Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.4 HIGH
CVE-2026-9255 — Tool Execution Without Authorization via Piped Stdin in Kiro CLI

Missing input source validation in the tool authorization prompt in Kiro CLI before 1.28.0 allows a local attacker to execute arbitrary tools, including shell commands, without user approval by craft…

kiro_cli kiro_cli | Authorization
May 22, 2026 Jun 04, 2026
May 22, 2026
Jun 04, 2026
5.9 MEDIUM
CVE-2026-42626 — HP ENVY 5000 series Printers TCP Connection Overflow

HP ENVY 5000 series printers VERBASPP1N003.2237A.00 do not properly manage concurrent TCP connections to port 9100 (JetDirect/RAW printing). An unauthenticated remote attacker on the same network can…

| Denial of Service
May 22, 2026 May 22, 2026
May 22, 2026
May 22, 2026
7.3 HIGH
CVE-2026-37470 — ClipBucket Remote Code Execution Vulnerability

An issue in ClipBucket v5 v.5.5.2 allows an attacker to execute arbitrary code via the Authentication interface, login page endpoint and HTTP response security headers components

Remote | Authentication
May 22, 2026 May 22, 2026
May 22, 2026
May 22, 2026
7.3 HIGH
CVE-2026-36228 — Easy Chat Server Buffer Overflow Vulnerability

Buffer Overflow vulnerability in Easy Chat Server 3.1 allows a remote attacker to obtain sensitive information and execute arbitrary code via the chat message functionality

Remote | Memory Corruption
May 22, 2026 May 22, 2026
May 22, 2026
May 22, 2026
6.5 MEDIUM
CVE-2026-36227 — Easy Chat Server Directory Traversal Vulnerability

Directory Traversal vulnerability in Easy Chat Server 3.1 allows a remote attacker to obtain sensitive information and execute arbitrary code via the UserName parameter

Remote | Path Traversal
May 22, 2026 May 22, 2026
May 22, 2026
May 22, 2026
6.1 MEDIUM
CVE-2026-36226 — Advantech WebAccess/SCADA Cross Site Scripting

Cross Site Scripting vulnerability in Advantech WebAccess/SCADA 8.0-2015.08.16 allows a remote attacker to obtain sensitive information via the decryption field in the Create New Project User compone…

Remote | Cross-Site Scripting
May 22, 2026 May 22, 2026
May 22, 2026
May 22, 2026
7.6 HIGH
CVE-2026-34207 — TypeBot: SSRF Protection Bypass via DNS-Resolved Hostnames in Webhook / HTTP Request Vali…

TypeBot is a chatbot builder tool. In versions prior to 3.16.0, SSRF protection for Webhook / HTTP Request blocks validates only the URL string, blocked hostname literals, and literal IP formats. It …

typebot | Remote | Server-Side Request Forgery
May 22, 2026 May 22, 2026
May 22, 2026
May 22, 2026
10.0 CRITICAL
CVE-2026-33712 — TypeBot: Unauthenticated SSRF via isolated-vm fetch in preview chat endpoint bypasses SSR…

Typebot is a chatbot builder tool. In versions 3.15.2 and prior, the preview chat endpoint (POST /api/v1/typebots/{typebotId}/preview/startChat) allows unauthenticated users to achieve Server-Side Re…

typebot | Remote | Server-Side Request Forgery
May 22, 2026 May 22, 2026
May 22, 2026
May 22, 2026
9.8 CRITICAL
CVE-2026-32253 — Sunshine: Authentication bypass via improper client certificate validation

Sunshine is a self-hosted game stream host for Moonlight. In versions prior to 2026.516.143833, the client-certificate authentication can be bypassed because of how OpenSSL verification results are h…

sunshine | Remote | Authentication
May 22, 2026 May 26, 2026
May 22, 2026
May 26, 2026
5.4 MEDIUM
CVE-2026-28735 — GitHub OAuth Scope Validation

