Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.8 CRITICAL
CVE-2026-31226 — "TinyZero HDFS File Operation Utilities Command Injection Vulnerability"

The TinyZero project thru commit 6652a63c57fa7e5ccde3fc9c598c7176ff15b839 (2025-58-24) contains a critical command injection vulnerability (CWE-78) in its HDFS file operation utilities. The vulnerabi…

Remote | Injection
May 12, 2026 May 19, 2026
May 12, 2026
May 19, 2026
8.8 HIGH
CVE-2026-31225 — Apache Superduper Remote Code Execution Vulnerability

The superduper project thru v0.10.0 contains a critical remote code execution vulnerability in its query parsing component. The _parse_op_part() function in query.py uses the unsafe eval() function t…

Remote | Injection
May 12, 2026 May 13, 2026
May 12, 2026
May 13, 2026
8.8 HIGH
CVE-2026-31224 — Snorkel Torch Insecure Deserialization Vulnerability

The snorkel library thru v0.10.0 contains an insecure deserialization vulnerability (CWE-502) in the MultitaskClassifier.load() method of the MultitaskClassifier class. The method loads model weight …

snorkel | Remote | Injection
May 12, 2026 May 13, 2026
May 12, 2026
May 13, 2026
8.8 HIGH
CVE-2026-31223 — Apache Snorkel Insecure Deserialization Vulnerability

The snorkel library thru v0.10.0 contains a critical insecure deserialization vulnerability (CWE-502) in the BaseLabeler.load() method of the BaseLabeler class. The method loads serialized labeler mo…

snorkel | Remote | Injection
May 12, 2026 May 15, 2026
May 12, 2026
May 15, 2026
8.8 HIGH
CVE-2026-31222 — Snorkel Torch Insecure Deserialization Vulnerability

The snorkel library thru v0.10.0 contains an insecure deserialization vulnerability (CWE-502) in the Trainer.load() method of the Trainer class. The method loads model checkpoint files using torch.lo…

snorkel | Remote | Injection
May 12, 2026 May 15, 2026
May 12, 2026
May 15, 2026
8.8 HIGH
CVE-2026-31221 — PyTorch-Lightning Insecure Deserialization Vulnerability

PyTorch-Lightning versions 2.6.0 and earlier contain an insecure deserialization vulnerability (CWE-502) in the checkpoint loading mechanism. The LightningModule.load_from_checkpoint() method, which …

pytorch_lightning | Remote | Injection
May 12, 2026 May 15, 2026
May 12, 2026
May 15, 2026
9.8 CRITICAL
CVE-2026-31220 — PySyft Syft Datasite/Server Remote Code Execution

PySyft (Syft Datasite/Server) versions 0.9.5 and earlier are vulnerable to remote code execution due to insufficient validation and sandboxing of user-submitted code. The system allows low-privileged…

Remote | Injection
May 12, 2026 May 15, 2026
May 12, 2026
May 15, 2026
8.8 HIGH
CVE-2026-31219 — Optimate - Insecure Deserialization Vulnerability

The _load_model() function in the neural_magic_training.py script of the optimate project in commit a6d302f912b481c94370811af6b11402f51d377f (2024-07-21) is vulnerable to insecure deserialization (CW…

Remote | Authentication
May 12, 2026 May 15, 2026
May 12, 2026
May 15, 2026
8.8 HIGH
CVE-2026-31218 — Optimate Pickle Deserialization Remote Code Execution

The _load_model() function in the neural_magic_training.py script of the optimate project in commit a6d302f912b481c94370811af6b11402f51d377f (2024-07-21) is vulnerable to insecure deserialization (CW…

Remote | Injection
May 12, 2026 May 15, 2026
May 12, 2026
May 15, 2026
9.8 CRITICAL
CVE-2026-31217 — Optimate Python Code Execution Vulnerability

The _load_model() function in the neural_magic_training.py script of the optimate project in commit a6d302f912b481c94370811af6b11402f51d377f (2024-07-21) allows arbitrary code execution. When a user …

optimate | Remote | Injection
May 12, 2026 May 26, 2026
May 12, 2026
May 26, 2026
9.1 CRITICAL
CVE-2026-31216 — Nexenta MinIO Unauthorized File Deletion Vulnerability

