Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.5 HIGH
CVE-2026-9372 — ItzCrazyKns Vane Model Provider API route.ts server-side request forgery

A flaw has been found in ItzCrazyKns Vane up to 1.12.1. This vulnerability affects unknown code of the file src/app/api/providers/route.ts of the component Model Provider API. This manipulation of th…

vane | Remote | Server-Side Request Forgery
May 24, 2026 May 26, 2026
May 24, 2026
May 26, 2026
5.6 MEDIUM
CVE-2026-9371 — ItzCrazyKns Vane API route.ts missing authentication

A security vulnerability has been detected in ItzCrazyKns Vane up to 1.12.1. Affected by this issue is some unknown functionality of the file route.ts of the component API. The manipulation leads to …

vane | Remote | Authentication
May 24, 2026 May 26, 2026
May 24, 2026
May 26, 2026
3.7 LOW
CVE-2026-9370 — ulisesbocchio jasypt-spring-boot Password Hash SimpleGCMConfig.java getSecretKeySaltGener…

A weakness has been identified in ulisesbocchio jasypt-spring-boot up to 3.0.5/4.0.4. Affected by this vulnerability is the function getSecretKeySaltGenerator of the file jasypt-spring-boot/src/main/…

jasypt-spring-boot | Remote | Cryptography
May 24, 2026 May 26, 2026
May 24, 2026
May 26, 2026
5.3 MEDIUM
CVE-2026-9369 — NousResearch hermes-agent CLI web-dashboard web_server.py _discover_dashboard_plugins com…

A security flaw has been discovered in NousResearch hermes-agent 2026.4.23. Affected is the function _discover_dashboard_plugins of the file hermes_cli/web_server.py of the component CLI web-dashboar…

hermes-agent | Misconfiguration
May 24, 2026 May 26, 2026
May 24, 2026
May 26, 2026
7.5 HIGH
CVE-2026-9368 — NousResearch hermes-agent Environment Variable code_execution_tool.py execute_code sandbox

A vulnerability was identified in NousResearch hermes-agent up to 2026.4.16. This impacts the function execute_code of the file tools/code_execution_tool.py of the component Environment Variable Hand…

hermes-agent | Remote | Misconfiguration
May 24, 2026 May 26, 2026
May 24, 2026
May 26, 2026
7.5 HIGH
CVE-2026-9367 — NousResearch hermes-agent terminal_tool approval.py detect_dangerous_command os command i…

A vulnerability was determined in NousResearch hermes-agent up to 5157f5427f19488b31c6fdebbacd15d798ce7f63. This affects the function detect_dangerous_command of the file tools/approval.py of the com…

hermes-agent | Remote | Injection
May 24, 2026 May 26, 2026
May 24, 2026
May 26, 2026
7.5 HIGH
CVE-2026-9366 — NousResearch hermes-agent prompt_builder.py _scan_context_content injection

A vulnerability was found in NousResearch hermes-agent 2026.4.23. The impacted element is the function _scan_context_content of the file agent/prompt_builder.py. The manipulation results in injection…

hermes-agent | Remote | Injection
May 24, 2026 May 26, 2026
May 24, 2026
May 26, 2026
5.6 MEDIUM
CVE-2026-9365 — Ettercap GG Dissector ec_gg.c FUNC_DECODER heap-based overflow

A vulnerability has been found in Ettercap up to 0.8.3. The affected element is the function FUNC_DECODER of the file src/dissectors/ec_gg.c of the component GG Dissector. The manipulation of the arg…

ettercap | Remote | Memory Corruption
May 24, 2026 May 26, 2026
May 24, 2026
May 26, 2026
7.5 HIGH
CVE-2026-9364 — projectworlds Online Art Gallery Shop adminHome.php sql injection

A flaw has been found in projectworlds Online Art Gallery Shop 1.0. Impacted is an unknown function of the file /admin/adminHome.php. Executing a manipulation of the argument social_linked can lead t…

online_art_gallery_shop | Remote | Injection
May 24, 2026 May 26, 2026
May 24, 2026
May 26, 2026
6.5 MEDIUM
CVE-2026-9363 — Edimax EW-7438RPn POST Request formEZCHNwlanSetu formEZCHNwlanSetup command injection

