Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.3 MEDIUM
CVE-2026-42335 — MaxKB: SSRF Bypass in MaxKB OSS URL Fetch due to URL Parsing Discrepancy

MaxKB is an open-source AI assistant for enterprise. Prior to 2.8.1, MaxKB v2.8.0 and prior are vulnerable to a server-side request forgery (SSRF) bypass in the OSS file service URL fetch (chat/api/o…

maxkb | Remote | Server-Side Request Forgery
May 26, 2026 May 27, 2026
May 26, 2026
May 27, 2026
4.3 MEDIUM
CVE-2026-36239 — PbootCMS Code Injection Vulnerability

PbootCMS v.3.2.11 contains a code injection vulnerability in its site configuration functionality

Remote | Injection
May 26, 2026 May 27, 2026
May 26, 2026
May 27, 2026
2.4 LOW
CVE-2025-68711 — AppLockZ Android App Lock Fingerprint Lockscreen Bypass Vulnerability

AppLockZ App Lock and Fingerprint Lock (applock.passwordfingerprint.applockz) 4.2.11 for Android allows a local attacker with physical access to bypass the PIN lock. The lock is implemented as an ove…

| Authentication
May 26, 2026 May 27, 2026
May 26, 2026
May 27, 2026
2.4 LOW
CVE-2025-68708 — SailingLab AppLock Android Overlay Bypass

SailingLab AppLock (aka com.alpha.applock) 4.3.8 for Android allows a local attacker with physical access to bypass the PIN lock. The lock is implemented as an overlay rather than by using Android's …

| Authentication
May 26, 2026 May 27, 2026
May 26, 2026
May 27, 2026
7.1 HIGH
CVE-2025-14361 — WordPress Woocommerce Envato Affiliates plugin <= 1.2.1 - Settings Change vulnerability

Missing Authorization vulnerability in AA-Team Woocommerce Envato Affiliates allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Woocommerce Envato Affiliates: from n…

Remote | Authorization
May 26, 2026 May 27, 2026
May 26, 2026
May 27, 2026
Showing 20 of 8265 Results