Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.4 MEDIUM
CVE-2026-20210 — Cisco Catalyst SD-WAN Manager Privilege Escalation Vulnerability

A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker with read-only permissions to modify configurations and perform …

catalyst_sd-wan_manager | Remote | Authorization
May 14, 2026 May 14, 2026
May 14, 2026
May 14, 2026
5.4 MEDIUM
CVE-2026-20209 — Cisco Catalyst SD-WAN Manager Privilege Escalation Vulnerability

A vulnerability in the web UI of Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, could allow an authenticated, remote attacker with read-only permissions to elevate their privileges from low …

catalyst_sd-wan_manager | Remote | Authorization
May 14, 2026 May 14, 2026
May 14, 2026
May 14, 2026
10.0 CRITICAL
CVE-2026-20182 — Cisco Catalyst SD-WAN Controller Authentication Bypass Vulnerability - [Actively Exploite…

May 2026: This security advisory provides the details and fix information for a vulnerability that was discovered and fixed after the was disclosed in February 2026. This new advisory is for a new v…

catalyst_sd-wan_manager sd-wan_vsmart_controller | CISA KEV Remote | Authentication
May 14, 2026 May 15, 2026
May 14, 2026
May 15, 2026
2.6 LOW
CVE-2025-62317 — HCL AION is affected by a vulnerability where sensitive information may be included in UR…

HCL AION is affected by a vulnerability where sensitive information may be included in URL parameters. Passing sensitive data in URLs may expose it through browser history, logs, or intermediary syst…

aion | Information Disclosure
May 14, 2026 May 14, 2026
May 14, 2026
May 14, 2026
2.3 LOW
CVE-2025-62316 — HCL AION is affected by a vulnerability where certain security-related HTTP response head…

HCL AION is affected by a vulnerability where certain security-related HTTP response headers are not properly configured. Absence of these headers may reduce the effectiveness of browser-based securi…

aion | Misconfiguration
May 14, 2026 May 14, 2026
May 14, 2026
May 14, 2026
5.4 MEDIUM
CVE-2025-62313 — HCL AION is affected by a vulnerability where adequate protections against brute-force at…

HCL AION is affected by a vulnerability where adequate protections against brute-force attempts are not enforced. This may allow repeated authentication attempts, potentially leading to unauthorized …

aion | Authentication
May 14, 2026 May 14, 2026
May 14, 2026
May 14, 2026
3.0 LOW
CVE-2025-62312 — HCL AION is affected by a vulnerability where basic authorization tokens are used for aut…

HCL AION is affected by a vulnerability where basic authorization tokens are used for authentication. Use of basic authorization mechanisms may expose credentials to potential interception or misuse,…

aion | Authentication
May 14, 2026 May 14, 2026
May 14, 2026
May 14, 2026
4.3 MEDIUM
CVE-2025-62311 — HCL AION is affected by a vulnerability where backend service details may be transmitted …

HCL AION is affected by a vulnerability where backend service details may be transmitted over insecure HTTP channels. This may expose sensitive information to potential interception or unauthorized a…

aion | Information Disclosure
May 14, 2026 May 14, 2026
May 14, 2026
May 14, 2026
5.4 MEDIUM
CVE-2025-62310 — HCL AION is affected by a vulnerability where encryption is not enforced for certain data…

HCL AION is affected by a vulnerability where encryption is not enforced for certain data transmissions or operations. This may expose sensitive information to potential interception or unauthorized …

aion | Cryptography
May 14, 2026 May 14, 2026
May 14, 2026
May 14, 2026
2.6 LOW
CVE-2025-62309 — HCL AION is affected by a vulnerability where auto-complete functionality is enabled for …

HCL AION is affected by a vulnerability where auto-complete functionality is enabled for certain input fields. This may allow sensitive information to be stored in the browser, potentially leading to…

aion | Information Disclosure
May 14, 2026 May 14, 2026
May 14, 2026
May 14, 2026
5.1 MEDIUM
CVE-2025-62308 — HCL AION is affected by a vulnerability where sensitive backend infrastructure details ma…