A vulnerability was detected in Edimax EW-7438RPn 1.12. This issue affects the function formEZCHNwlanSetup of the file /goform/formEZCHNwlanSetu of the component POST Request Handler. Performing a ma…

ew-7438rpn | Remote | Injection
May 24, 2026 May 26, 2026
May 24, 2026
May 26, 2026
6.5 MEDIUM
CVE-2026-9362 — Edimax EW-7438RPn Setting formConnectionSetting command injection

A security vulnerability has been detected in Edimax EW-7438RPn 1.12. This vulnerability affects the function formConnectionSetting of the file /goform/formConnectionSetting of the component Setting …

ew-7438rpn | Remote | Injection
May 24, 2026 May 26, 2026
May 24, 2026
May 26, 2026
6.5 MEDIUM
CVE-2026-9361 — Edimax EW-7438RPn POST Request formAccep formAccept command injection

A weakness has been identified in Edimax EW-7438RPn 1.12. This affects the function formAccept of the file /goform/formAccep of the component POST Request Handler. This manipulation of the argument s…

ew-7438rpn | Remote | Injection
May 24, 2026 May 26, 2026
May 24, 2026
May 26, 2026
9.0 HIGH
CVE-2026-9360 — Edimax EW-7438RPn POST Request formwlencrypt24g buffer overflow

A security flaw has been discovered in Edimax EW-7438RPn 1.28a. Affected by this issue is the function formwlencrypt24g of the file /goform/formwlencrypt24g of the component POST Request Handler. The…

ew-7438rpn | Remote | Memory Corruption
May 24, 2026 May 26, 2026
May 24, 2026
May 26, 2026
6.5 MEDIUM
CVE-2026-9359 — Edimax EW-7438RPn POST Request formHwSet command injection

A vulnerability was identified in Edimax EW-7438RPn 1.28a. Affected by this vulnerability is the function formHwSet of the file /goform/formHwSet of the component POST Request Handler. The manipulati…

ew-7438rpn | Remote | Injection
May 24, 2026 May 26, 2026
May 24, 2026
May 26, 2026
5.0 MEDIUM
CVE-2026-9358 — postcss AST Serialization container.js toString recursion

A vulnerability was determined in postcss up to 7.1.1. Affected is the function toString of the file src/selectors/container.js of the component AST Serialization. Executing a manipulation can lead t…

postcss | Remote | Denial of Service
May 24, 2026 May 26, 2026
May 24, 2026
May 26, 2026
4.0 MEDIUM
CVE-2026-9357 — vBulletin Login cross site scripting

A vulnerability was found in vBulletin 6.x. This impacts an unknown function of the component Login. Performing a manipulation results in cross site scripting. It is possible to initiate the attack r…

vbulletin | Remote | Cross-Site Scripting
May 24, 2026 May 26, 2026
May 24, 2026
May 26, 2026
7.5 HIGH
CVE-2026-9356 — SourceCodester Hospitals Patient Records Management System manage_history.php sql injecti…

A vulnerability has been found in SourceCodester Hospitals Patient Records Management System 1.0. This affects an unknown function of the file /admin/patients/manage_history.php. Such manipulation of…

May 24, 2026 May 26, 2026
May 24, 2026
May 26, 2026
7.5 HIGH
CVE-2026-9355 — SourceCodester Hospitals Patient Records Management System Master.php save_patient_histor…

A flaw has been found in SourceCodester Hospitals Patient Records Management System 1.0. The impacted element is an unknown function of the file /classes/Master.php?f=save_patient_history. This manip…

May 24, 2026 May 26, 2026
May 24, 2026
May 26, 2026
6.5 MEDIUM
CVE-2026-9354 — NousResearch hermes-agent Slack Agent/Mattermost Agent escape output

A vulnerability was detected in NousResearch hermes-agent up to 2026.4.16. The affected element is an unknown function of the component Slack Agent/Mattermost Agent. The manipulation of the argument …

hermes-agent | Remote | Injection
May 24, 2026 May 26, 2026
May 24, 2026
May 26, 2026
7.5 HIGH
CVE-2026-9353 — NousResearch hermes-agent Skills Guard Multi-Word Prompt skills_guard.py injection

A security vulnerability has been detected in NousResearch hermes-agent up to 2026.4.23. Impacted is an unknown function of the file agent/skills_guard.py of the component Skills Guard Multi-Word Pro…

hermes-agent | Remote | Injection
May 24, 2026 May 26, 2026
May 24, 2026
May 26, 2026
Showing 20 of 6689 Results