Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.7 HIGH
CVE-2026-41505 — RELATE: Predictable Token Generation in auth.py and exam.py

RELATE is a web-based courseware package. Prior to commit 2f68e16, RELATE is vulnerable to predictable token generation in auth.py's make_sign_in_key() function and exam.py's gen_ticket_code() functi…

relate | Remote | Authentication
May 07, 2026 May 07, 2026
May 07, 2026
May 07, 2026
8.3 HIGH
CVE-2026-41422 — Daptin vulnerable to SQL injection via unvalidated goqu.L() calls in aggregate API

Daptin is a GraphQL/JSON-API headless CMS. Prior to version 0.11.4, the /aggregate/:typename endpoint accepted column and group query parameters that were passed verbatim to goqu.L() — a raw SQL lite…

Remote | Injection
May 07, 2026 May 07, 2026
May 07, 2026
May 07, 2026
9.8 CRITICAL
CVE-2026-36458 — ChestnutCMS SQL Injection

ChestnutCMS v1.5.10 has a SQL injection vulnerability. The content parameter of the cms_content tag can be manipulated in the admin backend and injected into a SQL query when the template is rendered.

Remote | Injection
May 07, 2026 May 08, 2026
May 07, 2026
May 08, 2026
6.9 MEDIUM
CVE-2026-32686 — Unbounded exponent in decimal enables unauthenticated DoS

Uncontrolled Resource Consumption vulnerability in ericmj decimal allows unauthenticated remote Denial of Service. The decimal library does not bound the exponent on parsed input. Storing a decimal …

decimal | Denial of Service
May 07, 2026 May 08, 2026
May 07, 2026
May 08, 2026
6.1 MEDIUM
CVE-2025-67202 — Sidekiq-cron XSS Vulnerability

Sidekiq-cron thru 2.3.1, an open-source scheduling add-on for Sidekiq, is vulnerable to a cross-site scripting (xss) vulnerability via crafted URL being rended from cron.erb.

Remote | Cross-Site Scripting
May 07, 2026 May 08, 2026
May 07, 2026
May 08, 2026
9.8 CRITICAL
CVE-2025-63706 — "Next NPM Package Command Injection Vulnerability"

NPM package next-npm-version1.0.1 is vulnerable to Command injection.

Remote | Injection
May 07, 2026 May 08, 2026
May 07, 2026
May 08, 2026
8.8 HIGH
CVE-2025-63705 — Node-TS-OCR OS Command Injection

NPM package node-ts-ocr 1.0.15 is vulnerable to OS Command Injection via the invokeImageOcr function in src/index.js.

Remote | Injection
May 07, 2026 May 08, 2026
May 07, 2026
May 08, 2026
Showing 20 of 7187 Results