Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.9 MEDIUM
CVE-2026-46722 — XML External Entity Injection in extension "Faceted Search" (ke_search)

The OOXML parsing of the file indexer does not disable external entity resolution. A crafted xlsx or pptx document placed in an indexed directory can cause local files to be read or outbound HTTP req…

Remote | XML External Entity
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
6.9 MEDIUM
CVE-2026-46721 — Broken Access Control in extension "Frontend User Registration" (sf_register)

The create and edit flows do not restrict which user properties may be submitted and do not enforce access control on the frontend user group assignment. As a result, an attacker can assign an arbitr…

Remote | Authorization
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
0.0 NA
CVE-2026-46586 — Apache OFBiz: Improper Validation in traverseContent Service Enables Authenticated Groovy…

Improper Control of Generation of Code ('Code Injection'), Improper Neutralization of Directives in Dynamically Evaluated Code ('Eval Injection') vulnerability in Apache OFBiz. This issue affects Ap…

| Injection
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
0.0 NA
CVE-2026-45434 — Apache OFBiz: Authentication Bypass via Password-Change Logic Flaw Leading to RCE

Improper Authentication vulnerability in Apache OFBiz via Password-Change Logic Flaw Leading to Remote Code Execution This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgr…

| Authentication
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
0.0 NA
CVE-2026-45187 — Apache OFBiz: Improper Authorization in Scheduled Job Creation Allows Low-Privileged User…

Improper Authorization vulnerability in Apache OFBiz Webtools. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue.

| Authorization
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
0.0 NA
CVE-2026-41919 — Apache OFBiz: Authentication Bypass due to Improper Neutralization of LDAP Special Elemen…

Improper Neutralization of Special Elements used in an LDAP Query ('LDAP Injection') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrad…

| Injection
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
0.0 NA
CVE-2026-35086 — Apache OFBiz: Authenticated Remote Code Execution via Unsafe Template Expansion in email …

Improper Control of Generation of Code ('Code Injection') vulnerability in email services of Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to vers…

| Injection
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
0.0 NA
CVE-2026-31986 — Apache OFBiz: Unauthenticated RCE via Default JWT Signing Key and Widget Template Injecti…

Use of Hard-coded Cryptographic Key vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue.

| Cryptography
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
0.0 NA
CVE-2026-31910 — Apache OFBiz: Improper Input Validation in UI Factory Classes Leads to SSRF and Blind Fil…

Server-Side Request Forgery (SSRF) vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue.

| Server-Side Request Forgery
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
0.0 NA
CVE-2026-31909 — Apache OFBiz: Unauthenticated Shipment Label Image Disclosure

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, whi…

| Information Disclosure
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
0.0 NA
CVE-2026-31906 — Apache OFBiz: Reflected XSS via Improper HTML Attribute Escaping in Layered-Modal Dialog …

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrad…

| Cross-Site Scripting
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
0.0 NA
CVE-2026-31388 — Apache OFBiz: Cross-Tenant Data Exposure via Program Export Feature

Improper Access Control vulnerability in Apache OFBiz in multi-tenant deployments. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixe…

| Authorization
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
0.0 NA
CVE-2026-31387 — Apache OFBiz: Cookie Manipulation Allows Authenticated JWT Forgery and Account Impersonat…

Improper Authentication vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue.

| Authentication
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
0.0 NA
CVE-2026-31380 — Apache OFBiz: FreeMarker SSTI via Duplicate Parameter Sanitization Bypass

Improper Neutralization of Special Elements used in an Expression Language Statement ('Expression Language Injection') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06…

| Injection
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
0.0 NA
CVE-2026-31379 — Apache OFBiz: Path Traversal and File Upload Validation Bypass Leading to Arbitrary File …

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting'), Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Improper Control of Generation of…

| Cross-Site Scripting
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
0.0 NA
CVE-2026-31378 — Apache OFBiz: JSON Attribute Override and URL Allowlist Bypass Leads to Remote Code Execu…

Improper Input Validation vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.09.06, which fixes the issue.

| Injection
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
9.6 CRITICAL
CVE-2026-2611 — Improper Origin Validation in mlflow/mlflow

In MLflow version 3.9.0, the MLflow Assistant feature introduced improper origin validation in its /ajax-api endpoints. This vulnerability allows a remote attacker to exploit cross-origin requests fr…

Remote | Misconfiguration
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
0.0 NA
CVE-2026-29226 — Apache OFBiz: Low-Privilege SSRF in Content Component

Server-Side Request Forgery (SSRF) vulnerability in Apache OFBiz via Content component operations. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24.0…

| Server-Side Request Forgery
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
0.0 NA
CVE-2026-29220 — Apache OFBiz: Low-Privilege LFI in Content Component

Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to v…

| Path Traversal
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
0.0 NA
CVE-2026-29207 — Apache OFBiz: Low-Privilege SSTI Leading to RCE in the Content Component

Improper Neutralization of Special Elements Used in a Template Engine vulnerability in Apache OFBiz. This issue affects Apache OFBiz: before 24.09.06. Users are recommended to upgrade to version 24…

| Injection
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
Showing 20 of 6281 Results