Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
4.3 MEDIUM
CVE-2026-2306 — Ninja Tables <= 5.2.6 - Missing Authorization to Authenticated (Subscriber+) Arbitrary Ta…

The Ninja Tables – Easy Data Table Builder plugin for WordPress is vulnerable to unauthorized database table creation due to missing authorization checks on the `createFluentCartTable` function in al…

Remote | Authorization
May 06, 2026 May 06, 2026
May 06, 2026
May 06, 2026
6.5 MEDIUM
CVE-2026-5753 — All-in-One WP Migration Unlimited Extension <= 2.83 - Missing Authorization to Authentica…

The All-in-One WP Migration Unlimited Extension plugin for WordPress is vulnerable to Missing Authorization in versions up to, and including, 2.83. This is due to the 'Ai1wmve_Schedules_Controller::s…

Remote | Authorization
May 06, 2026 May 06, 2026
May 06, 2026
May 06, 2026
5.3 MEDIUM
CVE-2026-3208 — Mercado Pago payments for WooCommerce <= 8.7.11 - Missing Authorization to Unauthenticate…

The Mercado Pago payments for WooCommerce plugin for WordPress is vulnerable to unauthorized access of data due to a missing capability check on the 'mp_pix_image' WooCommerce API endpoint in all ver…

Remote | Authorization
May 06, 2026 May 06, 2026
May 06, 2026
May 06, 2026
5.0 MEDIUM
CVE-2026-7573 — GetUserRoles API endpoint allows any authenticated user to enumerate ACL policies across …

An authorization bypass (CWE-639) in the GetUserRoles gRPC API endpoint in Velocidex Velociraptor below version 0.76.5 allows any authenticated low-privilege user to retrieve the complete ACL policy …

Remote | Authorization
May 06, 2026 May 06, 2026
May 06, 2026
May 06, 2026
4.4 MEDIUM
CVE-2026-7572 — Velociraptor EVTX Parser — Process Crash via Crafted .evtx File

An off-by-one error (CWE-193) in the ConsumeUnit16Array and ConsumeUnit64Array functions in Velocidex Velociraptor before version 0.76.5 on Windows and Linux allows a local attacker to cause a Denial…

| Memory Corruption
May 06, 2026 May 06, 2026
May 06, 2026
May 06, 2026
7.5 HIGH
CVE-2025-71256 — "NR Modem Remote Denial of Service (DoS) Vulnerability"

In nr modem, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed.

| Denial of Service
May 06, 2026 May 06, 2026
May 06, 2026
May 06, 2026
7.5 HIGH
CVE-2025-71255 — "Modem IMS Denial of Service Vulnerability"

In Modem IMS, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed.

| Denial of Service
May 06, 2026 May 06, 2026
May 06, 2026
May 06, 2026
7.5 HIGH
CVE-2025-71254 — "Modem IMS Remote Denial of Service Vulnerability"

In Modem IMS, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed.

| Denial of Service
May 06, 2026 May 06, 2026
May 06, 2026
May 06, 2026
7.5 HIGH
CVE-2025-71253 — "Modem IMS Remote Denial of Service Vulnerability"

In Modem IMS, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed.

| Denial of Service
May 06, 2026 May 06, 2026
May 06, 2026
May 06, 2026
7.5 HIGH
CVE-2025-71252 — "Modem IMS Remote Denial of Service Vulnerability"

In Modem IMS, there is a possible improper input validation. This could lead to remote denial of service with no additional execution privileges needed.

| Denial of Service
May 06, 2026 May 06, 2026
May 06, 2026
May 06, 2026
7.5 HIGH
CVE-2025-71251 — Apache IMS Remote Denial of Service Vulnerability

In IMS, there is a possible system crash due to improper input validation. This could lead to remote denial of service with no additional execution privileges needed.

