Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.8 HIGH
CVE-2026-41526 — KDE KCoreAddons Shell Injection Vulnerability

In KDE KCoreAddons before 6.25, KShell::quoteArgs is intended to safely quote arguments so that they can be passed to a shell command. This parsing does not adequately handle metacharacters, leading …

kcoreaddons | Injection
Apr 28, 2026 May 05, 2026
Apr 28, 2026
May 05, 2026
6.5 MEDIUM
CVE-2026-41525 — KDE Dolphin Flatpak Sandbox Escalation Vulnerability

KDE Dolphin before 25.12.3 allows applications in a Flatpak (or with AppArmor confinement) to open folders outside of the application sandbox without additional scrutiny. Dolphin's implementation of …

| Path Traversal
Apr 28, 2026 May 19, 2026
Apr 28, 2026
May 19, 2026
5.9 MEDIUM
CVE-2026-40966 — VectorStoreChatMemoryAdvisor conversation scoping can lead to cross-tenant memory exfiltr…

In Spring AI, an attacker can bypass conversation isolation and exfiltrate sensitive memory from other users’ chat histories, including secrets and credentials, by injecting filter logic through conv…

spring_ai | Remote | Injection
Apr 28, 2026 Apr 29, 2026
Apr 28, 2026
Apr 29, 2026
8.7 HIGH
CVE-2024-54013 — Authentication Bypass

Penetration Testing engineers at Amazon have identified a security flaw related to request handling in the web server component that could, under certain conditions, lead to unintended access to prot…

| Authorization
Apr 28, 2026 Apr 28, 2026
Apr 28, 2026
Apr 28, 2026
8.5 HIGH
CVE-2024-54012 — Command Injection

Penetration Testing engineers at Amazon discovered a vulnerability where the camera system failed to properly validate input, allowing specially crafted requests containing malicious commands to be e…

| Injection
Apr 28, 2026 Apr 28, 2026
Apr 28, 2026
Apr 28, 2026
5.3 MEDIUM
CVE-2024-54011 — Missing Error/Exception Handling

Penetration Testing engineers at Amazon have discovered a flaw where the camera system fails to properly handle data supplied in certain requests, causing a service disruption. The manufacturer has r…

Remote | Denial of Service
Apr 28, 2026 Apr 28, 2026
Apr 28, 2026
Apr 28, 2026
Showing 20 of 6566 Results