Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-30950 — AutoGPT has Authenticated Session Hijacking via IDOR

AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Versions 0.6.36 through 0.6.50 are vulnerable to Authenticated Session Hijac…

| Authentication
May 18, 2026 May 18, 2026
May 18, 2026
May 18, 2026
3.9 LOW
CVE-2026-27964 — FacturaScripts: Reflected Cross-Site Scripting (XSS) via Cookie Manipulation

FacturaScripts is an open source accounting and invoicing software. Versions 2025.7 and prior contain a Reflected Cross-Site Scripting (XSS) vulnerability through the fsNick cookie parameter. The app…

| Cross-Site Scripting
May 18, 2026 May 18, 2026
May 18, 2026
May 18, 2026
6.5 MEDIUM
CVE-2026-27892 — FacturaScripts: Unstripped Image Metadata (EXIF) Leakage via Library Module File Upload/D…

FacturaScripts is an open source accounting and invoicing software. In versions prior to 2026, the Library module stores and serves uploaded images byte-for-byte, without stripping EXIF/XMP/IPTC meta…

Remote | Information Disclosure
May 18, 2026 May 18, 2026
May 18, 2026
May 18, 2026
7.2 HIGH
CVE-2026-27891 — Remote Code Execution (RCE) via Zip Slip in Plugin Upload Mechanism

FacturaScripts is an open source accounting and invoicing software. Versions 2026 and below contain a critical vulnerability in the Plugins::add() function. The system fails to properly validate the …

Remote | Path Traversal
May 18, 2026 May 18, 2026
May 18, 2026
May 18, 2026
6.5 MEDIUM
CVE-2026-27737 — BigBlueButton has Stored XSS in bbb-playback replay

BigBlueButton is an open-source virtual classroom. In versions prior to 3.0.19, the recording playback (presentation format) was not sanitizing user's input in public chat. This allowed for a malicio…

Remote | Cross-Site Scripting
May 18, 2026 May 18, 2026
May 18, 2026
May 18, 2026
8.6 HIGH
CVE-2026-8851 — SOGo 5.12.7 SQL Injection via addUserInAcls endpoint

SOGo 5.12.7 contains a SQL injection vulnerability in the Access Control List management functionality that allows authenticated users to extract arbitrary data from the database by injecting SQL sub…

Remote | Injection
May 18, 2026 May 18, 2026
May 18, 2026
May 18, 2026
9.8 CRITICAL
CVE-2026-8838 — Remote Code Execution via eval() Injection in amazon-redshift-python-driver

Unsafe use of Python's eval() on server-received data in the vector_in() function in amazon-redshift-python-driver before 2.1.14 allows a rogue server or man-in-the-middle actor to execute arbitrary …

Remote | Injection
May 18, 2026 May 18, 2026
May 18, 2026
May 18, 2026
7.0 HIGH
CVE-2026-4137 — Incomplete Fix for CVE-2025-10279: Insecure Temporary Directory Permissions in mlflow/mlf…

In mlflow/mlflow versions prior to 3.11.0, the `get_or_create_nfs_tmp_dir()` function in `mlflow/utils/file_utils.py` creates temporary directories with world-writable permissions (0o777), and the `_…

| Misconfiguration
May 18, 2026 May 18, 2026
May 18, 2026
May 18, 2026
9.9 CRITICAL
CVE-2026-27130 — Dokploy has Command Injection in its Service Operations

Dokploy is a free, self-hostable Platform as a Service (PaaS). Versions 0.26.6 and below have OS command injection through the appName parameter. 3 chained issues cause this problem: inadequate input…

Remote | Injection
May 18, 2026 May 18, 2026
May 18, 2026
May 18, 2026
8.6 HIGH
CVE-2026-26978 — Free PBX backup: Deserialization of Untrusted Data in admin/modules/backup/Models/BackupS…

FreePBX is an open source IP PBX. In versions below 16.0.71 and 17.0.6, the backup module does not properly sanitize data during restore operations, potentially leading to compromise if the backup co…

