Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.1 MEDIUM
CVE-2026-42338 — ip-address: XSS in Address6 HTML-emitting methods

ip-address is a library for parsing and manipulating IPv4 and IPv6 addresses in JavaScript. Prior to 10.1.1, Address6.group() and Address6.link() do not HTML-escape attacker-controlled content before…

ip-address | Remote | Cross-Site Scripting
May 12, 2026 May 19, 2026
May 12, 2026
May 19, 2026
7.8 HIGH
CVE-2026-42191 — OpenTelemetry.Exporter.OpenTelemetryProtocol: Disk retry default temp path enables local …

OpenTelemetry.Exporter.OpenTelemetryProtocol is the OTLP (OpenTelemetry Protocol) exporter implementation. From 1.8.0 to 1.15.2, the OTLP disk retry feature in OpenTelemetry.Exporter.OpenTelemetryPro…

May 12, 2026 May 26, 2026
May 12, 2026
May 26, 2026
7.8 HIGH
CVE-2026-34690 — After Effects | Stack-based Buffer Overflow (CWE-121)

After Effects versions 26.0, 25.6.4 and earlier are affected by a Stack-based Buffer Overflow vulnerability that could result in arbitrary code execution in the context of the current user. Exploitat…

macos windows after_effects | Memory Corruption
May 12, 2026 May 13, 2026
May 12, 2026
May 13, 2026
6.2 MEDIUM
CVE-2026-34688 — CAI Content Credentials | Improper Input Validation (CWE-20)

CAI Content Credentials versions 0.78.2, 0.7.0 and earlier are affected by an Improper Input Validation vulnerability that could result in an application denial-of-service. An attacker could exploit …

c2pa c2pa-web | Denial of Service
May 12, 2026 May 15, 2026
May 12, 2026
May 15, 2026
8.7 HIGH
CVE-2026-34686 — Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)

Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a low-pr…

commerce magento commerce_b2b | Remote | Cross-Site Scripting
May 12, 2026 May 13, 2026
May 12, 2026
May 13, 2026
3.4 LOW
CVE-2026-34685 — Adobe Commerce | Improper Input Validation (CWE-20)

Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier [NEEDS REVIEW: impact mismatch — ticket says 'Arbitrary file system write', CIA triad derives 'Sec…

commerce magento commerce_b2b | Remote | Authorization
May 12, 2026 May 20, 2026
May 12, 2026
May 20, 2026
6.2 MEDIUM
CVE-2026-34680 — CAI Content Credentials | Integer Overflow or Wraparound (CWE-190)

CAI Content Credentials versions 0.78.2, 0.7.0 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in an application denial-of-service. An attacker could exp…

c2pa c2pa-web | Denial of Service
May 12, 2026 May 15, 2026
May 12, 2026
May 15, 2026
6.2 MEDIUM
CVE-2026-34679 — CAI Content Credentials | Improper Input Validation (CWE-20)

CAI Content Credentials versions 0.78.2, 0.7.0 and earlier are affected by an Improper Input Validation vulnerability that could result in an application denial-of-service. An attacker could exploit …

c2pa c2pa-web | Denial of Service
May 12, 2026 May 15, 2026
May 12, 2026
May 15, 2026
6.2 MEDIUM
CVE-2026-34678 — CAI Content Credentials | Uncontrolled Resource Consumption (CWE-400)

CAI Content Credentials versions 0.78.2, 0.7.0 and earlier are affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attacker could explo…

c2pa c2pa-web | Denial of Service
May 12, 2026 May 15, 2026
May 12, 2026
May 15, 2026
6.2 MEDIUM
CVE-2026-34677 — CAI Content Credentials | Uncontrolled Resource Consumption (CWE-400)

CAI Content Credentials versions 0.78.2, 0.7.0 and earlier are affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attacker could explo…

c2pa c2pa-web | Denial of Service
May 12, 2026 May 15, 2026
May 12, 2026
May 15, 2026
6.2 MEDIUM
CVE-2026-34673 — CAI Content Credentials | Uncontrolled Resource Consumption (CWE-400)

