Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.1 MEDIUM
CVE-2026-7163 — Assisted-service: assisted-service: authenticated users can gain administrative access to…

A vulnerability in the assisted-service REST API, an optional Assisted Installer (assisted-service) component in the Multicluster Engine (MCE), allows an authenticated user with minimal namespace-sco…

| Authentication
Apr 30, 2026 Apr 30, 2026
Apr 30, 2026
Apr 30, 2026
0.0 NA
CVE-2026-7246 — Pallets Click contains a command injection via Unsanitized Filename "click.edit()"

Pallets Click, versions 8.3.2 and below, contain a command injection vulnerability in the click.edit() function, allowing attackers to pass arbitrary OS commands from an unprivileged account.

| Injection
Apr 30, 2026 Apr 30, 2026
Apr 30, 2026
Apr 30, 2026
8.1 HIGH
CVE-2026-7402 — Improper Rate Limiting in MeWare Software's PDKS

Improper Control of Interaction Frequency vulnerability in MeWare Software Development Inc. PDKS allows Flooding. This issue affects PDKS: from V16.20200313 before VMYR_3.5.2025117.

Remote | Denial of Service
Apr 30, 2026 Apr 30, 2026
Apr 30, 2026
Apr 30, 2026
8.1 HIGH
CVE-2026-7399 — IDOR in MeWare Software's PDKS

Authorization bypass through User-Controlled key vulnerability in MeWare Software Development Inc. PDKS allows Privilege Abuse. This issue affects PDKS: from V16.20200313 before VMYR_3.5.2025117.

Remote | Authorization
Apr 30, 2026 Apr 30, 2026
Apr 30, 2026
Apr 30, 2026
6.5 MEDIUM
CVE-2026-7382 — Information Disclosure in MeWare Software's PDKS

Exposure of Sensitive Information to an Unauthorized Actor, Exposure of private personal information to an unauthorized actor vulnerability in MeWare Software Development Inc. PDKS allows Excavation.…

Remote | Information Disclosure
Apr 30, 2026 Apr 30, 2026
Apr 30, 2026
Apr 30, 2026
7.4 HIGH
CVE-2025-14576 — Possible QML code injection in VectorImage component

Insufficient validation of node IDs in Qt SVG module allows arbitrary QML/JavaScript code injection when loading malicious SVG files through the VectorImage component in Qt Quick. While QML execution…

| Injection
Apr 30, 2026 Apr 30, 2026
Apr 30, 2026
Apr 30, 2026
7.7 HIGH
CVE-2024-13971 — Arbitrary File Read and Server Side Request Forgery via XML External Entities in Lobster_…

Unauthenticated attackers can exploit a weakness in the XML parser functionality of Lobster_pro prior to version 4.12.6-GA. This allows them to obtain read access to files on the application server a…

Remote | XML External Entity
Apr 30, 2026 Apr 30, 2026
Apr 30, 2026
Apr 30, 2026
0.0 NA
CVE-2026-5080 — Dancer::Session::Abstract versions through 1.3522 for Perl generates session ids insecure…

Dancer::Session::Abstract versions through 1.3522 for Perl generates session ids insecurely. The session id is generated from summing the character codepoints of the absolute pathname with the proce…

| Cryptography
Apr 30, 2026 Apr 30, 2026
Apr 30, 2026
Apr 30, 2026
7.4 HIGH
CVE-2026-41882 — JetBrains IntelliJ IDEA Local File Disclosure

In JetBrains IntelliJ IDEA before 2024.3.7.1, 2025.1.7.1, 2025.2.6.2, 2025.3.4.1, 2026.1.1 reading arbitrary local files was possible via built-in web server

Remote | Path Traversal
Apr 30, 2026 Apr 30, 2026
Apr 30, 2026
Apr 30, 2026
0.0 NA
CVE-2026-31693 — cifs: some missing initializations on replay

In the Linux kernel, the following vulnerability has been resolved: cifs: some missing initializations on replay In several places in the code, we have a label to signify the start of the code wher…

| Memory Corruption
Apr 30, 2026 Apr 30, 2026
Apr 30, 2026
Apr 30, 2026
4.6 MEDIUM
CVE-2026-1493 — Cross-Site Scripting in LEX Baza Dokumentów

