Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
3.8 LOW
CVE-2026-34094 — Customized help link for page protection indicator is relative to subpage name, because t…

Vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Page/Article.Php. This issue affects MediaWiki: from * before 1.43.7, 1.44.4, 1.45.2.

mediawiki | Remote
May 11, 2026 May 18, 2026
May 11, 2026
May 18, 2026
5.3 MEDIUM
CVE-2026-34093 — Special:UserRights allows viewing user rights from private wiki

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation MediaWiki. This vulnerability is associated with program files includes/Specials/SpecialUserRights.P…

mediawiki | Remote | Information Disclosure
May 11, 2026 May 18, 2026
May 11, 2026
May 18, 2026
8.1 HIGH
CVE-2026-30635 — Automagik-Genie MCP Server Command Injection Vulnerability

Command injection vulnerability in automagik-genie 2.5.27 MCP Server allows attackers to execute arbitrary commands via the view_task (aka view) in the readTranscriptFromCommit function in dist/mcp/s…

Remote | Injection
May 11, 2026 May 13, 2026
May 11, 2026
May 13, 2026
7.1 HIGH
CVE-2026-2393 — Server-Side Request Forgery (SSRF) in mlflow/mlflow

A Server-Side Request Forgery (SSRF) vulnerability exists in MLflow versions prior to 3.9.0. The `_create_webhook()` function in `mlflow/server/handlers.py` accepts a user-controlled `url` parameter …

mlflow | Remote | Server-Side Request Forgery
May 11, 2026 May 27, 2026
May 11, 2026
May 27, 2026
7.3 HIGH
CVE-2026-2291 — CVE-2026-2291

dnsmasqs extract_name() function can be abused to cause a heap buffer overflow, allowing an attacker to inject false DNS cache entries, which could result in DNS lookups to redirect to an attacker-co…

ftldns | Remote | Memory Corruption
May 11, 2026 May 13, 2026
May 11, 2026
May 13, 2026
Showing 20 of 7525 Results