HCL AION is affected by a vulnerability where sensitive backend infrastructure details may be exposed. Exposure of such information could reveal internal system architecture or configuration details,…

aion | Information Disclosure
May 14, 2026 May 14, 2026
May 14, 2026
May 14, 2026
5.1 MEDIUM
CVE-2025-62305 — HCL AION is affected by a vulnerability where certain operations may trigger out-of-band …

HCL AION is affected by a vulnerability where certain operations may trigger out-of-band interactions, potentially resulting in unintended disclosure of sensitive information. Such behaviour may allo…

aion | Information Disclosure
May 14, 2026 May 14, 2026
May 14, 2026
May 14, 2026
8.6 HIGH
CVE-2026-44504 — Aegra: Cross-user run injection in /threads/{thread_id}/runs (IDOR)

Aegra is a drop-in replacement for LangSmith Deployments. Prior to 0.9.7, with multiple authenticated users on a shared instance are vulnerable to a cross-tenant IDOR. Any authenticated attacker, giv…

Remote | Authorization
May 14, 2026 May 14, 2026
May 14, 2026
May 14, 2026
7.0 HIGH
CVE-2026-44503 — Kiota abstractions RedirectHandler leaks Cookie/Proxy-Authorization headers on cross-host…

The RedirectHandler middleware in microsoft/kiota-java (com.microsoft.kiota:microsoft-kiota-http-okHttp v1.9.0) and other Kiota libraries fails to strip sensitive HTTP headers when following 3xx redi…

Remote | Misconfiguration
May 14, 2026 May 14, 2026
May 14, 2026
May 14, 2026
7.1 HIGH
CVE-2026-44501 — DataHub OIDC REDIRECT_URL Cookie Deserialization Vulnerability

DataHub is an open-source metadata platform. Prior to 1.5.0.3, The DataHub frontend (datahub-frontend-react) deserializes attacker-controlled Java objects from the REDIRECT_URL HTTP cookie during the…

datahub | Remote | Injection
May 14, 2026 May 16, 2026
May 14, 2026
May 16, 2026
5.9 MEDIUM
CVE-2026-42597 — Gotenberg: Chromium URL conversion routes read arbitrary files under /tmp via file:// sch…

Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.32.0, the /forms/chromium/convert/url and /forms/chromium/screenshot/url routes accept url=file:///tmp/... from anonymous callers…

gotenberg | Remote | Path Traversal
May 14, 2026 May 18, 2026
May 14, 2026
May 18, 2026
9.4 CRITICAL
CVE-2026-42596 — Gotenberg: Unauthenticated SSRF via default deny-list bypass in downloadFrom and webhook

Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.31.0, the default deny-lists used by Gotenberg's downloadFrom feature and webhook feature are bypassable. Because the filter is r…

gotenberg | Remote | Server-Side Request Forgery
May 14, 2026 May 18, 2026
May 14, 2026
May 18, 2026
8.6 HIGH
CVE-2026-42595 — Gotenberg: Server-Side Request Forgery via Chromium URL Endpoint with Redirect-Based Deny…

Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.32.0, Gotenberg's Chromium URL-to-PDF endpoint (/forms/chromium/convert/url) has no default protection against HTTP/HTTPS-based S…

gotenberg | Remote | Server-Side Request Forgery
May 14, 2026 May 18, 2026
May 14, 2026
May 18, 2026
7.5 HIGH
CVE-2026-42594 — Gotenberg: Unauthenticated denial of service via echo.Context pool reuse in webhook async…

Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.32.0, the webhook middleware spawns a goroutine that holds a reference to the request's echo.Context after the synchronous handle…

gotenberg | Remote | Memory Corruption
May 14, 2026 May 18, 2026
May 14, 2026
May 18, 2026
5.3 MEDIUM
CVE-2026-42593 — Gotenberg: Arbitrary PDF read via stampExpression and watermarkExpression in merge, split…

Gotenberg is a Docker-powered stateless API for PDF files. Prior to 8.32.0, pdfengines/merge, pdfengines/split, libreoffice/convert, chromium/convert/url, chromium/convert/html, and chromium/convert/…

gotenberg | Remote | Path Traversal
May 14, 2026 May 18, 2026
May 14, 2026
May 18, 2026
Showing 20 of 7172 Results