Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
4.3 MEDIUM
CVE-2026-9604 — JeecgBoot AiragModelController access control

A vulnerability was detected in JeecgBoot up to 3.9.1. This vulnerability affects unknown code of the component AiragModelController. The manipulation of the argument list/queryById results in improp…

jeecgboot | Remote | Authorization
May 26, 2026 May 27, 2026
May 26, 2026
May 27, 2026
4.8 MEDIUM
CVE-2026-8647 — Crypt::ScryptKDF versions through 0.010 for Perl uses insecure random number source when …

Crypt::ScryptKDF versions through 0.010 for Perl uses insecure random number source when no CSPRNG module is available. The random_bytes function fell back to using the built-in rand() function when…

Remote | Cryptography
May 26, 2026 May 28, 2026
May 26, 2026
May 28, 2026
5.3 MEDIUM
CVE-2026-46740 — Mojolicious::Plugin::Statsd versions through 0.04 for Perl allowed metric injections

Mojolicious::Plugin::Statsd versions through 0.04 for Perl allowed metric injections. The metric names and set values were not checked for newlines, colons or pipes. Metrics generated from untrusted…

Remote | Injection
May 26, 2026 May 28, 2026
May 26, 2026
May 28, 2026
6.5 MEDIUM
CVE-2026-9603 — SourceCodester eDoc Doctor Appointment System delete-session.php authorization

A security vulnerability has been detected in SourceCodester eDoc Doctor Appointment System 1.0. This affects an unknown part of the file /admin/delete-session.php. The manipulation of the argument I…

edoc_doctor_appointment_system | Remote | Authorization
May 26, 2026 May 27, 2026
May 26, 2026
May 27, 2026
7.5 HIGH
CVE-2026-9584 — code-projects Project Management System Login chk.php sql injection

A security vulnerability has been detected in code-projects Project Management System 1.0. Affected is an unknown function of the file chk.php of the component Login. The manipulation leads to sql in…

project_management_system | Remote | Injection
May 26, 2026 May 27, 2026
May 26, 2026
May 27, 2026
8.2 HIGH
CVE-2026-5260 — Gnutls: gnutls: information disclosure via heap overread in rsa key exchange

A flaw was found in libgnutls. A remote attacker, by sending an extremely short premaster secret during an RSA key exchange to a server using an RSA key backed by a PKCS#11 token, could trigger a sho…

May 26, 2026 Jun 02, 2026
May 26, 2026
Jun 02, 2026
6.5 MEDIUM
CVE-2026-48710 — Starlette has missing Host header validation that poisons request.url.path, bypassing pat…

Starlette is a lightweight ASGI framework/toolkit. Prior to version 1.0.1, the HTTP `Host` request header was not validated before being used to reconstruct `request.url`. Because the routing algorit…

starlette | Remote | Misconfiguration
May 26, 2026 Jun 03, 2026
May 26, 2026
Jun 03, 2026
8.1 HIGH
CVE-2026-45574 — epa4all-client: TLS Certificate Validation Disabled in Production

epa4all-client is the Java Client for epa4all / ePA 3.0 in the Telematik Infrastruktur. Prior to 1.2.2, an attacker on the network path between the ePA service and the Konnektor can present any TLS c…

| Misconfiguration
May 26, 2026 May 27, 2026
May 26, 2026
May 27, 2026
8.6 HIGH
CVE-2026-45298 — Dozzle: Pre-auth SSRF with response-body reflection via POST /api/notifications/test-webh…

Dozzle is a realtime log viewer for docker containers. Prior to 10.5.2, in a default dozzle deploy (the documented quickstart, no DOZZLE_AUTH_PROVIDER set), POST /api/notifications/test-webhook is re…

dozzle | Remote | Server-Side Request Forgery
May 26, 2026 May 29, 2026
May 26, 2026
May 29, 2026
9.6 CRITICAL
CVE-2026-44985 — Dozzle: Cross-Site WebSocket Hijacking (CSWSH) on exec/attach endpoints bypasses authenti…

Dozzle is a realtime log viewer for docker containers. Prior to 10.5.2, he WebSocket upgrader for the /exec and /attach endpoints uses CheckOrigin: func(r *http.Request) bool { return true }, accepti…

dozzle | Remote | Authentication
May 26, 2026 May 29, 2026
May 26, 2026
May 29, 2026
7.3 HIGH
CVE-2026-44983 — smallbitvec: Safe API Triggered Heap Buffer Overflow via Integer Overflow

smallbitvec is a growable bit-vector for Rust, optimized for size. From 1.0.1 to 2.6.0, an integer overflow in the internal capacity calculation of smallbitvec can lead to an undersized heap allocati…

| Memory Corruption
May 26, 2026 Jun 01, 2026
May 26, 2026
Jun 01, 2026
9.8 CRITICAL
CVE-2026-44966 — Velocity.js: Prototype Pollution in #set path assignment

