Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.8 MEDIUM
CVE-2026-45246 — Summarize < 0.15.1 Insecure File Permissions Information Disclosure

Summarize prior to 0.15.1 contains an insecure file permission vulnerability in the refresh-free configuration rewrite path that allows local users to read sensitive credentials by exploiting default…

summarize | Misconfiguration
May 18, 2026 May 19, 2026
May 18, 2026
May 19, 2026
7.4 HIGH
CVE-2026-45245 — Summarize < 0.15.1 Unauthorized Daemon Request via Untrusted Events

Summarize prior to 0.15.1 contains a vulnerability in the hover summary feature that allows malicious pages to dispatch synthetic mouseover events over attacker-controlled links, causing the extensio…

summarize | Remote | Server-Side Request Forgery
May 18, 2026 May 19, 2026
May 18, 2026
May 19, 2026
5.4 MEDIUM
CVE-2026-45244 — Summarize < 0.15.1 Unapproved Browser Automation Execution

Summarize prior to 0.15.1 contains a missing authorization vulnerability that allows attackers to execute browser automation actions without per-call user approval when the extension automation featu…

summarize | Remote | Authorization
May 18, 2026 May 19, 2026
May 18, 2026
May 19, 2026
4.6 MEDIUM
CVE-2026-21789 — HCL Connections is vulnerable to broken access control

HCL Connections contains a broken access control vulnerability that may allow unauthorized user to update data in certain scenarios.

Remote | Authorization
May 18, 2026 May 18, 2026
May 18, 2026
May 18, 2026
6.1 MEDIUM
CVE-2025-65954 — SimpleSAMLphp-casserver has an Open Redirect vulnerability via logout

SimpleSAMLphp-casserver is a CAS 1.0 and 2.0 compliant CAS server in the form of a SimpleSAMLphp module. In versions below 6.3.1 and 7.0.0, the logout endpoint accepts a url query parameter to redire…

May 18, 2026 May 27, 2026
May 18, 2026
May 27, 2026
10.0 HIGH
CVE-2026-8836 — lwIP snmpv3 USM snmp_msg.c snmp_parse_inbound_frame stack-based overflow

A vulnerability was found in lwIP up to 2.2.1. Affected is the function snmp_parse_inbound_frame of the file src/apps/snmp/snmp_msg.c of the component snmpv3 USM Handler. Performing a manipulation of…

lwip | Remote | Memory Corruption
May 18, 2026 May 18, 2026
May 18, 2026
May 18, 2026
6.1 MEDIUM
CVE-2026-45243 — Summarize < 0.15.1 Browser Extension Missing Authorization via Content Script

Summarize prior to 0.15.1 contains a missing authorization vulnerability in the content script window.postMessage bridge that allows malicious pages to perform unauthorized operations on automation a…

summarize | Remote | Authorization
May 18, 2026 May 19, 2026
May 18, 2026
May 19, 2026
7.1 HIGH
CVE-2026-45242 — Summarize < 0.15.1 Path Traversal via slidesDir Parameter

Summarize prior to 0.15.1 contains a path traversal vulnerability in the /v1/summarize daemon endpoint that allows authenticated callers to write files to arbitrary directories by supplying an absolu…

summarize | Remote | Path Traversal
May 18, 2026 May 19, 2026
May 18, 2026
May 19, 2026
6.1 MEDIUM
CVE-2026-45231 — DumbAssets 1.0.11 Stored Cross-Site Scripting via Asset Fields

DumbAssets through 1.0.11 contains a stored cross-site scripting vulnerability in asset fields including name, description, modelNumber, serialNumber, and tags that are stored without server-side san…

Remote | Cross-Site Scripting
May 18, 2026 May 18, 2026
May 18, 2026
May 18, 2026
9.8 CRITICAL
CVE-2026-45495 — Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

Microsoft Edge (Chromium-based) Remote Code Execution Vulnerability

edge edge_chromium | Remote
May 18, 2026 May 26, 2026
May 18, 2026
May 26, 2026
6.1 MEDIUM
CVE-2026-45494 — Microsoft Edge (Chromium-based) Spoofing Vulnerability

Microsoft Edge (Chromium-based) Spoofing Vulnerability

edge edge_chromium | Remote
May 18, 2026 May 19, 2026
May 18, 2026
May 19, 2026
5.4 MEDIUM
CVE-2026-45492 — Microsoft Edge (Chromium-based) Security Feature Bypass Vulnerability

Improper input validation in Microsoft Edge (Chromium-based) allows an unauthorized attacker to bypass a security feature over a network.

