Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.4 CRITICAL
CVE-2026-44315 — free5GC: NEF 3gpp-pfd-management API is unauthenticated; forged bearer tokens can create,…

free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, free5GC's NEF mounts the 3gpp-pfd-management API without inbound OAuth2/bearer-token authorization. A network attacker…

free5gc | Remote | Authentication
May 27, 2026 May 28, 2026
May 27, 2026
May 28, 2026
8.1 HIGH
CVE-2026-42790 — nameConstraints DNS bypass via subject CommonName fallback in public_key hostname verific…

Improper Certificate Validation vulnerability in Erlang OTP public_key (pubkey_cert and public_key modules) allows a DNS nameConstraints bypass via subject CommonName fallback in TLS hostname verific…

erlang\/otp | Remote
May 27, 2026 Jun 02, 2026
May 27, 2026
Jun 02, 2026
7.7 HIGH
CVE-2026-42459 — free5GC: Improper Input Validation and Generation of Error Message Containing Sensitive I…

free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, the free5GC UDM component fails to validate the supi path parameter in six GET handlers of the nudm-sdm (Subscriber Da…

free5gc | Remote | Injection
May 27, 2026 May 28, 2026
May 27, 2026
May 28, 2026
8.2 HIGH
CVE-2026-42083 — free5GC: PCF Npcf_SMPolicyControl missing authentication middleware allows unauthenticate…

free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, PCF Npcf_SMPolicyControl missing authentication middleware allows unauthenticated access to SM policy handlers and dis…

free5gc | Remote | Authentication
May 27, 2026 May 28, 2026
May 27, 2026
May 28, 2026
5.4 MEDIUM
CVE-2026-42082 — free5GC: Missing Concurrent NAS SMC Validation During NGAP Handover

free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, the AMF in Free5GC does not enforce the concurrent security procedure rules defined in 3GPP TS 33.501 §6.9.5.1. The AM…

free5gc | Remote | Authentication
May 27, 2026 May 28, 2026
May 27, 2026
May 28, 2026
7.1 HIGH
CVE-2026-42081 — free5GC: UE Security Capability bypass on NGAP PathSwitchRequest

free5GC is an open-source implementation of the 5G core network. Prior to 4.2.2, the AMF in Free5GC does not verify the UE Security Capabilities received in NGAP PathSwitchRequest messages against it…

free5gc | Denial of Service
May 27, 2026 May 29, 2026
May 27, 2026
May 29, 2026
7.8 HIGH
CVE-2026-38945 — Raynet Rvia Command Injection Vulnerability

Command injection in Raynet rvia version 12.6 Update 8 and previous versions allows adversaries to execute arbitrary code via a crafted path that matches the improperly terminated search criteria of …

| Injection
May 27, 2026 Jun 01, 2026
May 27, 2026
Jun 01, 2026
5.4 MEDIUM
CVE-2026-38931 — Creators of Code SimplePHP Stored XSS

A stored cross-site scripting (XSS) vulnerability in the /admin/config-module.php component of creatorsofcode simplephp GitHub commit 5184cff (Latest as of 2026-02-27) via injecting a crafted payload.

Remote | Cross-Site Scripting
May 27, 2026 May 27, 2026
May 27, 2026
May 27, 2026
6.5 MEDIUM
CVE-2026-38930 — OpenRapid RapidCMS Authentication Bypass

OpenRapid RapidCMS v1.3.1 was discovered to contain an authentication bypass in the /template/default/menu.php component. This vulnerability is exploited via injecting a crafted SQL payload into the …

Remote | Authentication
May 27, 2026 May 28, 2026
May 27, 2026
May 28, 2026
4.3 MEDIUM
CVE-2025-70116 — GPAC MP4Box NULL Pointer Dereference

A NULL pointer dereference in GPAC MP4Box: when parsing certain truncated MP4 files, an unknown/invalid stsd entry can result in missing descriptor fields (e.g., codec/mime/profile strings). gf_media…

Remote | Memory Corruption
May 27, 2026 Jun 01, 2026
May 27, 2026
Jun 01, 2026
5.5 MEDIUM
CVE-2025-68712 — SpSoft AppLock Fingerprint and PIN Bypass Vulnerability