LEX Baza Dokumentów is vulnerable to DOM-based XSS in "em" cookie parameter. The application unsafely processes the parameter on the client side, allowing an attacker to execute arbitrary JavaScript …

| Cross-Site Scripting
Apr 30, 2026 Apr 30, 2026
Apr 30, 2026
Apr 30, 2026
0.0 NA
CVE-2026-31787 — xen/privcmd: fix double free via VMA splitting

In the Linux kernel, the following vulnerability has been resolved: xen/privcmd: fix double free via VMA splitting privcmd_vm_ops defines .close (privcmd_close), but neither .may_split nor .open. W…

| Memory Corruption
Apr 30, 2026 Apr 30, 2026
Apr 30, 2026
Apr 30, 2026
0.0 NA
CVE-2026-31786 — Buffer overflow in drivers/xen/sys-hypervisor.c

In the Linux kernel, the following vulnerability has been resolved: Buffer overflow in drivers/xen/sys-hypervisor.c The build id returned by HYPERVISOR_xen_version(XENVER_build_id) is neither NUL t…

| Memory Corruption
Apr 30, 2026 Apr 30, 2026
Apr 30, 2026
Apr 30, 2026
0.0 NA
CVE-2026-31692 — rtnetlink: add missing netlink_ns_capable() check for peer netns

In the Linux kernel, the following vulnerability has been resolved: rtnetlink: add missing netlink_ns_capable() check for peer netns rtnl_newlink() lacks a CAP_NET_ADMIN capability check on the pee…

| Authorization
Apr 30, 2026 Apr 30, 2026
Apr 30, 2026
Apr 30, 2026
5.3 MEDIUM
CVE-2026-6498 — Five Star Restaurant Reservations <= 2.7.16 - Unauthenticated Payment Bypass via PHP Type…

The Five Star Restaurant Reservations plugin for WordPress is vulnerable to a payment bypass via PHP type juggling in versions up to, and including, 2.7.16 This is due to the valid_payment() function…

Remote | Authentication
Apr 30, 2026 Apr 30, 2026
Apr 30, 2026
Apr 30, 2026
7.4 HIGH
CVE-2026-42800 — Deference after null check in ims_client sip

NULL pointer dereference vulnerability in ASR1903 in ASR Lapwing_Linux on Linux (ims_client modules) allows Pointer Manipulation. This vulnerability is associated with program files sip/utils/src/s…

Remote | Memory Corruption
Apr 30, 2026 Apr 30, 2026
Apr 30, 2026
Apr 30, 2026
0.0 NA
CVE-2026-41016 — Apache Airflow Providers SMTP: No certificate validation on SMTP STARTTLS connections in …

Apache Airflow's SMTP provider `SmtpHook` called Python's `smtplib.SMTP.starttls()` without an SSL context, so no certificate validation was performed on the TLS upgrade. A man-in-the-middle between …

| Cryptography
Apr 30, 2026 Apr 30, 2026
Apr 30, 2026
Apr 30, 2026
7.4 HIGH
CVE-2026-42799 — Out-of-bounds read in ulp

Out-of-bounds read vulnerability in ASR Kestrel (nr_fw modules) allows Overflow Buffers. This vulnerability is associated with program files Code/Nr/nr_fw/RA/src/NrPwrCtrl.C. This issue affects …

Remote | Memory Corruption
Apr 30, 2026 Apr 30, 2026
Apr 30, 2026
Apr 30, 2026
0.0 NA
CVE-2026-42512 — Remotely triggerable out-of-bounds heap write in dhclient

As dhclient is building an environment to pass to dhclient-script, it may need to resize the array of string pointers. The code which expands the array incorrectly calculates its new size when reque…

freebsd | Memory Corruption
Apr 30, 2026 Apr 30, 2026
Apr 30, 2026
Apr 30, 2026
0.0 NA
CVE-2026-39457 — Stack overflow via select() file descriptor set overflow

When exchanging data over a socket, libnv uses select(2) to wait for data to arrive. However, it does not verify whether the provided socket descriptor fits in select(2)'s file descriptor set size l…

freebsd | Memory Corruption
Apr 30, 2026 Apr 30, 2026
Apr 30, 2026
Apr 30, 2026
Showing 20 of 5913 Results