Mattermost versions 11.6.x <= 11.6.0, 11.5.x <= 11.5.3, 11.4.x <= 11.4.4, 10.11.x <= 10.11.14 fail to validate the OAuth token scope on the callback which allows an authenticated Mattermost user to g…

mattermost_server legal_hold | Remote | Authorization
May 22, 2026 May 22, 2026
May 22, 2026
May 22, 2026
8.7 HIGH
CVE-2026-28445 — Typebot: Stored XSS via Rating Block Custom Icon Bypasses isUnsafe Sandbox in Builder Pre…

Typebot is a chatbot builder tool. In versions 3.15.2 and prior, the RatingButton component in the embed package renders the user-controlled customIcon.svg field directly via Solid's innerHTML direct…

typebot | Remote | Cross-Site Scripting
May 22, 2026 May 22, 2026
May 22, 2026
May 22, 2026
6.5 MEDIUM
CVE-2026-28444 — Typebot: IDOR in Result Logs Endpoint Allows Cross-Workspace Data Disclosure

Typebot is a chatbot builder tool. In versions 3.15.2 and prior, the getResultLogs API endpoint authorizes the caller against the provided typebotId but fetches logs solely by resultId without verify…

typebot | Remote | Authorization
May 22, 2026 May 22, 2026
May 22, 2026
May 22, 2026
5.4 MEDIUM
CVE-2026-9251 — Devolutions Server Missing Authorization Vulnerability

Missing authorization in the entry status management feature in Devolutions Server allows a non-administrator authenticated user to bypass the administrator-enforced Pending Approval flow and gain ac…

devolutions_server | Remote | Authorization
May 22, 2026 May 22, 2026
May 22, 2026
May 22, 2026
3.1 LOW
CVE-2026-9249 — Devolutions Server Unverified Password Change Vulnerability

Unverified password change in Devolutions Server allows an attacker to change a user's password without providing the previous one via a crafted password change request. This issue affects : * D…

devolutions_server | Remote | Authentication
May 22, 2026 May 22, 2026
May 22, 2026
May 22, 2026
2.6 LOW
CVE-2026-9248 — Devolutions Server Authorization Bypass Vulnerability

Authorization bypass in the entry duplication feature in Devolutions Server allows an authenticated user with write access to any vault to copy documentation and attachments from an entry in a vault …

devolutions_server | Remote | Authorization
May 22, 2026 May 22, 2026
May 22, 2026
May 22, 2026
2.4 LOW
CVE-2026-9247 — Devolutions Server Insufficient Logging (Information Disclosure)

Insufficient logging in the entry export feature in Devolutions Server allows an authenticated user with export permissions to export a sealed entry without triggering the unseal notification to admi…

devolutions_server | Remote | Information Disclosure
May 22, 2026 May 22, 2026
May 22, 2026
May 22, 2026
4.3 MEDIUM
CVE-2026-9246 — Devolutions Server Improper Access Control

Improper access control in the entry documentation and attachment features in Devolutions Server allows an authenticated user with vault read access to retrieve the documentation and attachments of s…

devolutions_server | Remote | Authorization
May 22, 2026 May 22, 2026
May 22, 2026
May 22, 2026
5.0 MEDIUM
CVE-2026-9245 — Devolutions Server Open Redirect Vulnerability

Improper input validation in the external authentication provider flow in Devolutions Server allows an unauthenticated remote attacker to redirect victims to an attacker-controlled domain via a craft…

devolutions_server | Remote | Server-Side Request Forgery
May 22, 2026 May 22, 2026
May 22, 2026
May 22, 2026
4.3 MEDIUM
CVE-2026-9224 — Devolutions Server Unauthenticated Active Directory User Profile Update

Missing authorization in the user profile update feature in Devolutions Server allows an authenticated Active Directory user to modify their own profile attributes via a crafted API request. This is…

devolutions_server | Remote | Authorization
May 22, 2026 May 22, 2026
May 22, 2026
May 22, 2026
4.3 MEDIUM
CVE-2026-9223 — Devolutions Server Authentication Bypass

Missing authorization in the vault import feature in Devolutions Server  2026.1.16.0 and earlier allows a low-privileged authenticated user to create new vaults via a crafted import request.

devolutions_server | Remote | Authorization
May 22, 2026 May 22, 2026
May 22, 2026
May 22, 2026
Showing 20 of 6835 Results