Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2025-69599 — RayVentory Scan Engine Path Environment Variable Privilege Escalation Vulnerability

RayVentory Scan Engine through 12.6 Update 8 allows attackers to gain privileges if they control the value of the PATH environment variable. NOTE: this is disputed because ability of an attacker to c…

| Misconfiguration
May 08, 2026 May 08, 2026
May 08, 2026
May 08, 2026
7.3 HIGH
CVE-2025-67888 — Softaculous SitePad OS Command Injection Vulnerability

An issue was discovered in Control Web Panel (CWP) before 0.9.8.1209. User input passed via the "key" GET parameter to /admin/index.php (when the "api" parameter is set) is not properly sanitized bef…

Remote | Injection
May 08, 2026 May 08, 2026
May 08, 2026
May 08, 2026
0.0 NA
CVE-2025-67887 — Bitrix Remote Code Execution Vulnerability

1C-Bitrix through 25.100.500 allows Remote Code Execution because an actor with SOURCE/WRITE permissions for the Translate Module can upload and execute code by sending a PHP file and a .htaccess fil…

| Authentication
May 08, 2026 May 08, 2026
May 08, 2026
May 08, 2026
6.3 MEDIUM
CVE-2025-67886 — Bitrix24 Remote Code Execution via Unrestricted File Upload

Bitrix24 through 25.100.300 allows Remote Code Execution because an actor with SOURCE/WRITE permissions for the Translate Module can upload and execute code by sending a PHP file and a .htaccess file…

Remote | Misconfiguration
May 08, 2026 May 08, 2026
May 08, 2026
May 08, 2026
7.3 HIGH
CVE-2025-55449 — AstrBotDevs AstrBot Critical JWT Private Key Hardcoding Vulnerability

AstrBotDevs AstrBot 3.5.15 has Advanced_System_for_Text_Response_and_Bot_Operations_Tool as the hardcoded private key used to sign a JWT.

astrbot | Remote | Cryptography
May 08, 2026 May 08, 2026
May 08, 2026
May 08, 2026
9.8 CRITICAL
CVE-2023-46453 — GL.iNet SQL Injection Regular Expression Authentication Bypass

Certain GL.iNet devices with 4.x firmware allow authentication bypass (resulting in administrative control of the device) via a username that is both a valid SQL statement and a valid regular express…

Remote | Authentication
May 08, 2026 May 08, 2026
May 08, 2026
May 08, 2026
7.3 HIGH
CVE-2024-53326 — LINQPad Deserialization Remote Code Execution

LINQPad before 5.52.01 Pro edition is vulnerable to Unsafe Deserialization in LINQPad.AutoRefManager::PopulateFromCache(), leading to code execution.

| Misconfiguration
May 08, 2026 May 08, 2026
May 08, 2026
May 08, 2026
9.1 CRITICAL
CVE-2024-51092 — LibreNMS OS Command Injection Vulnerability

LibreNMS before 24.10.0 allows a remote attacker to execute arbitrary code via OS command injection involving AboutController.php's index(), SettingsController.php's update(), and PollDevice.php's in…

librenms | Remote | Injection
May 08, 2026 May 08, 2026
May 08, 2026
May 08, 2026
7.5 HIGH
CVE-2024-46508 — Yeti-Platform JWT Token Forgery Vulnerability

yeti-platform yeti before 2.1.12 allows attackers to generate valid JWT tokens is the secret is not changed (by setting YETI_AUTH_SECRET_KEY to a value other than SECRET).

yeti | Remote | Authentication
May 08, 2026 May 08, 2026
May 08, 2026
May 08, 2026
7.3 HIGH
CVE-2024-46507 — Yeti-Platform SSTI Code Execution

A SSTI (server side template injection) vulnerability in the custom template export function in yeti-platform yeti before 2.1.12 allows attackers to execute code on the application server.

yeti | Remote | Injection
May 08, 2026 May 08, 2026
May 08, 2026
May 08, 2026
7.3 HIGH
CVE-2024-45257 — BYOB Command Injection Vulnerability

A Command Injection issue in the payload build page in BYOB (Build Your Own Botnet) 2.0 allows attackers to execute arbitrary commands on the server via a crafted build parameter. This occurs in free…

Remote | Injection
May 08, 2026 May 08, 2026
May 08, 2026
May 08, 2026
5.4 MEDIUM
CVE-2024-33724 — SOPlanning Cross Site Scripting (XSS)

SOPlanning 1.52.00 is vulnerable to Cross Site Scripting (XSS) via the groupe_id parameter to process/groupe_save.php.

