Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-28846 — Apple iOS Buffer Overflow Vulnerability

A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26…

macos iphone_os tvos watchos ipados visionos | Memory Corruption
May 11, 2026 May 12, 2026
May 11, 2026
May 12, 2026
7.8 HIGH
CVE-2026-28840 — Apple macOS Root Privilege Escalation Vulnerability

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.4. An app may be able to gain root privileges.

macos | Authorization
May 11, 2026 May 12, 2026
May 11, 2026
May 12, 2026
0.0 NA
CVE-2026-28830 — Apple macOS Sensitive Data Access Race Condition

A race condition was addressed with additional validation. This issue is fixed in macOS Tahoe 26.4. An app may be able to access sensitive user data.

macos | Race Condition
May 11, 2026 May 12, 2026
May 11, 2026
May 12, 2026
0.0 NA
CVE-2026-28819 — iOS Kernel OOB Write Vulnerability

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5. An app may …

macos iphone_os ipados | Memory Corruption
May 11, 2026 May 12, 2026
May 11, 2026
May 12, 2026
0.0 NA
CVE-2026-20696 — "Apple macOS Tahoe Authorization Bypass"

An authorization issue was addressed with improved state management. This issue is fixed in macOS Tahoe 26.4. An app may be able to access sensitive user data.

macos | Authorization
May 11, 2026 May 12, 2026
May 11, 2026
May 12, 2026
7.5 HIGH
CVE-2026-8321 — inkeep agents runAuth Middleware runAuth.ts createDevContext authentication bypass

A vulnerability was detected in inkeep agents 0.58.14. This vulnerability affects the function createDevContext of the file agents-api/src/middleware/runAuth.ts of the component runAuth Middleware. P…

Remote | Authentication
May 11, 2026 May 12, 2026
May 11, 2026
May 12, 2026
5.8 MEDIUM
CVE-2026-8320 — jishenghua jshERP updatePlatformConfigByKey Endpoint UserService.java getUserByWeixinCode…

A security vulnerability has been detected in jishenghua jshERP up to 3.6. This affects the function getUserByWeixinCode of the file jshERP-boot/src/main/java/com/jsh/erp/service/UserService.java of …

jsherp | Remote | Server-Side Request Forgery
May 11, 2026 May 12, 2026
May 11, 2026
May 12, 2026
5.5 MEDIUM
CVE-2026-8319 — aiwaves-cn agents cheshire_cat_core stray_cat.py recall_relevant_memories_to_working_memo…

A weakness has been identified in aiwaves-cn agents up to e8c4e3c2d19739d3dff59e577d1c97090cc15f59. Affected by this issue is the function recall_relevant_memories_to_working_memory of the file core/…

Remote | Denial of Service
May 11, 2026 May 12, 2026
May 11, 2026
May 12, 2026
0.0 NA
CVE-2026-6146 — Amazon::Credentials versions through 1.2.0 for Perl uses rand to generate encryption keys

Amazon::Credentials versions through 1.2.0 for Perl uses rand to generate encryption keys. Amazon::Credentials stores credentials in an obfuscated form to prevent access to the secrets from a data d…

| Cryptography
May 11, 2026 May 12, 2026
May 11, 2026
May 12, 2026
6.8 MEDIUM
CVE-2026-45026 — WeGIA: Stored XSS in html/atendido/processo_aceitacao.php

WeGIA is a web manager for charitable institutions. In versions prior to 3.7.3, a Stored Cross-Site Scripting (XSS) vulnerability allows an authenticated user to inject malicious JavaScript into the …

wegia | Remote | Cross-Site Scripting
May 11, 2026 May 12, 2026
May 11, 2026
May 12, 2026
6.8 MEDIUM
CVE-2026-45025 — WeGIA: Stored XSS in html/atendido/etapa_processo.php

WeGIA is a web manager for charitable institutions. In versions prior to 3.7.3, a Stored Cross-Site Scripting (XSS) vulnerability allows an authenticated user to inject malicious JavaScript into the …

wegia | Remote | Cross-Site Scripting
May 11, 2026 May 11, 2026
May 11, 2026
May 11, 2026
4.5 MEDIUM
CVE-2026-42887 — Audiobookshelf: Stored Cross-Site Scripting in Login Page Custom Message

