Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.5 MEDIUM
CVE-2026-31380 — Apache OFBiz: FreeMarker SSTI via Duplicate Parameter Sanitization Bypass

Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06…

ofbiz | Remote | Injection
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
6.1 MEDIUM
CVE-2026-31379 — Apache OFBiz: Path Traversal and File Upload Validation Bypass Leading to Arbitrary File …

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Improper Control of Generation of…

ofbiz | Remote | Cross-Site Scripting
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
6.5 MEDIUM
CVE-2026-31378 — Apache OFBiz: JSON Attribute Override and URL Allowlist Bypass Leads to Remote Code Execu…

Improper Input Validation vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue.

ofbiz | Remote | Injection
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
9.6 CRITICAL
CVE-2026-2611 — Improper Origin Validation in mlflow/mlflow

In MLflow version 3.9.0, the MLflow Assistant feature introduced improper origin validation in its /ajax-api endpoints. This vulnerability allows a remote attacker to exploit cross-origin requests fr…

mlflow | Remote | Misconfiguration
May 19, 2026 May 22, 2026
May 19, 2026
May 22, 2026
7.3 HIGH
CVE-2026-29226 — Apache OFBiz: Low-Privilege SSRF in Content Component

Server-Side Request Forgery (SSRF) vulnerability in Apache OFBiz via Content component operations. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.0…

ofbiz | Remote | Server-Side Request Forgery
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
6.5 MEDIUM
CVE-2026-29220 — Apache OFBiz: Low-Privilege LFI in Content Component

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to v…

ofbiz | Remote | Path Traversal
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
6.5 MEDIUM
CVE-2026-29207 — Apache OFBiz: Low-Privilege SSTI Leading to RCE in the Content Component

Improper Neutralization of Special Elements Used in a Template Engine vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24…

ofbiz | Remote | Injection
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
6.3 MEDIUM
CVE-2026-44408 — Unauthorized access vulnerability in ZTE MU5250

There is an unauthorized access vulnerability in ZTE MU5250. Due to improper permission control of the Web interface, an unauthorized attacker can  modify configuration through the interface.

mu5250_firmware | Authentication
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
5.4 MEDIUM
CVE-2026-8922 — Org.keycloak/keycloak-services: keycloak: org.keycloak.protocol.oidc: security flaw in or…

A flaw was found in Keycloak. When both realm-level and client-level `notBefore` revocation policies are configured, Keycloak's OpenID Connect (OIDC) Introspection feature fails to properly honor the…

build_of_keycloak | Remote | Authorization
May 19, 2026 Jun 03, 2026
May 19, 2026
Jun 03, 2026
9.8 CRITICAL
CVE-2026-4885 — Piotnet Addons for Elementor Pro <= 7.1.70 - Unauthenticated Arbitrary File Upload via Fo…

The Piotnet Addons for Elementor Pro plugin for WordPress is vulnerable to arbitrary file upload due to missing file type validation in the 'pafe_ajax_form_builder' function in all versions up to, an…

Remote | Misconfiguration
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
7.5 HIGH
CVE-2026-47317 — Samsung Escargot Uncontrolled Recursion Memory Allocation Vulnerability

Uncontrolled Recursion vulnerability in Samsung Open Source Escargot allows Excessive Allocation. This issue affects Escargot: 590345cc6258317c5da850d846ce6baaf2afc2d3.

escargot | Remote | Denial of Service
May 19, 2026 Jun 02, 2026
May 19, 2026
Jun 02, 2026
7.5 HIGH
CVE-2026-47316 — Samsung Escargot Exceptional Condition Vulnerability

Improper Check or Handling of Exceptional Conditions vulnerability in Samsung Open Source Escargot allows Input Data Manipulation. This issue affects Escargot: 590345cc6258317c5da850d846ce6baaf2afc2…

escargot | Remote | Misconfiguration
May 19, 2026 Jun 02, 2026
May 19, 2026
Jun 02, 2026
7.5 HIGH
CVE-2026-47315 — Samsung Open Source Escargot Unvalidated Input Condition

Improper Check for Unusual or Exceptional Conditions vulnerability in Samsung Open Source Escargot allows Input Data Manipulation. This issue affects Escargot: 590345cc6258317c5da850d846ce6baaf2afc2…

escargot | Remote | Denial of Service
May 19, 2026 Jun 02, 2026
May 19, 2026
Jun 02, 2026
9.8 CRITICAL
CVE-2026-47314 — Samsung Escargot OOB Write Buffer Overflow

Out-of-bounds write vulnerability in Samsung Open Source Escargot allows Overflow Buffers. This issue affects Escargot: 590345cc6258317c5da850d846ce6baaf2afc2d3.

escargot | Remote | Memory Corruption
May 19, 2026 Jun 02, 2026
May 19, 2026
Jun 02, 2026
7.5 HIGH
CVE-2026-47313 — Samsung Open Source Escargot Excessive Allocation Buffer Overflow

Memory allocation with excessive size value vulnerability in Samsung Open Source Escargot allows Excessive Allocation. This issue affects Escargot: 590345cc6258317c5da850d846ce6baaf2afc2d3.

escargot | Remote | Memory Corruption
May 19, 2026 Jun 02, 2026
May 19, 2026
Jun 02, 2026
7.5 HIGH
CVE-2026-47312 — Samsung Escargot Buffer Manipulation Vulnerability

Release of invalid pointer or reference vulnerability in Samsung Open Source Escargot allows Buffer Manipulation. This issue affects Escargot: 590345cc6258317c5da850d846ce6baaf2afc2d3.

escargot | Remote | Memory Corruption
May 19, 2026 Jun 02, 2026
May 19, 2026
Jun 02, 2026
4.3 MEDIUM
CVE-2026-8830 — Keycloak: org.keycloak/keycloak-services: keycloak: policy bypass during webauthn credent…

A flaw was found in Keycloak. An authenticated user can bypass configured WebAuthn policies during credential registration by manipulating client-side JavaScript. This occurs because the server-side …

build_of_keycloak | Remote | Authentication
May 19, 2026 Jun 02, 2026
May 19, 2026
Jun 02, 2026
5.5 MEDIUM
CVE-2026-8814 — ExifReader PNG zTXt Data Amplification Vulnerability

Versions of the package exifreader before 4.39.0 are vulnerable to Improper Handling of Highly Compressed Data (Data Amplification) due to decompressing PNG zTXt metadata without enforcing a built-in…

Remote | Denial of Service
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
7.7 HIGH
CVE-2026-8813 — Apache ExifReader ICC mluc Tag Buffer Overflow Vulnerability

This affects versions of the package exifreader before 4.39.0. A crafted image containing an ICC mluc tag can set an attacker-controlled record count together with a zero record size. During parsing,…

Remote | Denial of Service
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
9.8 CRITICAL
CVE-2026-47311 — Samsung Open Source Escargot Heap Buffer Overflow

Heap-based buffer overflow vulnerability in Samsung Open Source Escargot allows Overflow Buffers. This issue affects Escargot: 590345cc6258317c5da850d846ce6baaf2afc2d3.

escargot | Remote | Memory Corruption
May 19, 2026 Jun 02, 2026
May 19, 2026
Jun 02, 2026
Showing 20 of 7020 Results