Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.2 MEDIUM
CVE-2026-34672 — CAI Content Credentials | Integer Underflow (Wrap or Wraparound) (CWE-191)

CAI Content Credentials versions 0.78.2, 0.7.0 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an application denial-of-service. An attacker c…

| Denial of Service
May 12, 2026 May 12, 2026
May 12, 2026
May 12, 2026
6.2 MEDIUM
CVE-2026-34671 — CAI Content Credentials | Integer Overflow or Wraparound (CWE-190)

CAI Content Credentials versions 0.78.2, 0.7.0 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in an application denial-of-service. An attacker could exp…

| Denial of Service
May 12, 2026 May 12, 2026
May 12, 2026
May 12, 2026
6.2 MEDIUM
CVE-2026-34669 — CAI Content Credentials | Improper Input Validation (CWE-20)

CAI Content Credentials versions 0.78.2, 0.7.0 and earlier are affected by an Improper Input Validation vulnerability that could result in an application denial-of-service. An attacker could exploit …

| Denial of Service
May 12, 2026 May 12, 2026
May 12, 2026
May 12, 2026
6.2 MEDIUM
CVE-2026-34678 — CAI Content Credentials | Uncontrolled Resource Consumption (CWE-400)

CAI Content Credentials versions 0.78.2, 0.7.0 and earlier are affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attacker could explo…

| Denial of Service
May 12, 2026 May 12, 2026
May 12, 2026
May 12, 2026
6.2 MEDIUM
CVE-2026-34688 — CAI Content Credentials | Improper Input Validation (CWE-20)

CAI Content Credentials versions 0.78.2, 0.7.0 and earlier are affected by an Improper Input Validation vulnerability that could result in an application denial-of-service. An attacker could exploit …

| Denial of Service
May 12, 2026 May 12, 2026
May 12, 2026
May 12, 2026
6.2 MEDIUM
CVE-2026-34680 — CAI Content Credentials | Integer Overflow or Wraparound (CWE-190)

CAI Content Credentials versions 0.78.2, 0.7.0 and earlier are affected by an Integer Overflow or Wraparound vulnerability that could result in an application denial-of-service. An attacker could exp…

| Denial of Service
May 12, 2026 May 12, 2026
May 12, 2026
May 12, 2026
6.2 MEDIUM
CVE-2026-34668 — CAI Content Credentials | Improper Input Validation (CWE-20)

CAI Content Credentials versions 0.78.2, 0.7.0 and earlier are affected by an Improper Input Validation vulnerability that could result in an application denial-of-service. An attacker could exploit …

| Denial of Service
May 12, 2026 May 12, 2026
May 12, 2026
May 12, 2026
6.2 MEDIUM
CVE-2026-34673 — CAI Content Credentials | Uncontrolled Resource Consumption (CWE-400)

CAI Content Credentials versions 0.78.2, 0.7.0 and earlier are affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attacker could explo…

| Denial of Service
May 12, 2026 May 12, 2026
May 12, 2026
May 12, 2026
6.2 MEDIUM
CVE-2026-34667 — CAI Content Credentials | Integer Underflow (Wrap or Wraparound) (CWE-191)

CAI Content Credentials versions 0.78.2, 0.7.0 and earlier are affected by an Integer Underflow (Wrap or Wraparound) vulnerability that could result in an application denial-of-service. An attacker c…

| Denial of Service
May 12, 2026 May 12, 2026
May 12, 2026
May 12, 2026
7.5 HIGH
CVE-2026-34665 — CAI Content Credentials | Uncontrolled Resource Consumption (CWE-400)

CAI Content Credentials versions 0.78.2, 0.7.0 and earlier are affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attacker could explo…

Remote | Denial of Service
May 12, 2026 May 12, 2026
May 12, 2026
May 12, 2026
6.2 MEDIUM
CVE-2026-34670 — CAI Content Credentials | Improper Input Validation (CWE-20)