SpSoft AppLock (com.sp.protector.free) 7.9.40 for Android allows a local attacker with physical access to bypass fingerprint or PIN authentication. Although the app integrates Android's biometric mec…

| Authentication
May 27, 2026 May 28, 2026
May 27, 2026
May 28, 2026
4.3 MEDIUM
CVE-2022-41656 — WordPress Account Manager for WooCommerce plugin <= 2.1.2 - Broken Access Control vulnera…

Missing Authorization vulnerability in Bizswoop Account Manager for WooCommerce allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects Account Manager for WooCom…

Remote | Authorization
May 27, 2026 May 27, 2026
May 27, 2026
May 27, 2026
3.8 LOW
CVE-2026-9712 — Insecure direct object reference

When creating an export through the pretix API, API clients are returned an UUID value for their export job (a long, random string like 35742818-c375-4d15-839f-d49aecce94d6). Using this UUID, the A…

pretix | Remote | Authorization
May 27, 2026 May 27, 2026
May 27, 2026
May 27, 2026
4.3 MEDIUM
CVE-2026-9674 — Jenkins Multijob Plugin CSRF Vulnerability

A cross-site request forgery (CSRF) vulnerability in Jenkins Multijob Plugin 662.vd2e0001f6b_b_d and earlier allows attackers to resume failed Multijob builds.

multijob | Remote | Cross-Site Request Forgery
May 27, 2026 May 28, 2026
May 27, 2026
May 28, 2026
8.0 HIGH
CVE-2026-6957 — Path traversal in Mattermost Legal Hold plugin via unsanitized file name from federated p…

Mattermost Plugins versions <=1.1.5 fail to sanitize filenames received from federated peers before using them to construct export destination paths, which allows an administrator of a remote federat…

mattermost_server legal_hold | Remote | Path Traversal
May 27, 2026 Jun 02, 2026
May 27, 2026
Jun 02, 2026
9.4 CRITICAL
CVE-2026-49103 — Webmin File Name Injection Vulnerability

Webmin before 2.640 does not safely construct a filename for saving of an attachment within the mailboxes component. This occurs in mailboxes/detachall.cgi.

webmin | Remote | Path Traversal
May 27, 2026 May 27, 2026
May 27, 2026
May 27, 2026
6.1 MEDIUM
CVE-2026-49102 — Webmin SVG Attachment XSS

Webmin before 2.640 allows mailboxes/detach.cgi XSS via an SVG document attachment that is viewed in the mailboxes component, because image/svg+xml is used instead of a safe type (e.g., text/plain).

webmin | Remote | Cross-Site Scripting
May 27, 2026 May 27, 2026
May 27, 2026
May 27, 2026
4.7 MEDIUM
CVE-2026-49059 — WordPress Facebook for WooCommerce plugin <= 3.7.0 - Open Redirection vulnerability

URL Redirection to Untrusted Site ('Open Redirect') vulnerability in Facebook Facebook for WooCommerce allows Phishing. This issue affects Facebook for WooCommerce: from n/a through 3.7.0.

facebook_for_woocommerce | Remote | Misconfiguration
May 27, 2026 May 27, 2026
May 27, 2026
May 27, 2026
5.3 MEDIUM
CVE-2026-49053 — WordPress ElementsKit Elementor addons Lite plugin <= 3.9.6 - Broken Access Control vulne…

Missing Authorization vulnerability in Wpmet ElementsKit Elementor addons Lite allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects ElementsKit Elementor addon…

Remote | Authorization
May 27, 2026 May 27, 2026
May 27, 2026
May 27, 2026
4.3 MEDIUM
CVE-2026-49052 — WordPress ElementsKit Elementor addons Lite plugin <= 3.9.6 - Broken Access Control vulne…

Missing Authorization vulnerability in Wpmet ElementsKit Elementor addons Lite allows Exploiting Incorrectly Configured Access Control Security Levels. This issue affects ElementsKit Elementor addon…

Remote | Authorization
May 27, 2026 May 27, 2026
May 27, 2026
May 27, 2026
Showing 20 of 7016 Results