CAI Content Credentials versions 0.78.2, 0.7.0 and earlier are affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attacker could explo…

c2pa c2pa-web | Denial of Service
May 12, 2026 May 15, 2026
May 12, 2026
May 15, 2026
6.2 MEDIUM
CVE-2026-34672 — CAI Content Credentials | Integer Underflow (Wrap or Wraparound) (CWE-191)

CAI Content Credentials versions 0.78.2, 0.7.0 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an application denial-of-service. An attacker c…

c2pa c2pa-web | Denial of Service
May 12, 2026 May 15, 2026
May 12, 2026
May 15, 2026
6.2 MEDIUM
CVE-2026-34671 — CAI Content Credentials | Integer Overflow or Wraparound (CWE-190)

CAI Content Credentials versions 0.78.2, 0.7.0 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in an application denial-of-service. An attacker could exp…

c2pa c2pa-web | Denial of Service
May 12, 2026 May 15, 2026
May 12, 2026
May 15, 2026
6.2 MEDIUM
CVE-2026-34670 — CAI Content Credentials | Improper Input Validation (CWE-20)

CAI Content Credentials versions 0.78.2, 0.7.0 and earlier are affected by an Improper Input Validation vulnerability that could result in an application denial-of-service. An attacker could exploit …

c2pa c2pa-web | Denial of Service
May 12, 2026 May 15, 2026
May 12, 2026
May 15, 2026
6.2 MEDIUM
CVE-2026-34669 — CAI Content Credentials | Improper Input Validation (CWE-20)

CAI Content Credentials versions 0.78.2, 0.7.0 and earlier are affected by an Improper Input Validation vulnerability that could result in an application denial-of-service. An attacker could exploit …

c2pa c2pa-web | Denial of Service
May 12, 2026 May 15, 2026
May 12, 2026
May 15, 2026
6.2 MEDIUM
CVE-2026-34668 — CAI Content Credentials | Improper Input Validation (CWE-20)

CAI Content Credentials versions 0.78.2, 0.7.0 and earlier are affected by an Improper Input Validation vulnerability that could result in an application denial-of-service. An attacker could exploit …

c2pa c2pa-web | Denial of Service
May 12, 2026 May 15, 2026
May 12, 2026
May 15, 2026
6.2 MEDIUM
CVE-2026-34667 — CAI Content Credentials | Integer Underflow (Wrap or Wraparound) (CWE-191)

CAI Content Credentials versions 0.78.2, 0.7.0 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an application denial-of-service. An attacker c…

c2pa c2pa-web | Denial of Service
May 12, 2026 May 15, 2026
May 12, 2026
May 15, 2026
6.2 MEDIUM
CVE-2026-34666 — CAI Content Credentials | Improper Input Validation (CWE-20)

CAI Content Credentials versions 0.78.2, 0.7.0 and earlier are affected by an Improper Input Validation vulnerability that could result in an application denial-of-service. An attacker could exploit …

c2pa c2pa-web | Denial of Service
May 12, 2026 May 15, 2026
May 12, 2026
May 15, 2026
7.5 HIGH
CVE-2026-34665 — CAI Content Credentials | Uncontrolled Resource Consumption (CWE-400)

CAI Content Credentials versions 0.78.2, 0.7.0 and earlier are affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attacker could explo…

c2pa c2pa-web | Remote | Denial of Service
May 12, 2026 May 15, 2026
May 12, 2026
May 15, 2026
4.8 MEDIUM
CVE-2026-34658 — Adobe Commerce | Cross-site Scripting (Stored XSS) (CWE-79)

Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by a stored Cross-Site Scripting (XSS) vulnerability that could be abused by a high-p…

commerce magento commerce_b2b | Remote | Cross-Site Scripting
May 12, 2026 May 20, 2026
May 12, 2026
May 20, 2026
Showing 20 of 7242 Results