CAI Content Credentials versions 0.78.2, 0.7.0 and earlier are affected by an Improper Input Validation vulnerability that could result in an application denial-of-service. An attacker could exploit …

| Denial of Service
May 12, 2026 May 12, 2026
May 12, 2026
May 12, 2026
6.2 MEDIUM
CVE-2026-34679 — CAI Content Credentials | Improper Input Validation (CWE-20)

CAI Content Credentials versions 0.78.2, 0.7.0 and earlier are affected by an Improper Input Validation vulnerability that could result in an application denial-of-service. An attacker could exploit …

| Denial of Service
May 12, 2026 May 12, 2026
May 12, 2026
May 12, 2026
6.2 MEDIUM
CVE-2026-34666 — CAI Content Credentials | Improper Input Validation (CWE-20)

CAI Content Credentials versions 0.78.2, 0.7.0 and earlier are affected by an Improper Input Validation vulnerability that could result in an application denial-of-service. An attacker could exploit …

| Denial of Service
May 12, 2026 May 12, 2026
May 12, 2026
May 12, 2026
6.2 MEDIUM
CVE-2026-34677 — CAI Content Credentials | Uncontrolled Resource Consumption (CWE-400)

CAI Content Credentials versions 0.78.2, 0.7.0 and earlier are affected by an Uncontrolled Resource Consumption vulnerability that could lead to application denial-of-service. An attacker could explo…

| Denial of Service
May 12, 2026 May 12, 2026
May 12, 2026
May 12, 2026
0.0 NA
CVE-2026-44225 — Pulpy: Incomplete filesystem sandbox in pulpy.fs bridge allows packaged web apps to read …

Pulpy is a lightweight, cross-platform desktop application packager for web apps. Prior to 0.1.1, Pulpy injects a pulpy.fs JavaScript API into every packaged web application, giving it access to the …

| Path Traversal
May 12, 2026 May 12, 2026
May 12, 2026
May 12, 2026
0.0 NA
CVE-2026-44223 — vLLM: extract_hidden_states speculative decoding crashes server on any request with penal…

vLLM is an inference and serving engine for large language models (LLMs). From to before 0.20.0, the extract_hidden_states speculative decoding proposer in vLLM returns a tensor with an incorrect sh…

| Denial of Service
May 12, 2026 May 12, 2026
May 12, 2026
May 12, 2026
0.0 NA
CVE-2026-44222 — vLLM: Remote DoS via Special-Token Placeholders

vLLM is an inference and serving engine for large language models (LLMs). From 0.6.1 to before 0.20.0, there is a a Token Injection vulnerability in vLLM’s multimodal processing. Unauthenticated, tex…

| Injection
May 12, 2026 May 12, 2026
May 12, 2026
May 12, 2026
0.0 NA
CVE-2026-44221 — ArcadeDB: Cross-database authorization bypass and unsecured newly-created databases

ArcadeDB is a Multi-Model DBMS. Prior to 2.6.4, authenticated users and API tokens scoped to a specific database could read, write, and mutate schema on any other database on the same server. Two dis…

| Authorization
May 12, 2026 May 12, 2026
May 12, 2026
May 12, 2026
0.0 NA
CVE-2026-44217 — sse-channel: SSE Injection via unsanitized event fields

sse-channel is an SSE-implementation which can be used to any node.js http request/response stream. Prior to 4.0.1, implementations that allow user-provided values to be passed to event, retry or id …

| Injection
May 12, 2026 May 12, 2026
May 12, 2026
May 12, 2026
4.3 MEDIUM
CVE-2026-34656 — Adobe Commerce | Improper Authorization (CWE-285)

Adobe Commerce versions 2.4.9-beta1, 2.4.8-p4, 2.4.7-p9, 2.4.6-p14, 2.4.5-p16, 2.4.4-p17 and earlier are affected by an Improper Authorization vulnerability that could result in a Security feature by…

Remote | Authorization
May 12, 2026 May 12, 2026
May 12, 2026
May 12, 2026
Showing 20 of 6230 Results