Remote | Cross-Site Scripting
May 08, 2026 May 08, 2026
May 08, 2026
May 08, 2026
6.3 MEDIUM
CVE-2024-33722 — SOPlanning SQL Injection

SOPlanning 1.52.00 is vulnerable to SQL Injection by an authenticated user via projets.php with statut[].

Remote | Injection
May 08, 2026 May 08, 2026
May 08, 2026
May 08, 2026
7.3 HIGH
CVE-2024-33288 — "PHP Prison Management System SQL Injection"

Prison Management System Using PHP v1.0 was discovered to contain a SQL injection vulnerability via the username on the Admin login page.

Remote | Injection
May 08, 2026 May 08, 2026
May 08, 2026
May 08, 2026
6.3 MEDIUM
CVE-2024-30167 — Atlona AT-OME-MS42 Remote Command Execution Vulnerability

/cgi-bin/time.cgi in Atlona AT-OME-MS42 Matrix Switcher 1.1.2 allow remote authenticated users to execute arbitrary commands as root via a POST request that carries a serverName parameter.

Remote | Injection
May 08, 2026 May 08, 2026
May 08, 2026
May 08, 2026
7.5 HIGH
CVE-2024-27686 — Mikrotik RouterOS SMB Denial of Service

Mikrotik RouterOS (x86) 6.40.5 through 6.49.10 (fixed in 7) allows a remote attacker to cause a denial of service (device crash) via crafted packet data to the SMB service on TCP port 445.

Remote | Denial of Service
May 08, 2026 May 08, 2026
May 08, 2026
May 08, 2026
5.3 MEDIUM
CVE-2023-47268 — PrusaSlicer Code Injection Vulnerability

In libslic3r/GCode/PostProcessor.cpp in Prusa PrusaSlicer through 2.6.1, a crafted 3mf project file can execute arbitrary code on a host where the project is sliced and G-code exported.

| Memory Corruption
May 08, 2026 May 08, 2026
May 08, 2026
May 08, 2026
7.8 HIGH
CVE-2026-8148 — NAVER MYBOX Explorer Windows Privilege Escalation Vulnerability

NAVER MYBOX Explorer for Windows before 3.0.11.160 allows a local attacker to escalate privileges to NT AUTHORITY\SYSTEM via registry manipulation due to improper privilege checks.

mybox | Authorization
May 08, 2026 May 08, 2026
May 08, 2026
May 08, 2026
9.0 HIGH
CVE-2026-8138 — Tenda CX12L SetPptpServerCfg” formSetPPTPServer stack-based overflow

A vulnerability was found in Tenda CX12L 16.03.53.12. This issue affects the function formSetPPTPServer of the file /goform/SetPptpServerCfg”. The manipulation results in stack-based buffer overflow.…

cx12l_firmware | Remote | Memory Corruption
May 08, 2026 May 08, 2026
May 08, 2026
May 08, 2026
9.0 HIGH
CVE-2026-8137 — Totolink X5000R formDdns sub_458E40 buffer overflow

A vulnerability has been found in Totolink X5000R 9.1.0u.6369_B20230113. This vulnerability affects the function sub_458E40 of the file /boafrm/formDdns. The manipulation of the argument submit-url l…

x5000r_firmware | Remote | Memory Corruption
May 08, 2026 May 08, 2026
May 08, 2026
May 08, 2026
Showing 20 of 5788 Results