Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-46510 — Prototype pollution in form-data-objectizer via bracket-notation form keys

form-data-objectizer converts FormData to object. Prior to 1.0.1, form-data-objectizer walks bracket-notation form keys (e.g. name[sub]) into nested objects without filtering __proto__, constructor, …

| Misconfiguration
May 29, 2026 May 29, 2026
May 29, 2026
May 29, 2026
3.8 LOW
CVE-2026-40528 — OpenSC < 0.27.0 Buffer Overrun in do_key_value() via profile.c

OpenSC before 0.27.0, fixed in commit 0358817, contains a stack and heap buffer overrun vulnerability in the do_key_value() function in src/pkcs15init/profile.c that allows attackers to corrupt memor…

| Memory Corruption
May 29, 2026 May 29, 2026
May 29, 2026
May 29, 2026
0.0 NA
CVE-2026-45582 — n8n-MCP: Workflow telemetry sanitizer could retain partial values from URL-shaped node pa…

n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior to 2.51.3, the workflow telemetry sanitizer could retain partial fragments of …

| Information Disclosure
May 29, 2026 May 29, 2026
May 29, 2026
May 29, 2026
0.0 NA
CVE-2026-45707 — n8n-MCP: Multi-tenant MCP requests fall back to process-level n8n credentials when tenant…

n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior to 2.51.2, when ENABLE_MULTI_TENANT=true, the HTTP transport documents that th…

| Authorization
May 29, 2026 May 29, 2026
May 29, 2026
May 29, 2026
0.0 NA
CVE-2026-44698 — Home Assistant: Cross-origin iframe access token exfiltration via WebView JS bridge callb…

Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2026.4.1 for iOS and 2026.4.4 for Android, he Home Assistant Companion apps for Android and …

| Cross-Site Scripting
May 29, 2026 May 29, 2026
May 29, 2026
May 29, 2026
0.0 NA
CVE-2026-10061 — TRENDnet TEW-432BRP formWPS command injection

A vulnerability was found in TRENDnet TEW-432BRP 3.10B20. Affected is the function formWPS of the file /goform/formWPS. The manipulation of the argument peerPin results in command injection. The atta…

| Injection
May 29, 2026 May 29, 2026
May 29, 2026
May 29, 2026
3.8 LOW
CVE-2026-40510 — OpenSC < 0.27.0-rc1 Stack Buffer Overflow via piv_process_history() in card-piv.c

OpenSC before 0.27.0-rc1, fixed in commit 3f24f0b, contains a stack buffer overflow vulnerability in piv_process_history() in src/libopensc/card-piv.c that allows physically present attackers to trig…

| Memory Corruption
May 29, 2026 May 29, 2026
May 29, 2026
May 29, 2026
0.0 NA
CVE-2026-45615 — mouse07410/asn1c: 1-byte Heap Out-of-Bounds Read in `INTEGER_decode_oer` via Malformed OE…

mouse07410/asn1c is an ASN.1 compiler. In 1.4 and earlier, a memory safety vulnerability was identified in the OER decoding skeleton files generated by asn1c (specifically INTEGER_oer.c). When parsin…

| Memory Corruption
May 29, 2026 May 29, 2026
May 29, 2026
May 29, 2026
2.4 LOW
CVE-2026-49318 — Indian Scout Bobber 2025 Infotainment Digital Round skips PIN entry when WCM is silent at…

Incorrect behavior order in the Infotainment / Digital Round display of the Indian Motorcycle Scout Bobber + Tech 2025 model year allows an adjacent-network attacker to bypass the PIN entry screen. T…

| Misconfiguration
May 29, 2026 May 29, 2026
May 29, 2026
May 29, 2026
8.7 HIGH
CVE-2026-9509 — Uncaught exception vulnerability in Suprema's BioStar

An unhandled exception in Suprema BioStar 2 (Server), versions 2.9.8, 2.9.10, and 2.9.11, that allows an unauthenticated remote attacker to cause a denial of service (DoS) by sending HTTP POST reques…

Remote | Denial of Service
May 29, 2026 May 29, 2026
May 29, 2026
May 29, 2026
10.0 CRITICAL
CVE-2026-9508 — Incorrect Permission Assignment for Critical Resource vulnerability in Suprema's BioStar

