Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.5 HIGH
CVE-2026-42497 — Archive::Tar versions before 3.08 for Perl extract hardlinks to attacker controlled paths…

Archive::Tar versions before 3.08 for Perl extract hardlinks to attacker controlled paths outside the extraction directory. _make_special_file() passes the tar header's linkname to link() without va…

\ | Remote | Path Traversal
May 26, 2026 May 28, 2026
May 26, 2026
May 28, 2026
9.1 CRITICAL
CVE-2026-42496 — Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targ…

Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory. _make_special_file() passes the tar header's linkname to symlink() with…

\ | Remote | Path Traversal
May 26, 2026 May 28, 2026
May 26, 2026
May 28, 2026
1.8 LOW
CVE-2025-71310 — Backdrop CMS YouTube GDPR Cookies Module XSS

The GDPR cookies module for Backdrop CMS (before 1.x-1.3.5) doesn't sufficiently protect visitors from Cross Site Scripting (XSS) if a malicious value has been provided for the optional 'Info conte…

Remote | Cross-Site Scripting
May 26, 2026 May 26, 2026
May 26, 2026
May 26, 2026
7.5 HIGH
CVE-2026-9517 — hemant6488 CodeIgniter-StudentManagementSystem Student Management addStudentView access c…

A vulnerability was determined in hemant6488 CodeIgniter-StudentManagementSystem. The affected element is an unknown function of the file /index.php/students/addStudentView of the component Student M…

codeigniter-studentmanagementsystem | Remote | Authorization
May 26, 2026 May 26, 2026
May 26, 2026
May 26, 2026
6.5 MEDIUM
CVE-2026-9515 — Totolink CA750-PoE Setting cstecgi.cgi setUnloadUserData os command injection

A vulnerability was detected in Totolink CA750-PoE 6.2c.510. The affected element is the function setUnloadUserData of the file /cgi-bin/cstecgi.cgi of the component Setting Handler. The manipulation…

ca750-poe | Remote | Injection
May 26, 2026 May 26, 2026
May 26, 2026
May 26, 2026
9.8 CRITICAL
CVE-2026-8376 — Perl versions through 5.43.10 have a heap buffer overflow when compiling regular expressi…

Perl versions through 5.43.10 have a heap buffer overflow when compiling regular expressions with a repeated fixed string on 32-bit builds. Perl_study_chunk in regcomp_study.c checked the size of th…

perl | Remote | Memory Corruption
May 26, 2026 May 27, 2026
May 26, 2026
May 27, 2026
Showing 20 of 8066 Results