Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.2 HIGH
CVE-2026-6973 — Ivanti Endpoint Manager Mobile (EPMM) Improper Input Validation Vulnerability - [Actively…

An Improper Input Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remotely authenticated user with administrative access to achieve remote code execution.

endpoint_manager_mobile | CISA KEV Remote | Injection
May 07, 2026 May 07, 2026
May 07, 2026
May 07, 2026
9.8 CRITICAL
CVE-2026-5788 — Ivanti EPMM Improper Access Control Remote Code Execution

An Improper Access Control in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticated attacker to invoke arbitrary methods.

endpoint_manager_mobile | Remote | Authorization
May 07, 2026 May 07, 2026
May 07, 2026
May 07, 2026
9.1 CRITICAL
CVE-2026-5787 — Ivanti EPMM Certificate Validation Vulnerability (Certificate Impersonation)

An Improper Certificate Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticated attacker to impersonate registered Sentry hosts and obtain valid CA-…

endpoint_manager_mobile | Remote | Misconfiguration
May 07, 2026 May 07, 2026
May 07, 2026
May 07, 2026
8.8 HIGH
CVE-2026-5786 — Ivanti EPMM Improper Access Control Remote Authentication Bypass

An Improper Access Control vulnerability in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote authenticated attacker to gain administrative access.

endpoint_manager_mobile | Remote | Authorization
May 07, 2026 May 07, 2026
May 07, 2026
May 07, 2026
5.4 MEDIUM
CVE-2026-36388 — "PHPGurukal Hospital Management System XSS"

A Cross-Site Scripting (XSS) vulnerability was found in PHPGurukal Hospital Management System v4.0 in the /hospital/hms/edit-profile.php page. This flaw allows an authenticated attacker (patient) to …

Remote | Cross-Site Scripting
May 07, 2026 May 07, 2026
May 07, 2026
May 07, 2026
6.5 MEDIUM
CVE-2026-36387 — Codeastro Membership Management System Remote File Upload RCE

A Remote Code Execution vulnerability was found in CODEASTRO Membership Management System v1.0 in /add_members.php. This vulnerability affects the file upload functionality, where improper file sanit…

Remote | Injection
May 07, 2026 May 07, 2026
May 07, 2026
May 07, 2026
5.4 MEDIUM
CVE-2026-36341 — Webkul Krayin CRM Cross-Site Scripting (XSS)

Cross-Site Scripting (XSS) vulnerability exists in Webkul Krayin CRM v2.1.5. The application fails to sanitize user-supplied input in the comment field during Activity creation on the /admin/activiti…

Remote | Cross-Site Scripting
May 07, 2026 May 07, 2026
May 07, 2026
May 07, 2026
7.5 HIGH
CVE-2025-65122 — YouTube Regex Denial of Service Vulnerability

Regex Denial of Service in youtube-regex npm package through version 1.0.5.

Remote | Denial of Service
May 07, 2026 May 07, 2026
May 07, 2026
May 07, 2026
9.8 CRITICAL
CVE-2025-63704 — "Query-Parser-String NPM Prototype Pollution Vulnerability"

NPM package query-parser-string 1.0.0 is vulnerable to Prototype Pollution. The package does not properly sanitize user supplied query parameters and merges them to the newly created object.

Remote | Injection
May 07, 2026 May 08, 2026
May 07, 2026
May 08, 2026
9.8 CRITICAL
CVE-2025-63703 — "npm parse-ini Prototype Pollution"

npm package parse-ini v1.0.6 is vulnerable to Prototype Pollution in index.js().

Remote | Misconfiguration
May 07, 2026 May 08, 2026
May 07, 2026
May 08, 2026
6.8 MEDIUM
CVE-2025-4397 — Medtronic MyCareLink Patient Monitor Data Encryption Weakness

Medtronic MyCareLink Patient Monitor uses per-product credentials that are stored in a recoverable format. An attacker can use these credentials to modify encrypted drive data.

| Information Disclosure
May 07, 2026 May 07, 2026
May 07, 2026
May 07, 2026
6.8 MEDIUM
CVE-2025-4386 — Medtronic MyCareLink Patient Monitor Hardware Debug Port

Medtronic MyCareLink Patient Monitor has an internal serial interface, which allows an attacker with physical access to access a login prompt via a UART terminal.​

| Authentication
May 07, 2026 May 07, 2026
May 07, 2026
May 07, 2026
Showing 20 of 7172 Results