Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.3 MEDIUM
CVE-2026-33052 — MantisBT: Authorization Bypass in Global Profile Creation

Mantis Bug Tracker (MantisBT) is an open source issue tracker. Versions 2.28.0 and 2.28.1 allow a low-privileged authenticated user assigned the "add_profile_threshold" permission to create a global …

mantisbt | Remote | Authorization
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
7.3 HIGH
CVE-2026-32323 — Mullvad VPN for macOS: Local Privilege Escalation via unverified bundle path in installer

Mullvad VPN is a VPN client app for desktop and mobile. When using macOS with versions 2026.1 and below, Mullvad VPN may allow local privilege escalation during installation or upgrade. The installer…

| Authorization
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
5.1 MEDIUM
CVE-2026-32312 — GLPI: Unauthorized export of form structure

GLPI is a free asset and IT management software package. In versions 11.0.0 through 11.0.6, an authenticated user with forms READ permission can export the structure of unauthorized forms. This issue…

Remote | Authorization
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
5.3 MEDIUM
CVE-2026-32244 — Discourse: Cached outdated summaries can leak removed content

Discourse is an open-source discussion platform. In versions prior to 2026.1.4, 2026.3.1, 2026.4.1 and 2026.5.0-latest.1, outdated cached AI summaries can leak removed content to anonymous and unpriv…

Remote | Information Disclosure
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
7.1 HIGH
CVE-2026-30950 — AutoGPT has Authenticated Session Hijacking via IDOR

AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Versions 0.6.36 through 0.6.50 are vulnerable to Authenticated Session Hijac…

Remote | Authentication
May 18, 2026 May 18, 2026
May 18, 2026
May 18, 2026
3.9 LOW
CVE-2026-27964 — FacturaScripts: Reflected Cross-Site Scripting (XSS) via Cookie Manipulation

FacturaScripts is an open source accounting and invoicing software. Versions 2025.7 and prior contain a Reflected Cross-Site Scripting (XSS) vulnerability through the fsNick cookie parameter. The app…

facturascripts | Cross-Site Scripting
May 18, 2026 May 18, 2026
May 18, 2026
May 18, 2026
6.5 MEDIUM
CVE-2026-27892 — FacturaScripts: Unstripped Image Metadata (EXIF) Leakage via Library Module File Upload/D…

FacturaScripts is an open source accounting and invoicing software. In versions prior to 2026, the Library module stores and serves uploaded images byte-for-byte, without stripping EXIF/XMP/IPTC meta…

facturascripts | Remote | Information Disclosure
May 18, 2026 May 18, 2026
May 18, 2026
May 18, 2026
7.2 HIGH
CVE-2026-27891 — Remote Code Execution (RCE) via Zip Slip in Plugin Upload Mechanism

FacturaScripts is an open source accounting and invoicing software. Versions 2026 and below contain a critical vulnerability in the Plugins::add() function. The system fails to properly validate the …

facturascripts | Remote | Path Traversal
May 18, 2026 May 18, 2026
May 18, 2026
May 18, 2026
6.5 MEDIUM
CVE-2026-27737 — BigBlueButton has Stored XSS in bbb-playback replay

BigBlueButton is an open-source virtual classroom. In versions prior to 3.0.19, the recording playback (presentation format) was not sanitizing user's input in public chat. This allowed for a malicio…

Remote | Cross-Site Scripting
May 18, 2026 May 18, 2026
May 18, 2026
May 18, 2026
8.6 HIGH
CVE-2026-8851 — SOGo 5.12.7 SQL Injection via addUserInAcls endpoint

SOGo 5.12.7 contains a SQL injection vulnerability in the Access Control List management functionality that allows authenticated users to extract arbitrary data from the database by injecting SQL sub…

Remote | Injection
May 18, 2026 May 18, 2026
May 18, 2026
May 18, 2026
9.8 CRITICAL
CVE-2026-8838 — Remote Code Execution via eval() Injection in amazon-redshift-python-driver

