Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.9 MEDIUM
CVE-2026-42600 — MinIO: Path Traversal via msgpack Body in `ReadMultiple` Storage-REST Endpoint

MinIO is a high-performance object storage system. From RELEASE.2022-07-24T01-54-52Z to before RELEASE.2026-04-14T21-32-45Z, A path traversal vulnerability in MinIO's ReadMultiple internode storage-R…

minio | Remote | Path Traversal
May 11, 2026 May 26, 2026
May 11, 2026
May 26, 2026
8.2 HIGH
CVE-2026-42564 — jotty·page: Unauthenticated Path Traversal leads to sensitive file disclosure and session…

jotty·page is a self-hosted app for your checklists and notes. Prior to 1.22.0, an unauthenticated path traversal vulnerability exists in /api/app-icons/[filename]. The filename route parameter is jo…

Remote | Path Traversal
May 11, 2026 May 13, 2026
May 11, 2026
May 13, 2026
2.4 LOW
CVE-2026-42188 — Geyser: Server-Side Request Forgery (SSRF) via Player Head Texture URL

Geyser is a bridge between Minecraft: Bedrock Edition and Minecraft: Java Edition. Prior to 2.9.3, a server-side request forgery (SSRF) vulnerability exists in Geyser’s handling of Bedrock player hea…

geyser | Remote | Server-Side Request Forgery
May 11, 2026 May 13, 2026
May 11, 2026
May 13, 2026
7.8 HIGH
CVE-2026-42046 — libcaca: Heap OOB write in canvas import functions caused by int overflow

libcaca is a colour ASCII art library. In 0.99.beta20 and earlier, an integer overflow vulnerability in libcaca's canvas import functionality allows an attacker to cause a controlled heap out-of-boun…

libcaca | Memory Corruption
May 11, 2026 May 13, 2026
May 11, 2026
May 13, 2026
7.7 HIGH
CVE-2026-34961 — barebox ext4 Extent Parsing Out-of-Bounds Read

barebox prior to version 2026.04.0 contains out-of-bounds read vulnerabilities in ext4 extent parsing due to missing validation of the eh_entries field against buffer capacity in fs/ext4/ext4_common.…

barebox | Memory Corruption
May 11, 2026 May 13, 2026
May 11, 2026
May 13, 2026
7.1 HIGH
CVE-2026-34960 — barebox Out-of-Bounds Read in DHCP Option Parsing

barebox prior to version 2026.04.0 contains an out-of-bounds read vulnerability in DHCP option parsing within the dhcp_message_type() function that fails to verify the options pointer remains within …

barebox | Memory Corruption
May 11, 2026 May 16, 2026
May 11, 2026
May 16, 2026
Showing 20 of 7426 Results