted malicious code…

Babel is a compiler for writing next generation JavaScript. From 7.12.0 to before 7.29.4 and 8.0.0-alpha.13, using Babel to compile code that was specifically crafted by an attacker can cause Babel t…

babel | Memory Corruption
May 26, 2026 May 27, 2026
May 26, 2026
May 27, 2026
6.8 MEDIUM
CVE-2026-44707 — Chatwoot: Pre-Account Takeover via OAuth on Unconfirmed Accounts

Chatwoot is a customer engagement suite. From 2.14.0 to before 4.13.0, a Pre-Account Takeover (Pre-ATO) vulnerability existed in Chatwoot's authentication flow. Because email confirmation was not enf…

chatwoot | Remote | Authentication
May 26, 2026 May 26, 2026
May 26, 2026
May 26, 2026
8.5 HIGH
CVE-2026-44706 — Chatwoot: SQL Injection in Conversation/Contact Filter API via Custom Attribute Values

Chatwoot is a customer engagement suite. From 2.2.0 to before 4.11.2, a SQL injection vulnerability exists in the conversation and contact filter APIs. When filtering by a custom attribute of type da…

chatwoot | Remote | Injection
May 26, 2026 May 26, 2026
May 26, 2026
May 26, 2026
8.7 HIGH
CVE-2026-44669 — Faction: Stored XSS in Assessment Attachment Filename Preview Rendering

FACTION is a PenTesting Report Generation and Collaboration Framework. Prior to 1.8.3, Faction is vulnerable to stored cross-site scripting (XSS) via attachment filenames in assessment file preview f…

faction | Remote | Cross-Site Scripting
May 26, 2026 May 26, 2026
May 26, 2026
May 26, 2026
9.8 CRITICAL
CVE-2026-44668 — Faction: Unauthenticated Read, Modify, and Delete of Boilerplate Templates

FACTION is a PenTesting Report Generation and Collaboration Framework. Prior to 1.8.3, AccessControlInterceptor, the authentication gate for all Struts2 actions, unconditionally calls invocation.invo…

faction | Remote | Authentication
May 26, 2026 May 27, 2026
May 26, 2026
May 27, 2026
8.7 HIGH
CVE-2026-44667 — Faction: Stored XSS in Remediation Verification Attachment Filename Preview Rendering

FACTION is a PenTesting Report Generation and Collaboration Framework. Prior to 1.8.3, Faction is vulnerable to stored cross-site scripting (XSS) via attachment filenames in remediation verification …

faction | Remote | Cross-Site Scripting
May 26, 2026 May 27, 2026
May 26, 2026
May 27, 2026
3.5 LOW
CVE-2026-42448 — wormhole receive, with --output pointing at an existing directory can be path-traversed

Magic Wormhole makes it possible to get arbitrary-sized files and directories from one computer to another. Prior to 0.24.0, there is a path traversal when a receiver who specifies "--output <dir>" w…

magic_wormhole | Remote | Path Traversal
May 26, 2026 May 26, 2026
May 26, 2026
May 26, 2026
4.4 MEDIUM
CVE-2026-41164 — nuts-node: JWT type confusion in v1 access token introspection allows VP replay as access…

nuts-node is the reference implementation of the Nuts specification. Prior to 6.2.3 and 5.4.31, the v1 access token introspection endpoint (/auth/v1/introspect_access_token) accepts any JWT signed by…

Remote | Authentication
May 26, 2026 May 26, 2026
May 26, 2026
May 26, 2026
5.8 MEDIUM
CVE-2026-24201 — NVIDIA vGPU Out-of-Bound Access Vulnerability

NVIDIA vGPU software contains a vulnerability in the virtual GPU manager, where an attacker could cause an out-of-bound access. A successful exploit of this vulnerability might lead to data tampering…

geforce tesla | Memory Corruption
May 26, 2026 May 26, 2026
May 26, 2026
May 26, 2026
7.0 HIGH
CVE-2026-24200 — NVIDIA vGPU Use-After-Free Vulnerability

NVIDIA vGPU software contains a vulnerability in the virtual GPU manager, where an attacker could cause a use-after-free for stack memory. A successful exploit of this vulnerability might lead to den…

geforce tesla | Memory Corruption
May 26, 2026 May 26, 2026
May 26, 2026
May 26, 2026
4.7 MEDIUM
CVE-2026-24199 — NVIDIA Display Driver for Linux Kernel Module Race Condition Vulnerability

NVIDIA Display Driver for Linux contains a vulnerability in a kernel module, where a user could cause a race condition by reordering compiler or processor memory instructions. A successful exploit of…

May 26, 2026 May 27, 2026
May 26, 2026
May 27, 2026
5.6 MEDIUM
CVE-2026-24198 — NVIDIA GPU Display Driver for Linux Memory Leak and Denial of Service

NVIDIA GPU Display Driver for Linux contains a vulnerability where an advanced attacker could use a race condition to leak sensitive memory, which might cause limited exposure of sensitive informati…

geforce tesla | Race Condition
May 26, 2026 May 26, 2026
May 26, 2026
May 26, 2026
6.5 MEDIUM
CVE-2026-24197 — NVIDIA Display Driver for Linux MIG Partition Management Memory Corruption Denial of Serv…

NVIDIA Display Driver for Linux contains a vulnerability in the Multi-Instance GPU (MIG) partition management, where an insecure default initialization of memory subsystem routing resources could lea…

geforce tesla | Misconfiguration
May 26, 2026 May 26, 2026
May 26, 2026
May 26, 2026
7.1 HIGH
CVE-2026-24196 — NVIDIA Display Driver for Linux Out-of-Bounds Read Information Disclosure and Denial of S…

NVIDIA Display Driver for Linux contains a vulnerability where a user could cause an out-of-bounds read. A successful exploit of this vulnerability might lead to denial of service and information dis…

geforce tesla | Information Disclosure
May 26, 2026 May 26, 2026
May 26, 2026
May 26, 2026
Showing 20 of 6736 Results