May 18, 2026 May 19, 2026
May 18, 2026
May 19, 2026
9.1 CRITICAL
CVE-2026-45230 — DumbAssets 1.0.11 Path Traversal File Deletion via /api/delete-file

DumbAssets through 1.0.11 contains a path traversal vulnerability in the POST /api/delete-file endpoint and filesToDelete array parameters that allows unauthenticated attackers to delete arbitrary fi…

Remote | Path Traversal
May 18, 2026 May 18, 2026
May 18, 2026
May 18, 2026
10.0 CRITICAL
CVE-2026-42822 — Azure Local Disconnected Operations (ALDO) Elevation of Privilege Vulnerability

Improper authentication in Azure Local Disconnected Operations allows an unauthorized attacker to elevate privileges over a network.

May 18, 2026 May 21, 2026
May 18, 2026
May 21, 2026
5.7 MEDIUM
CVE-2026-32849 — NetBSD Signed Integer Overflow in cryptodev_op via cryptodev.c

NetBSD prior to commit ec8451e contains a signed integer overflow vulnerability in the cryptodev_op() function in sys/opencrypto/cryptodev.c where the local variable iov_len is declared as a signed i…

| Memory Corruption
May 18, 2026 May 18, 2026
May 18, 2026
May 18, 2026
5.7 MEDIUM
CVE-2026-32848 — NetBSD cryptodev Race Condition Double-Free via cryptodev_op()

NetBSD prior to commit ec8451e contains a race condition vulnerability in cryptodev_op() within the opencrypto subsystem that allows local attackers to trigger a double-free condition by concurrently…

| Race Condition
May 18, 2026 May 18, 2026
May 18, 2026
May 18, 2026
6.1 MEDIUM
CVE-2026-29965 — HSC MailInspector XSS

HSC MailInspector 5.3.3-7 is vulnerable to Cross Site Scripting (XSS) in the /police/WarningUrlPage.php endpoint due to improper neutralization of user-supplied input that uses alternate or obfuscate…

mailinspector | Remote | Cross-Site Scripting
May 18, 2026 May 19, 2026
May 18, 2026
May 19, 2026
6.1 MEDIUM
CVE-2026-29964 — HSC MailInspector Cross-Site Scripting (XSS)

HSC MailInspector v5.3.3-7 contains a Cross-Site Scripting (XSS) vulnerability in the /tap/tap.php endpoint due to improper neutralization of user-controlled input using alternate or obfuscated JavaS…

mailinspector | Remote | Cross-Site Scripting
May 18, 2026 May 19, 2026
May 18, 2026
May 19, 2026
7.5 HIGH
CVE-2026-29963 — HSC MailInspector Path Traversal Vulnerability

HSC MailInspector 5.3.3-7 has a Path Traversal vulnerability due to improper validation of user-supplied input in the /tap/dw.php endpoint. The text parameter is used to construct file paths without …

mailinspector | Remote | Path Traversal
May 18, 2026 May 19, 2026
May 18, 2026
May 19, 2026
7.5 HIGH
CVE-2026-29962 — HSC MailInspector PHP Remote File Disclosure Vulnerability

HSC MailInspector v5.3.3-7 contains a Local File Inclusion (LFI) vulnerability caused by improper control of user-supplied file paths. The endpoint /vendor/phpunit/phpunit.php processes user-controll…

mailinspector | Remote | Path Traversal
May 18, 2026 May 19, 2026
May 18, 2026
May 19, 2026
Showing 20 of 7020 Results