Incorrect permission settings on a critical resource in Suprema BioStar 2 (versions 2.9.3 through 2.9.11) that allow backup files to be publicly exposed when the administrator configures their path w…

Remote | Misconfiguration
May 29, 2026 May 29, 2026
May 29, 2026
May 29, 2026
10.0 CRITICAL
CVE-2026-8326 — Remote Spark SparkView Path Traversal in RDP Drive Redirection leading to RCE

Path traversal vulnerability in Remote Spark (https://www.Remotespark.Com/) SparkView allows reading and writing arbitrary files in all directories as root. This leads to RCE. The affected component …

Remote | Path Traversal
May 29, 2026 May 29, 2026
May 29, 2026
May 29, 2026
4.6 MEDIUM
CVE-2026-49324 — Indian Scout Bobber 2025 WCM brute-force

Uncontrolled resource consumption in the Wireless Control Module (WCM) of the Indian Motorcycle Scout Bobber + Tech 2025 model year allows an adjacent-network attacker with write access to the in-veh…

| Denial of Service
May 29, 2026 May 29, 2026
May 29, 2026
May 29, 2026
4.3 MEDIUM
CVE-2026-49323 — Indian Scout Bobber 2025 WCM-to-ECM weak authentication

Weak authentication between the Wireless Control Module (WCM) and the Engine Control Module (ECM) of the Indian Motorcycle Scout Bobber + Tech 2025 model year allows an adjacent-network attacker with…

| Authentication
May 29, 2026 May 29, 2026
May 29, 2026
May 29, 2026
8.7 HIGH
CVE-2026-48527 — HaxCMS has a stored Cross-Site Scripting (XSS) bypass in saveNode endpoint

HAX CMS helps manage microsite universe with PHP or NodeJs backends. Versions up to and including 26.0.0 are affected by a stored cross-site scripting (XSS) vulnerability in the `/system/api/saveNode…

Remote | Cross-Site Scripting
May 29, 2026 May 29, 2026
May 29, 2026
May 29, 2026
5.1 MEDIUM
CVE-2026-45551 — Group-Office: Authenticated Stored XSS in Administrator Context via Arbitrary Cross-User …

Group-Office is an enterprise customer relationship management and groupware tool. Prior to 26.0.25, 25.0.100, and 6.8.165, GroupOffice allows authenticated users to persist arbitrary legacy settings…

Remote | Cross-Site Scripting
May 29, 2026 May 29, 2026
May 29, 2026
May 29, 2026
9.9 CRITICAL
CVE-2026-45312 — RAGFlow: Server-Side Template Injection in Prompt Generator leads to Remote Code Execution

RAGFlow is an open-source RAG (Retrieval-Augmented Generation) engine. In 0.24.0 and earlier, a Jinja2 template injection in the prompt generator (rag/prompts/generator.py) allows any authenticated u…

Remote | Injection
May 29, 2026 May 29, 2026
May 29, 2026
May 29, 2026
9.3 CRITICAL
CVE-2026-45043 — RustFS: ImportIam Allows Creation of Backdoor Service Accounts Under Any Parent Including…

RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, improper validation in the PUT /rustfs/admin/v3/import-iam endpoint allows a user with ImportIAMAction to create se…

Remote | Authorization
May 29, 2026 May 29, 2026
May 29, 2026
May 29, 2026
9.8 CRITICAL
CVE-2026-10071 — Interinfo|DreamMaker - Arbitrary File Upload

DreamMaker developed by Interinfo has an Arbitrary File Upload vulnerability, allowing unauthenticated remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code exec…

Remote | Misconfiguration
May 29, 2026 May 29, 2026
May 29, 2026
May 29, 2026
0.0 NA
CVE-2026-10060 — TRENDnet TEW-432BRP formSetRoute command injection

A vulnerability has been found in TRENDnet TEW-432BRP 3.10B20. This impacts the function formSetRoute of the file /goform/formSetRoute. The manipulation of the argument ip/mask/gateway leads to comma…

| Injection
May 29, 2026 May 29, 2026
May 29, 2026
May 29, 2026
Showing 20 of 6962 Results