| Denial of Service
May 06, 2026 May 06, 2026
May 06, 2026
May 06, 2026
3.4 LOW
CVE-2026-44405 — Paramiko RSA Key SHA-1 Vulnerability

In Paramiko through 4.0.0 before a448945, rsakey.py allows the SHA-1 algorithm.

paramiko | Cryptography
May 06, 2026 May 06, 2026
May 06, 2026
May 06, 2026
7.6 HIGH
CVE-2026-40934 — jupyter-server authentication cookies remain valid after password reset due to static coo…

Jupyter Server is the backend for Jupyter web applications. In versions 2.17.0 and earlier, the secret used to sign authentication cookies is persisted to a static file at ~/.local/share/jupyter/runt…

jupyter_server | Remote | Authentication
May 05, 2026 May 05, 2026
May 05, 2026
May 05, 2026
7.6 HIGH
CVE-2026-40110 — jupyter-server CORS origin validation bypass via unanchored regex in allow_origin_pat

Jupyter Server is the backend for Jupyter web applications. In versions 2.17.0 and earlier, the Origin header validation uses Python's re.match() to check incoming origins against the allow_origin_pa…

jupyter_server | Remote | Misconfiguration
May 05, 2026 May 05, 2026
May 05, 2026
May 05, 2026
8.2 HIGH
CVE-2026-40075 — OpenMRS Core arbitrary file read via path traversal in ModuleResourcesServlet

OpenMRS Core is an open source electronic medical record system platform. In versions 2.7.8 and earlier and versions 2.8.0 through 2.8.5, the `/openmrs/moduleResources/{moduleid}` endpoint is vulnera…

Remote | Path Traversal
May 05, 2026 May 05, 2026
May 05, 2026
May 05, 2026
0.0 NA
CVE-2026-28780 — Apache HTTP Server: buffer overflow in mod_proxy_ajp via ajp_msg_check_header()

Heap-based Buffer Overflow vulnerability in mod_proxy_ajp of Apache HTTP Server. If mod_proxy_ajp connects to a malicious AJP server this AJP server can send a malicious AJP message back to mod_proxy…

http_server | Memory Corruption
May 05, 2026 May 05, 2026
May 05, 2026
May 05, 2026
6.5 MEDIUM
CVE-2026-41950 — Dify < 1.14.0 Authorization Bypass via File UUID

Dify before version 1.14.0 contains an authorization bypass vulnerability that allows authenticated users to read the full contents of files uploaded by other users within the same tenant by supplyin…

dify | Remote | Authorization
May 05, 2026 May 05, 2026
May 05, 2026
May 05, 2026
7.7 HIGH
CVE-2026-40068 — Claude Code arbitrary code execution via git worktree commondir trust dialog bypass

In versions 2.1.63 through 2.1.83 of Claude Code, the folder trust determination logic used the git worktree commondir file without validating its contents. An attacker could craft a malicious reposi…

claude_code | Remote | Misconfiguration
May 05, 2026 May 05, 2026
May 05, 2026
May 05, 2026
8.8 HIGH
CVE-2026-39852 — Quarkus authorization bypass via semicolon path normalization inconsistency

Quarkus is a Java framework for building cloud-native applications. In versions prior to 3.20.6.1, 3.27.3.1, 3.33.1.1, 3.35.1.1, 3.34.7, and 3.35.2, a path normalization inconsistency between the sec…

Remote | Authorization
May 05, 2026 May 05, 2026
May 05, 2026
May 05, 2026
8.7 HIGH
CVE-2026-39849 — Pi-hole FTL remote code execution via newline injection in dns.interface configuration

Pi-hole FTL is the core engine of the Pi-hole network-level advertisement and tracker blocker. In versions before 6.6.1, the `dns.interface` configuration field in Pi-hole FTL accepted newline charac…

ftldns | Remote | Injection
May 05, 2026 May 05, 2026
May 05, 2026
May 05, 2026
Showing 20 of 5680 Results