Remote | Injection
May 18, 2026 May 18, 2026
May 18, 2026
May 18, 2026
9.8 CRITICAL
CVE-2026-25244 — WebdriverIO has Command Injection in the BrowserStack Service

WebdriverIO is a test automation framework for unit, e2e and component testing using WebDriver, WebDriver BiDi and Appium. Versions below 9.24.0 contain a command injection vulnerability leading to r…

Remote | Injection
May 18, 2026 May 18, 2026
May 18, 2026
May 18, 2026
8.2 HIGH
CVE-2026-22810 — Joplin: Path traversal in OneNote importer allows overwriting arbitrary files

Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Versions prior to 3.5.7 contain a path traversal vulnerability in the importer which allows o…

| Path Traversal
May 18, 2026 May 18, 2026
May 18, 2026
May 18, 2026
7.8 HIGH
CVE-2026-47092 — Claude HUD 0.0.12 Arbitrary Command Execution via COMSPEC Environment Variable

Claude HUD through 0.0.12, patched in commit 234d9aa, contains a command injection vulnerability that allows local attackers to execute arbitrary commands by manipulating the COMSPEC environment vari…

| Injection
May 18, 2026 May 18, 2026
May 18, 2026
May 18, 2026
4.8 MEDIUM
CVE-2026-47091 — Claude HUD 0.0.12 Path Traversal via transcript_path

Claude HUD through 0.0.12, patched in commit 234d9aa, contains a path traversal vulnerability that allows attackers to read arbitrary files by supplying an unvalidated transcript_path value via stdin…

| Path Traversal
May 18, 2026 May 18, 2026
May 18, 2026
May 18, 2026
4.6 MEDIUM
CVE-2026-47090 — Claude HUD 0.0.12 Terminal Injection via OSC 8 Hyperlinks

Claude HUD through 0.0.12, patched in commit 234d9aa, constructs OSC 8 terminal hyperlink escape sequences using raw cwd and branchUrl values without stripping control characters or encoding embedded…

| Misconfiguration
May 18, 2026 May 18, 2026
May 18, 2026
May 18, 2026
6.8 MEDIUM
CVE-2026-45246 — Summarize < 0.15.1 Insecure File Permissions Information Disclosure

Summarize prior to 0.15.1 contains an insecure file permission vulnerability in the refresh-free configuration rewrite path that allows local users to read sensitive credentials by exploiting default…

| Misconfiguration
May 18, 2026 May 18, 2026
May 18, 2026
May 18, 2026
7.4 HIGH
CVE-2026-45245 — Summarize < 0.15.1 Unauthorized Daemon Request via Untrusted Events

Summarize prior to 0.15.1 contains a vulnerability in the hover summary feature that allows malicious pages to dispatch synthetic mouseover events over attacker-controlled links, causing the extensio…

Remote | Server-Side Request Forgery
May 18, 2026 May 18, 2026
May 18, 2026
May 18, 2026
5.4 MEDIUM
CVE-2026-45244 — Summarize < 0.15.1 Unapproved Browser Automation Execution

Summarize prior to 0.15.1 contains a missing authorization vulnerability that allows attackers to execute browser automation actions without per-call user approval when the extension automation featu…

Remote | Authorization
May 18, 2026 May 18, 2026
May 18, 2026
May 18, 2026
4.6 MEDIUM
CVE-2026-21789 — HCL Connections is vulnerable to broken access control

HCL Connections contains a broken access control vulnerability that may allow unauthorized user to update data in certain scenarios.

Remote | Authorization
May 18, 2026 May 18, 2026
May 18, 2026
May 18, 2026
4.7 MEDIUM
CVE-2025-65954 — SimpleSAMLphp-casserver has an Open Redirect vulnerability via logout

SimpleSAMLphp-casserver is a CAS 1.0 and 2.0 compliant CAS server in the form of a SimpleSAMLphp module. In versions below 6.3.1 and 7.0.0, the logout endpoint accepts a url query parameter to redire…

Remote | Information Disclosure
May 18, 2026 May 18, 2026
May 18, 2026
May 18, 2026
Showing 20 of 6212 Results