Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.6 MEDIUM
CVE-2026-48916 — Jenkins LDAP Plugin LDAP Referral Vulnerability

Jenkins LDAP Plugin 807.v7d7de30930cf and earlier follows LDAP referrals.

lightweight_directory_access_protocol ldap | Remote | Misconfiguration
May 27, 2026 Jun 02, 2026
May 27, 2026
Jun 02, 2026
7.6 HIGH
CVE-2026-48545 — Gradio < 6.15.0 Cookie Injection via Shared Proxy Client

Gradio before version 6.15.0 contains a cookie injection vulnerability that allows remote attackers to perform cross-Space session fixation by exploiting a shared module-level HTTP client used across…

gradio | Remote | Misconfiguration
May 27, 2026 Jun 02, 2026
May 27, 2026
Jun 02, 2026
8.7 HIGH
CVE-2026-48544 — Taipy 4.1.1 Path Traversal via ElementLibrary.get_resource()

Taipy 4.1.1, fixed in commit 129fd40, contains a path traversal vulnerability in the ElementLibrary.get_resource() method in taipy/gui/extension/library.py that allows unauthenticated attackers to es…

taipy | Remote | Path Traversal
May 27, 2026 May 28, 2026
May 27, 2026
May 28, 2026
6.1 MEDIUM
CVE-2026-47119 — Agent Zero < 1.15 Stored XSS via image_get API Endpoint

Agent Zero before version 1.15 contains a stored cross-site scripting vulnerability that allows attackers to execute arbitrary JavaScript in the application origin by serving SVG files through the im…

Remote | Cross-Site Scripting
May 27, 2026 May 27, 2026
May 27, 2026
May 27, 2026
7.1 HIGH
CVE-2026-47118 — Agent Zero < 1.15 Path Traversal File Read via image_get API

Agent Zero before version 1.15 contains a path traversal vulnerability that allows unauthenticated attackers to read arbitrary files by supplying crafted paths to the image file serving endpoint, whi…

Remote | Path Traversal
May 27, 2026 May 27, 2026
May 27, 2026
May 27, 2026
5.4 MEDIUM
CVE-2026-45571 — go-git: Crafted repositories may modify main and submodule .git directories

go-git is an extensible git implementation library written in pure Go. Prior to 5.19.1 and 6.0.0-alpha.4, a path validation issue in go-git could allow crafted repository data to affect files outside…

go-git | Remote | Path Traversal
May 27, 2026 Jun 04, 2026
May 27, 2026
Jun 04, 2026
9.6 CRITICAL
CVE-2026-45570 — go-git: Improper single-quote escaping in go-git SSH transport

go-git is an extensible git implementation library written in pure Go. Prior to 5.19.1 and 6.0.0-alpha.4, go-git's SSH transport constructs the remote exec command by wrapping the repository path in …

go-git | Remote | Injection
May 27, 2026 Jun 04, 2026
May 27, 2026
Jun 04, 2026
7.5 HIGH
CVE-2026-45022 — go-git: Improper parsing of specially crafted objects may lead to inconsistent interpreta…

go-git is an extensible git implementation library written in pure Go. Prior to 5.19.0 and 6.0.0-alpha.3, go-git may parse malformed Git objects in a way that differs from upstream Git. When commit o…

go-git | Remote | Misconfiguration
May 27, 2026 Jun 04, 2026
May 27, 2026
Jun 04, 2026
8.8 HIGH
CVE-2026-44988 — LibVNCClient Tight Gradient decoding allows malicious server-triggered heap/stack OOB wri…

LibVNCClient is a library for easy implementation of a VNC client. In 0.9.15 and earlier, LibVNCClient's Tight encoding decoder uses fixed-size 2048-pixel scratch buffers for the Gradient filter, but…

libvncserver | Remote | Memory Corruption
May 27, 2026 Jun 01, 2026
May 27, 2026
Jun 01, 2026
5.0 MEDIUM
CVE-2026-44972 — GuardDog: Unsanitized human-readable scan output allows terminal escape injection from ma…

GuardDog is a CLI tool to identify malicious PyPI packages. From 2.6.0 to 2.9.0, GuardDog includes attacker-controlled filenames, file locations, messages, and code snippets in its default human-read…

guarddog | Information Disclosure
May 27, 2026 May 29, 2026
May 27, 2026
May 29, 2026
8.2 HIGH
CVE-2026-44971 — GuardDog: Blind GitHub URL rewrite in remote project scanning causes SSRF and `GH_TOKEN` …