The nexent v1.7.5.2 backend service contains an unauthorized arbitrary storage file deletion vulnerability in its file management API. The DELETE /storage/{object_name:path} endpoint lacks authentica…

nexent | Remote | Authorization
May 12, 2026 May 26, 2026
May 12, 2026
May 26, 2026
9.1 CRITICAL
CVE-2026-31215 — "Nexent ElasticSearch Unauthenticated Arbitrary File Deletion Vulnerability"

The nexent v1.7.5.2 backend service contains an unauthorized arbitrary file deletion vulnerability in its ElasticSearch service interface. The DELETE /{index_name}/documents endpoint lacks proper aut…

nexent | Remote | Authorization
May 12, 2026 May 26, 2026
May 12, 2026
May 26, 2026
9.8 CRITICAL
CVE-2026-31214 — TensorFlow PyTorch Insecure Deserialization Vulnerability

The torch-checkpoint-shrink.py script in the ml-engineering project in commit 0099885db36a8f06556efe1faf552518852cb1e0 (2025-20-27) contains an insecure deserialization vulnerability (CWE-502). The s…

Remote | Injection
May 12, 2026 May 13, 2026
May 12, 2026
May 13, 2026
8.8 HIGH
CVE-2026-30810 — Server-Side Request Forgery in API Checker leads to Privilege Escalation

Server-Side Request Forgery vulnerability allows Privilege Escalation via API Checker extension. This issue affects Pandora FMS: from 777 through 800

pandora_fms | Remote | Server-Side Request Forgery
May 12, 2026 May 13, 2026
May 12, 2026
May 13, 2026
8.1 HIGH
CVE-2026-30808 — Session Fixation in Authentication leads to Session Hijacking

Session Fixation vulnerability allows Session Hijacking via crafted session ID. This issue affects Pandora FMS: from 777 through 800

pandora_fms | Remote | Authentication
May 12, 2026 May 13, 2026
May 12, 2026
May 13, 2026
8.8 HIGH
CVE-2026-30807 — Cross-Site Request Forgery on Extension Pages

Cross-Site Request Forgery vulnerability allows an attacker to perform unauthorized actions via crafted web page. This issue affects Pandora FMS: from 777 through 800

pandora_fms | Remote | Cross-Site Request Forgery
May 12, 2026 May 13, 2026
May 12, 2026
May 13, 2026
9.1 CRITICAL
CVE-2026-30805 — Insecure Default Initialization in API Authentication leads to Authentication Bypass

Insecure Default Initialization of Resource vulnerability allows Authentication Bypass via API access. This issue affects Pandora FMS: from 777 through 800

pandora_fms | Remote | Authentication
May 12, 2026 May 13, 2026
May 12, 2026
May 13, 2026
5.4 MEDIUM
CVE-2023-30059 — MK-Auth Insecure Direct Object Reference

An insecure direct object reference in MK-Auth 23.01K4.9 allows attackers to access and send support calls for other users via manipulation of the chamado parameter through a crafted GET request.

Remote | Authorization
May 12, 2026 May 13, 2026
May 12, 2026
May 13, 2026
8.0 HIGH
CVE-2023-27753 — MK-Auth PHP File Upload Remote Code Execution Vulnerability

An arbitrary file upload vulnerability in MK-Auth 23.01K4.9 allows attackers to execute arbitrary code via uploading a crafted PHP file.

Remote | Misconfiguration
May 12, 2026 May 13, 2026
May 12, 2026
May 13, 2026
9.8 CRITICAL
CVE-2026-8401 — Sandbox escape in the Profile Backup component

Sandbox escape in the Profile Backup component. This vulnerability was fixed in Firefox 150.0.3, Firefox ESR 115.36, Firefox ESR 140.11, and Thunderbird 140.11.

firefox thunderbird | Remote | Misconfiguration
May 12, 2026 May 19, 2026
May 12, 2026
May 19, 2026
Showing 20 of 7241 Results