Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.1 MEDIUM
CVE-2026-44681 — Authlib: Open Redirect in Authlib OIDC Implicit/Hybrid Authorization

Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to 1.6.12 and 1.7.1, an unauthenticated open redirect in Authlib's OpenIDImplicitGrant and OpenIDHybridGrant authoriza…

authlib | Remote | Misconfiguration
May 27, 2026 Jun 02, 2026
May 27, 2026
Jun 02, 2026
9.3 CRITICAL
CVE-2026-44590 — Sherlock: Command Injection via pull_request_target in validate_modified_targets.yml

Sherlock hunts down social media accounts by username across social networks. Prior to 0.16.1, the GitHub Actions workflow validate_modified_targets.yml is vulnerable to command injection via the pul…

Remote | Injection
May 27, 2026 May 29, 2026
May 27, 2026
May 29, 2026
5.4 MEDIUM
CVE-2026-42877 — FacturaScripts: Stored XSS via product reference in sales/purchases

FacturaScripts is an open source accounting and invoicing software. In 2025.92 and earlier, a stored Cross-Site Scripting (XSS) vulnerability exists in the product search modal of sales (Core/Lib/Aja…

facturascripts | Remote | Cross-Site Scripting
May 27, 2026 May 29, 2026
May 27, 2026
May 29, 2026
8.7 HIGH
CVE-2026-42197 — RELATE Vulnerable to Stored XSS via Unprivileged User Profile

RELATE is a web-based courseware package. Versions prior to commit 555f0efb1c5bd7531c07cd73724d7e566a81f620 have a stored cross-site scripting vulnerability that allows any enrolled student to execut…

relate | Remote | Cross-Site Scripting
May 27, 2026 Jun 01, 2026
May 27, 2026
Jun 01, 2026
3.7 LOW
CVE-2026-33552 — Northern.tech Mender Enterprise Server Authentication Bypass

Northern.tech Mender Enterprise Server before 4.1.1 has Incorrect Access Control.

Remote | Authorization
May 27, 2026 Jun 01, 2026
May 27, 2026
Jun 01, 2026
Showing 20 of 7845 Results