GuardDog is a CLI tool to identify malicious PyPI packages. From 1.0.0 to 2.9.0, the programmatic remote project scanning path rewrites attacker-controlled repository URLs using a blind string replac…

guarddog | Remote | Server-Side Request Forgery
May 27, 2026 Jun 01, 2026
May 27, 2026
Jun 01, 2026
7.5 HIGH
CVE-2026-44902 — opentelemetry-js: Prometheus exporter process crash via malformed HTTP request

opentelemetry-js is the OpenTelemetry JavaScript Client. Prior to 0.217.0, a single malformed HTTP request crashes any Node.js process running the OpenTelemetry JS Prometheus exporter. The metrics en…

Remote | Denial of Service
May 27, 2026 May 29, 2026
May 27, 2026
May 29, 2026
5.6 MEDIUM
CVE-2026-44839 — RabbitMQ: Unsanitized vhost names allow for XSS in management UI

RabbitMQ is a messaging and streaming broker. From 3.7.0 to before 4.1.2 and 4.0.13, This vulnerability is fixed in 4.1.2 and 4.0.13.

rabbitmq_server | Remote
May 27, 2026 Jun 04, 2026
May 27, 2026
Jun 04, 2026
8.1 HIGH
CVE-2026-44838 — RabbitMQ MQTT Topic Permission Authorization Bypass

RabbitMQ is a messaging and streaming broker. From 4.2.0 to before 4.2.4, RabbitMQ's MQTT plugin allows for topic-level authorization using regular expressions with variable substitution. Administrat…

rabbitmq_server | Remote | Authorization
May 27, 2026 Jun 04, 2026
May 27, 2026
Jun 04, 2026
8.7 HIGH
CVE-2026-44830 — Empty API_TOKEN disables authentication on network-reachable HTTP/SSE transport

Nocturne Memory is a lightweight, rollbackable, and visual Long-Term Memory Server for MCP Agents. Prior to 2.4.1, when API_TOKEN is unset or empty, the BearerTokenAuthMiddleware bypasses authenticat…

| Authentication
May 27, 2026 Jun 01, 2026
May 27, 2026
Jun 01, 2026
7.1 HIGH
CVE-2026-42280 — Improper Permission Checking in Auth.js SDK

Auth0.js is a client-side JavaScript library for Auth0. From 8.11.0 to 9.32.0, under specific preconditions, the Auth0.js SDK may improperly return user profile information using a valid access token…

auth0.js | Remote | Authentication
May 27, 2026 Jun 04, 2026
May 27, 2026
Jun 04, 2026
8.8 HIGH
CVE-2026-42184 — Tauri: Origin Confusion Allows Remote Pages to Invoke Local-Only IPC Commands

Tauri is a framework for building binaries for all major desktop platforms. From 2.0 to 2.11.0, a flaw in Tauri's is_local_url() function causes it to incorrectly classify remote URLs as trusted loca…

tauri | Remote | Path Traversal
May 27, 2026 Jun 02, 2026
May 27, 2026
Jun 02, 2026
7.3 HIGH
CVE-2026-37713 — Dolibarr ERP/CRM Remote Code Execution

An issue in Dolibarr ERP/CRM v.22.0.0 through v.22.0.4 and v.24.0.0-alpha allows a remote attacker to execute arbitrary code via the htdocs/core/class/commonobject.class.php.

Remote | Injection
May 27, 2026 May 28, 2026
May 27, 2026
May 28, 2026
7.3 HIGH
CVE-2026-37712 — Dolibarr ERP/CRM Remote Code Execution Vulnerability

An issue in Dolibarr ERP/CRM v.22.0.0 through v.22.0.4 and v.24.0.0-alpha allows a remote attacker to execute arbitrary code via the htdocs/cron/class/cronjob.class.php, call_user_func_array() in fun…

Remote | Injection
May 27, 2026 May 28, 2026
May 27, 2026
May 28, 2026
7.3 HIGH
CVE-2026-37711 — Dolibarr ERP/CRM Remote Code Execution

An issue in Dolibarr ERP/CRM v.22.0.0 through v.22.0.4 and v.24.0.0-alpha allows a remote attacker to execute arbitrary code via the htdocs/core/actions_addupdatedelete.inc.php

Remote | Injection
May 27, 2026 May 27, 2026
May 27, 2026
May 27, 2026
Showing 20 of 6704 Results