Audiobookshelf is a self-hosted audiobook and podcast server. Prior to 2.33.0, a stored cross-site scripting (XSS) vulnerability exists in the Login Page due to improper sanitization of the authLogin…

audiobookshelf | Remote | Cross-Site Scripting
May 11, 2026 May 12, 2026
May 11, 2026
May 12, 2026
4.9 MEDIUM
CVE-2026-42886 — Audiobookshelf: Memory amplification DoS via oversized compressed details entry in backup…

Audiobookshelf is a self-hosted audiobook and podcast server. Prior to 2.32.2, the POST /api/backups/upload endpoint decompresses the details entry from an uploaded .audiobookshelf ZIP file entirely …

audiobookshelf | Remote | Denial of Service
May 11, 2026 May 12, 2026
May 11, 2026
May 12, 2026
4.3 MEDIUM
CVE-2026-42885 — Audiobookshelf: Path prefix bypass in filesystem existence check leaks out-of-scope file …

Audiobookshelf is a self-hosted audiobook and podcast server. Prior to 2.32.2, the POST /api/filesystem/pathexists endpoint uses String.startsWith() to validate that a resolved file path is within a …

audiobookshelf | Remote | Path Traversal
May 11, 2026 May 12, 2026
May 11, 2026
May 12, 2026
4.3 MEDIUM
CVE-2026-42884 — Audiobookshelf: Collection endpoints bypass library access controls exposing restricted l…

Audiobookshelf is a self-hosted audiobook and podcast server. Prior to 2.32.2, the GET /api/collections and GET /api/collections/:id endpoints return collections from all libraries without checking w…

audiobookshelf | Remote | Authorization
May 11, 2026 May 12, 2026
May 11, 2026
May 12, 2026
6.5 MEDIUM
CVE-2026-42883 — Audiobookshelf: Cross-library file exfiltration via unscoped bulk download endpoint

Audiobookshelf is a self-hosted audiobook and podcast server. Prior to 2.32.2, the GET /api/libraries/:id/download endpoint validates that the requesting user has access to the library specified in t…

audiobookshelf | Remote | Authorization
May 11, 2026 May 12, 2026
May 11, 2026
May 12, 2026
9.4 CRITICAL
CVE-2026-42882 — oxyno-zeta/s3-proxy: Security Issues in Resource Path Matching

oxyno-zeta/s3-proxy is an aws s3 proxy written in go. Prior to 5.0.0, s3-proxy contains an authentication bypass caused by inconsistent URL path interpretation between the authentication middleware a…

s3-proxy | Remote | Authentication
May 11, 2026 May 11, 2026
May 11, 2026
May 11, 2026
4.9 MEDIUM
CVE-2026-42876 — External Secrets Operator: Priviledge escalation with secret overwriting

External Secrets Operator reads information from a third-party service and automatically injects the values as Kubernetes Secrets. Prior to 2.4.1, a user who only has permission to create ExternalSec…

external_secrets_operator | Remote | Authentication
May 11, 2026 May 11, 2026
May 11, 2026
May 11, 2026
5.3 MEDIUM
CVE-2026-42875 — External Secrets Operator: Namespace Isolation Bypass in CAProvider ConfigMap Resolution …

External Secrets Operator reads information from a third-party service and automatically injects the values as Kubernetes Secrets. Prior to 2.4.0, Namespaced SecretStore resources that used CAProvide…

external_secrets_operator | Remote | Misconfiguration
May 11, 2026 May 11, 2026
May 11, 2026
May 11, 2026
3.7 LOW
CVE-2026-42874 — Microdot: HTTP response splitting in Response.set_cookie()

Microdot is a minimalistic Python web framework. Prior to 2.6.1, the Response.set_cookie() method does not sanitize its string arguments, and in particular will not detect the presence of the \r\n se…

Remote | Injection
May 11, 2026 May 11, 2026
May 11, 2026
May 11, 2026
Showing 20 of 6117 Results