Unsafe use of Python's eval() on server-received data in the vector_in() function in amazon-redshift-python-driver before 2.1.14 allows a rogue server or man-in-the-middle actor to execute arbitrary …

Remote | Injection
May 18, 2026 May 18, 2026
May 18, 2026
May 18, 2026
7.0 HIGH
CVE-2026-4137 — Incomplete Fix for CVE-2025-10279: Insecure Temporary Directory Permissions in mlflow/mlf…

In mlflow/mlflow versions prior to 3.11.0, the `get_or_create_nfs_tmp_dir()` function in `mlflow/utils/file_utils.py` creates temporary directories with world-writable permissions (0o777), and the `_…

| Misconfiguration
May 18, 2026 May 18, 2026
May 18, 2026
May 18, 2026
9.9 CRITICAL
CVE-2026-27130 — Dokploy has Command Injection in its Service Operations

Dokploy is a free, self-hostable Platform as a Service (PaaS). Versions 0.26.6 and below have OS command injection through the appName parameter. 3 chained issues cause this problem: inadequate input…

Remote | Injection
May 18, 2026 May 18, 2026
May 18, 2026
May 18, 2026
8.6 HIGH
CVE-2026-26978 — Free PBX backup: Deserialization of Untrusted Data in admin/modules/backup/Models/BackupS…

FreePBX is an open source IP PBX. In versions below 16.0.71 and 17.0.6, the backup module does not properly sanitize data during restore operations, potentially leading to compromise if the backup co…

Remote | Injection
May 18, 2026 May 18, 2026
May 18, 2026
May 18, 2026
9.8 CRITICAL
CVE-2026-25244 — WebdriverIO has Command Injection in the BrowserStack Service

WebdriverIO is a test automation framework for unit, e2e and component testing using WebDriver, WebDriver BiDi and Appium. Versions below 9.24.0 contain a command injection vulnerability leading to r…

Remote | Injection
May 18, 2026 May 18, 2026
May 18, 2026
May 18, 2026
8.2 HIGH
CVE-2026-22810 — Joplin: Path traversal in OneNote importer allows overwriting arbitrary files

Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Versions prior to 3.5.7 contain a path traversal vulnerability in the importer which allows o…

| Path Traversal
May 18, 2026 May 18, 2026
May 18, 2026
May 18, 2026
7.8 HIGH
CVE-2026-47092 — Claude HUD 0.0.12 Arbitrary Command Execution via COMSPEC Environment Variable

Claude HUD through 0.0.12, patched in commit 234d9aa, contains a command injection vulnerability that allows local attackers to execute arbitrary commands by manipulating the COMSPEC environment vari…

| Injection
May 18, 2026 May 18, 2026
May 18, 2026
May 18, 2026
4.8 MEDIUM
CVE-2026-47091 — Claude HUD 0.0.12 Path Traversal via transcript_path

Claude HUD through 0.0.12, patched in commit 234d9aa, contains a path traversal vulnerability that allows attackers to read arbitrary files by supplying an unvalidated transcript_path value via stdin…

| Path Traversal
May 18, 2026 May 18, 2026
May 18, 2026
May 18, 2026
4.6 MEDIUM
CVE-2026-47090 — Claude HUD 0.0.12 Terminal Injection via OSC 8 Hyperlinks

Claude HUD through 0.0.12, patched in commit 234d9aa, constructs OSC 8 terminal hyperlink escape sequences using raw cwd and branchUrl values without stripping control characters or encoding embedded…

| Misconfiguration
May 18, 2026 May 18, 2026
May 18, 2026
May 18, 2026
6.8 MEDIUM
CVE-2026-45246 — Summarize < 0.15.1 Insecure File Permissions Information Disclosure

Summarize prior to 0.15.1 contains an insecure file permission vulnerability in the refresh-free configuration rewrite path that allows local users to read sensitive credentials by exploiting default…

summarize | Misconfiguration
May 18, 2026 May 19, 2026
May 18, 2026
May 19, 2026
Showing 20 of 6267 Results