Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
3.3 LOW
CVE-2026-8219 — Devs Palace ERP Online supplier-save cross site scripting

A security vulnerability has been detected in Devs Palace ERP Online up to 4.0.0. The impacted element is an unknown function of the file /inventory/supplier-save. The manipulation leads to cross sit…

Remote | Cross-Site Scripting
May 10, 2026 May 10, 2026
May 10, 2026
May 10, 2026
3.3 LOW
CVE-2026-8218 — Devs Palace ERP Online purchase_return_save cross site scripting

A weakness has been identified in Devs Palace ERP Online up to 4.0.0. The affected element is an unknown function of the file /inventory/purchase_return_save. Executing a manipulation can lead to cro…

Remote | Cross-Site Scripting
May 10, 2026 May 10, 2026
May 10, 2026
May 10, 2026
6.5 MEDIUM
CVE-2026-8217 — Industrial Application Software IAS Canias ERP RMI Runtime.getRuntime.exec os command inj…

A security flaw has been discovered in Industrial Application Software IAS Canias ERP 8.03. Impacted is the function Runtime.getRuntime.exec of the component RMI Interface. Performing a manipulation …

Remote | Injection
May 10, 2026 May 10, 2026
May 10, 2026
May 10, 2026
7.5 HIGH
CVE-2026-8216 — Industrial Application Software IAS Canias ERP Java RMI Session Management iasServerRemot…

A vulnerability was identified in Industrial Application Software IAS Canias ERP 8.03. This issue affects the function iasServerRemoteInterface.doAction of the component Java RMI Session Management. …

Remote | Authentication
May 10, 2026 May 10, 2026
May 10, 2026
May 10, 2026
5.5 MEDIUM
CVE-2026-8215 — Industrial Application Software IAS Canias ERP RMI iasRequestFileEvent path traversal

A vulnerability was determined in Industrial Application Software IAS Canias ERP 8.03. This vulnerability affects the function iasRequestFileEvent of the component RMI Interface. This manipulation of…

Remote | Path Traversal
May 10, 2026 May 10, 2026
May 10, 2026
May 10, 2026
5.5 MEDIUM
CVE-2026-8214 — Industrial Application Software IAS Canias ERP RMI doAction improper authentication

A vulnerability was found in Industrial Application Software IAS Canias ERP 8.03. This affects the function doAction of the component RMI Interface. The manipulation of the argument sessionId results…

Remote | Authentication
May 10, 2026 May 10, 2026
May 10, 2026
May 10, 2026
5.3 MEDIUM
CVE-2026-8213 — OSGeo gdal Grid File GDapi.c GDSDfldsrch heap-based overflow

A vulnerability has been found in OSGeo gdal up to 3.13.0dev-4. Affected by this issue is the function GDSDfldsrch of the file frmts/hdf4/hdf-eos/GDapi.c of the component Grid File Handler. The manip…

| Memory Corruption
May 09, 2026 May 09, 2026
May 09, 2026
May 09, 2026
5.3 MEDIUM
CVE-2026-8212 — OSGeo gdal SWapi.c SWSDfldsrch heap-based overflow

A flaw has been found in OSGeo gdal up to 3.13.0dev-4. Affected by this vulnerability is the function SWSDfldsrch of the file frmts/hdf4/hdf-eos/SWapi.c. Executing a manipulation can lead to heap-bas…

| Memory Corruption
May 09, 2026 May 09, 2026
May 09, 2026
May 09, 2026
5.8 MEDIUM
CVE-2026-8211 — codelibs Fess JSP File AdminDesignAction.java update code injection

A vulnerability was detected in codelibs Fess up to 15.5.1. Affected by this issue is the function update of the file org/codelibs/fess/app/web/admin/design/AdminDesignAction.java of the component JS…

Remote | Injection
May 09, 2026 May 09, 2026
May 09, 2026
May 09, 2026
6.5 MEDIUM
CVE-2026-45184 — Kdenlive Proxy Parameter Injection Vulnerability

Kdenlive before 26.04.1 allows dangerous proxy parameters when an attacker-controlled project file is used.

| Misconfiguration
May 09, 2026 May 09, 2026
May 09, 2026
May 09, 2026
2.2 LOW
CVE-2026-45182 — GrapheneOS Quic VPN IP Disclosure

