Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.8 HIGH
CVE-2026-36828 — Panabit PAP-XM320 Command Injection Vulnerability

A command injection vulnerability exists in the /cgi-bin/tools/ajax_cmd endpoint of Panabit PAP-XM320 up to and including v7.7. The CGI component allows authenticated users to execute arbitrary shell…

Remote | Injection
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
5.4 MEDIUM
CVE-2026-36827 — Panabit PAP-XM320 Command Injection Vulnerability

A command injection vulnerability exists in Panabit PAP-XM320 up to and including V7.7. The web management interface invokes the backend helper /usr/sbin/pappiw and passes user-controlled parameters …

Remote | Injection
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
6.5 MEDIUM
CVE-2026-8706 — Sensitive user data could be leaked to other applications through Reader mode

Firefox for iOS hosted Reader mode on an unauthenticated local web server, allowing another application on the same device to request arbitrary URLs and receive the response rendered with the signed-…

firefox | Server-Side Request Forgery
May 19, 2026 May 20, 2026
May 19, 2026
May 20, 2026
8.4 HIGH
CVE-2026-5804 — Motorola Factory Test Auth Bypass

An improper authentication vulnerability was discovered in the Motorola Factory Test component (com.motorola.motocit). The application contained a reference to a writable file descriptor in external …

phones | Authentication
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
9.8 CRITICAL
CVE-2026-37281 — Hitarth-gg Zenshin OS Command Injection

An OS command injection vulnerability in the /stream-to-vlc Express route in hitarth-gg Zenshin before 2.7.0 allows remote attackers to execute arbitrary commands via the url parameter.

Remote | Injection
May 19, 2026 May 20, 2026
May 19, 2026
May 20, 2026
9.8 CRITICAL
CVE-2026-31072 — Apache APScheduler Python RCE via Insecure Deserialization

The JSONSerializer and CBORSerializer in APScheduler (all versions including 3.10.x and 4.0.0a5) are vulnerable to Remote Code Execution (RCE) via Insecure Deserialization. The unmarshal_object funct…

Remote | Injection
May 19, 2026 May 20, 2026
May 19, 2026
May 20, 2026
9.1 CRITICAL
CVE-2026-31071 — LalanaChami Pharmacy Management System Unauthenticated API Endpoint Vulnerability

API endpoints in LalanaChami Pharmacy Management System (commit 5c3d028) lack authentication middleware. Unauthenticated remote attackers can exploit this to dump all user records (including bcrypt p…

Remote | Authentication
May 19, 2026 May 20, 2026
May 19, 2026
May 20, 2026
9.8 CRITICAL
CVE-2026-31070 — LalanaChami Pharmacy Management System Privilege Escalation Vulnerability

The LalanaChami Pharmacy Management System (commit 5c3d028) allows unauthenticated remote attackers to escalate privileges by self-assigning an administrative role during registration. The /api/user/…

Remote | Authorization
May 19, 2026 May 20, 2026
May 19, 2026
May 20, 2026
8.8 HIGH
CVE-2026-31069 — BillaBear SQL Injection Vulnerability

BillaBear (all versions prior to Jan 2026) contains a SQL Injection vulnerability in the EventRepository. User-controlled input from metric filter names and aggregation properties is directly interpo…

Remote | Injection
May 19, 2026 May 20, 2026
May 19, 2026
May 20, 2026
9.8 CRITICAL
CVE-2026-30118 — Scalar Astro SSRF

scalar/astro v0.1.13 was discovered to contain a Server-Side Request Forgery (SSRF) in the scalar_url query parameter of the Scalar Proxy endpoint. This vulnerability allows unauthenticated attackers…

Remote | Server-Side Request Forgery
May 19, 2026 May 20, 2026
May 19, 2026
May 20, 2026
9.8 CRITICAL
CVE-2026-30117 — Scalar Astro Arbitrary File Upload Vulnerability

scalar/astro v0.1.13 was discovered to contain an arbitrary file upload vulnerability in the the scalar_url query parameter of the Scalar Proxy endpoint. This vulnerability allows attackers to execut…

Remote | Injection
May 19, 2026 May 20, 2026
May 19, 2026
May 20, 2026
9.8 CRITICAL
CVE-2026-8711 — NGINX JavaScript vulnerability

NGINX JavaScript has a vulnerability when the js_fetch_proxy directive is configured with at least one client-controlled NGINX variable (for example, $http_*, $arg_*, $cookie_*) and a location invoki…

njs | Remote | Memory Corruption
May 19, 2026 Jun 04, 2026
May 19, 2026
Jun 04, 2026
8.7 HIGH
CVE-2026-47100 — Funnel Builder for WooCommerce Checkout < 3.15.0.3 Missing Authorization via AJAX

Funnel Builder for WooCommerce Checkout prior to 3.15.0.3 contains a missing authorization vulnerability in the public checkout endpoint that allows unauthenticated attackers to invoke internal metho…

Remote | Authorization
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
6.9 MEDIUM
CVE-2026-45557 — Technitium DNS Server excessive DNSSEC requests

Technitium DNS Server aggressively tries to fetch missing RRSIG records or mismatched DNSKEY records. An attacker in control of a domain can cause a vulnerable system to generate excessive network tr…

dns_server | Remote | Denial of Service
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
9.8 CRITICAL
CVE-2026-44159 — Tyler Identity Local (TID-L) default administrative credentials

Tyler Identity Local (TID-L) uses documented, default administrative credentials. Users are not required to change the credentials before deployment. TID-L has not been distributed since December 202…

Remote | Authentication
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
8.7 HIGH
CVE-2026-43634 — HestiaCP 1.2.0-1.9.4 IP Spoofing via CF-Connecting-IP Header

HestiaCP versions 1.2.0 through 1.9.4 contain an IP spoofing vulnerability that allows unauthenticated remote attackers to bypass authentication security controls by supplying an arbitrary IP address…

Remote | Authentication
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
5.3 MEDIUM
CVE-2026-34883 — Dell Portrait Color Management Symbolic Link Escalation

An issue was discovered in the Portrait Dell Color Management application before 3.7.0 for Dell monitors. On Windows, a symbolic link vulnerability allows a local low-privileged user to escalate priv…

| Path Traversal
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
9.6 CRITICAL
CVE-2026-2587 — Glassfish Remote Code Execution Vulnerability

A critical Remote Code Execution (RCE) vulnerability was identified in the server-side template rendering mechanism used by the Glassfish gadget handler. The application processes .xml files and eval…

glassfish | Remote | Injection
May 19, 2026 May 21, 2026
May 19, 2026
May 21, 2026
9.1 CRITICAL
CVE-2026-2586 — GlassFish Administration Console Remote Code Execution Vulnerability

An authenticated Remote Code Execution (RCE) vulnerability was identified in GlassFish's Administration Console. A user with access to the panel can send crafted requests that allow the execution of …

glassfish | Remote | Authentication
May 19, 2026 May 21, 2026
May 19, 2026
May 21, 2026
7.3 HIGH
CVE-2025-70950 — Apache Go HTTP Directory Traversal Vulnerability

An issue in gohttp commit 34ea51 allows attackers to execute a directory traversal via supplying a crafted request.

Remote | Path Traversal
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
Showing 20 of 6747 Results