Velocity.js is a JavaScript implementation of the Apache Velocity template engine. In 2.1.5 and earlier, a prototype pollution vulnerability was discovered in velocityjs. This issue occurs during the…

velocity.js | Remote | Injection
May 26, 2026 Jun 02, 2026
May 26, 2026
Jun 02, 2026
7.5 HIGH
CVE-2026-44905 — Vanetza: Remote Denial of Service via Uncaught OER Encoding Exception in Cryptographic Ve…

Vanetza is an open-source implementation of the ETSI C-ITS protocol suite. In 26.02 and earlier, a denial-of-service vulnerability was identified in the cryptographic verification pipeline of Vanetza…

Remote | Denial of Service
May 26, 2026 Jun 01, 2026
May 26, 2026
Jun 01, 2026
6.1 MEDIUM
CVE-2026-44903 — Prometheus: Stored XSS via crafted histogram bucket label values in the heatmap display o…

Prometheus is an open-source monitoring system and time series database. From 2.49.0 to before 3.5.3 and 3.11.3, in the Prometheus server's legacy web UI (enabled via the command-line flag --enable-f…

prometheus | Remote | Cross-Site Scripting
May 26, 2026 Jun 05, 2026
May 26, 2026
Jun 05, 2026
8.1 HIGH
CVE-2026-44900 — epa4all-client: VAU Signature bypass

epa4all-client is the Java Client for epa4all / ePA 3.0 in the Telematik Infrastruktur. Prior to 1.2.1, in SignedPublicKeysTrustValidatorImpl.isTrusted(), the ECDSA signature verification at line 45…

| Cryptography
May 26, 2026 May 27, 2026
May 26, 2026
May 27, 2026
9.2 CRITICAL
CVE-2026-44895 — GitLab MCP Server: SSE transport has no authentication and wildcard CORS, exposing all Gi…

GitLab MCP Server lets an AI agent talk directly to GitLab. Prior to 0.6.0, the HTTP transport in src/transport.ts ships with no authentication layer at all and a wildcard Access-Control-Allow-Origin…

Remote | Authentication
May 26, 2026 Jun 01, 2026
May 26, 2026
Jun 01, 2026
6.5 MEDIUM
CVE-2026-44788 — SharpCompress: Directory traversal via directory entries in WriteToDirectory (zip slip va…

SharpCompress is a fully managed C# library to deal with many compression types and formats. In 0.47.4 and earlier, a path traversal vulnerability in IArchive.WriteToDirectory() allows a malicious ar…

sharpcompress sharpcompress | Remote | Path Traversal
May 26, 2026 Jun 05, 2026
May 26, 2026
Jun 05, 2026
6.5 MEDIUM
CVE-2026-44213 — OpenTelemetry.Exporter.Instana bypasses TLS certificate validation when a proxy is config…

The OpenTelemetry.Exporter.Instana exports telemetry to Instana backend. Prior to 1.1.0, the OpenTelemetry.Exporter.Instana NuGet package does not validate HTTPS/TLS certificates are valid when sendi…

May 26, 2026 May 29, 2026
May 26, 2026
May 29, 2026
7.5 HIGH
CVE-2026-43988 — Vanetza: Remote Denial of Service via Uncaught Exception in ASN.1/OER Parsing

Vanetza is an open-source implementation of the ETSI C-ITS protocol suite. In 26.02 and earlier, a denial-of-service vulnerability was identified in the ASN.1/OER parsing pipeline of Vanetza. When pr…

Remote | Denial of Service
May 26, 2026 Jun 01, 2026
May 26, 2026
Jun 01, 2026
5.3 MEDIUM
CVE-2026-42015 — Gnutls: gnutls: memory corruption due to off-by-one error in pkcs#12 bag handling

A flaw was found in gnutls. An off-by-one error exists in the PKCS#12 bag element bounds check. This vulnerability allows an remote attacker to write past the internal array of a PKCS#12 bag when app…

May 26, 2026 Jun 02, 2026
May 26, 2026
Jun 02, 2026
Showing 20 of 6714 Results