GrapheneOS before 2026050400 allows attackers to discover the real IP address of a VPN user as a consequence of a registerQuicConnectionClosePayload optimization, because an application can let syste…

| Information Disclosure
May 09, 2026 May 09, 2026
May 09, 2026
May 09, 2026
6.5 MEDIUM
CVE-2026-45181 — Hex-Rays IDA Pro Unrestricted Plugin Directory Access Vulnerability

Hex-Rays IDA Pro 9.2 and 9.3 before 9.3sp2 does not block Clang dependency-file generation (via argument injection), which allows attackers to place their code into a plugins directry if the victim u…

| Injection
May 09, 2026 May 09, 2026
May 09, 2026
May 09, 2026
5.3 MEDIUM
CVE-2026-8210 — aandrew-me tgpt Update helper.go helper.Update command injection

A security vulnerability has been detected in aandrew-me tgpt up to 2.11.1 on Linux/macOS. Affected by this vulnerability is the function helper.Update of the file helper.go of the component Update H…

| Injection
May 09, 2026 May 09, 2026
May 09, 2026
May 09, 2026
3.7 LOW
CVE-2026-8196 — JeecgBoot mLogin Endpoint LoginController.java authorization

A flaw has been found in JeecgBoot 3.9.1. The impacted element is an unknown function of the file jeecg-module-system/jeecg-system-biz/src/main/java/org/jeecg/modules/system/controller/LoginControlle…

Remote | Authorization
May 09, 2026 May 09, 2026
May 09, 2026
May 09, 2026
5.0 MEDIUM
CVE-2026-8195 — JeecgBoot SVG File CommonController.java cross site scripting

A vulnerability was detected in JeecgBoot up to 3.9.1. The affected element is an unknown function of the file jeecg-module-system/jeecg-system-biz/src/main/java/org/jeecg/modules/system/controller/C…

Remote | Cross-Site Scripting
May 09, 2026 May 09, 2026
May 09, 2026
May 09, 2026
5.0 MEDIUM
CVE-2026-8194 — osTicket Dispatcher class.dispatcher.php cross-site request forgery

A security vulnerability has been detected in osTicket up to 1.18.3. Impacted is an unknown function of the file include/class.dispatcher.php of the component Dispatcher. The manipulation of the argu…

Remote | Cross-Site Request Forgery
May 09, 2026 May 09, 2026
May 09, 2026
May 09, 2026
8.1 HIGH
CVE-2026-42606 — AzuraCast: Password Reset Poisoning via Untrusted X-Forwarded-Host Header Leads to Accoun…

AzuraCast is a self-hosted, all-in-one web radio management suite. Prior to version 0.23.6, the ApplyXForwarded middleware unconditionally trusts the client-supplied X-Forwarded-Host HTTP header with…

azuracast | Remote | Information Disclosure
May 09, 2026 May 09, 2026
May 09, 2026
May 09, 2026
8.8 HIGH
CVE-2026-42605 — AzuraCast: Path Traversal in `currentDirectory` Parameter Enables Remote Code Execution v…

AzuraCast is a self-hosted, all-in-one web radio management suite. Prior to version 0.23.6, the currentDirectory request parameter in the Flow.js media upload endpoint (POST /api/station/{station_id}…

azuracast | Remote | Path Traversal
May 09, 2026 May 09, 2026
May 09, 2026
May 09, 2026
9.3 CRITICAL
CVE-2026-42601 — ArchiveBox Vulnerable to RCE via unvalidated per-crawl config overrides in AddView

ArchiveBox is an open source self-hosted web archiving system. In versions 0.8.6rc0 and prior, the /add/ endpoint (AddView in core/views.py) accepts a config JSON field that gets merged into the craw…

archivebox | Remote | Injection
May 09, 2026 May 09, 2026
May 09, 2026
May 09, 2026
6.5 MEDIUM
CVE-2026-42576 — apko `DiscoverKeys` has a panic on non-rsa jwks key that causes crash during key discovery

apko allows users to build and publish OCI container images built from apk packages. Prior to version 1.2.7, DiscoverKeys in pkg/apk/apk/implementation.go unconditionally type-asserts JWKS keys as *r…

apko | Remote | Misconfiguration
May 09, 2026 May 09, 2026
May 09, 2026
May 09, 2026
Showing 20 of 5573 Results