Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.2 MEDIUM
CVE-2026-28897 — Apple iOS/iPadOS/ macOS/tvOS/watchOS/visionOS Buffer Overflow Vulnerability

A buffer overflow was addressed with improved input validation. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 2…

macos iphone_os tvos watchos ipados visionos | Memory Corruption
May 11, 2026 May 12, 2026
May 11, 2026
May 12, 2026
7.5 HIGH
CVE-2026-28883 — Apple iOS Use-After-Free Vulnerability in Processing Malicious Web Content

A use-after-free issue was addressed with improved memory management. This issue is fixed in iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Processing maliciously…

macos iphone_os tvos watchos ipados visionos | Remote | Memory Corruption
May 11, 2026 May 12, 2026
May 11, 2026
May 12, 2026
0.0 NA
CVE-2026-28873 — Apple iOS App Privacy Report Logging Bypass

This issue was addressed with additional entitlement checks. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.4 and iPadOS 26.4. An app may be able to circumvent App Privacy Report logging.

iphone_os ipados | Authorization
May 11, 2026 May 12, 2026
May 11, 2026
May 12, 2026
0.0 NA
CVE-2026-28872 — Apple iOS and iPadOS Remote Denial-of-Service Vulnerability

A resource exhaustion issue was addressed with improved input validation. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.4 and iPadOS 26.4. A remote attacker may be able to cause a denia…

iphone_os ipados | Denial of Service
May 11, 2026 May 12, 2026
May 11, 2026
May 12, 2026
7.5 HIGH
CVE-2026-28860 — Apple Keychain Key Modification Vulnerability (Local)

The issue was addressed with improved input validation. This issue is fixed in iOS 18.7.7 and iPadOS 18.7.7, iOS 26.4 and iPadOS 26.4, macOS Sequoia 15.7.5, macOS Sonoma 14.8.5, macOS Tahoe 26.4, tvO…

macos iphone_os tvos watchos ipados visionos | Remote | Information Disclosure
May 11, 2026 May 12, 2026
May 11, 2026
May 12, 2026
7.5 HIGH
CVE-2026-28848 — Apple macOS Buffer Overflow

A buffer overflow was addressed with improved bounds checking. This issue is fixed in macOS Sequoia 15.7.7, macOS Tahoe 26.5. A remote attacker may be able to cause unexpected system termination.

macos | Remote | Memory Corruption
May 11, 2026 May 12, 2026
May 11, 2026
May 12, 2026
0.0 NA
CVE-2026-28847 — Apple WebKit Unexpected Process Crash Vulnerability

The issue was addressed with improved memory handling. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Tahoe 26.5, tvOS 26.5, visionOS 26.5, watchOS 26.5. Process…

macos iphone_os tvos watchos ipados visionos | Memory Corruption
May 11, 2026 May 12, 2026
May 11, 2026
May 12, 2026
7.5 HIGH
CVE-2026-28846 — Apple iOS Buffer Overflow Vulnerability

A buffer overflow was addressed with improved bounds checking. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, iOS 26.5 and iPadOS 26.5, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26…

macos iphone_os tvos watchos ipados visionos | Remote | Memory Corruption
May 11, 2026 May 12, 2026
May 11, 2026
May 12, 2026
7.8 HIGH
CVE-2026-28840 — Apple macOS Root Privilege Escalation Vulnerability

A permissions issue was addressed with additional restrictions. This issue is fixed in macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.4. An app may be able to gain root privileges.

macos | Authorization
May 11, 2026 May 12, 2026
May 11, 2026
May 12, 2026
0.0 NA
CVE-2026-28830 — Apple macOS Sensitive Data Access Race Condition

A race condition was addressed with additional validation. This issue is fixed in macOS Tahoe 26.4. An app may be able to access sensitive user data.

macos | Race Condition
May 11, 2026 May 12, 2026
May 11, 2026
May 12, 2026
5.4 MEDIUM
CVE-2026-28819 — iOS Kernel OOB Write Vulnerability

An out-of-bounds write issue was addressed with improved bounds checking. This issue is fixed in iOS 18.7.9 and iPadOS 18.7.9, macOS Sequoia 15.7.7, macOS Sonoma 14.8.7, macOS Tahoe 26.5. An app may …

macos iphone_os ipados | Remote | Memory Corruption
May 11, 2026 May 12, 2026
May 11, 2026
May 12, 2026
0.0 NA
CVE-2026-20696 — "Apple macOS Tahoe Authorization Bypass"

An authorization issue was addressed with improved state management. This issue is fixed in macOS Tahoe 26.4. An app may be able to access sensitive user data.

macos | Authorization
May 11, 2026 May 12, 2026
May 11, 2026
May 12, 2026
7.5 HIGH
CVE-2026-8321 — inkeep agents runAuth Middleware runAuth.ts createDevContext authentication bypass

A vulnerability was detected in inkeep agents 0.58.14. This vulnerability affects the function createDevContext of the file agents-api/src/middleware/runAuth.ts of the component runAuth Middleware. P…

Remote | Authentication
May 11, 2026 May 12, 2026
May 11, 2026
May 12, 2026
5.8 MEDIUM
CVE-2026-8320 — jishenghua jshERP updatePlatformConfigByKey Endpoint UserService.java getUserByWeixinCode…

A security vulnerability has been detected in jishenghua jshERP up to 3.6. This affects the function getUserByWeixinCode of the file jshERP-boot/src/main/java/com/jsh/erp/service/UserService.java of …

jsherp | Remote | Server-Side Request Forgery
May 11, 2026 May 12, 2026
May 11, 2026
May 12, 2026
5.5 MEDIUM
CVE-2026-8319 — aiwaves-cn agents cheshire_cat_core stray_cat.py recall_relevant_memories_to_working_memo…

A weakness has been identified in aiwaves-cn agents up to e8c4e3c2d19739d3dff59e577d1c97090cc15f59. Affected by this issue is the function recall_relevant_memories_to_working_memory of the file core/…

Remote | Denial of Service
May 11, 2026 May 12, 2026
May 11, 2026
May 12, 2026
0.0 NA
CVE-2026-6146 — Amazon::Credentials versions through 1.2.0 for Perl uses rand to generate encryption keys

Amazon::Credentials versions through 1.2.0 for Perl uses rand to generate encryption keys. Amazon::Credentials stores credentials in an obfuscated form to prevent access to the secrets from a data d…

| Cryptography
May 11, 2026 May 12, 2026
May 11, 2026
May 12, 2026
6.8 MEDIUM
CVE-2026-45026 — WeGIA: Stored XSS in html/atendido/processo_aceitacao.php

WeGIA is a web manager for charitable institutions. In versions prior to 3.7.3, a Stored Cross-Site Scripting (XSS) vulnerability allows an authenticated user to inject malicious JavaScript into the …

wegia | Remote | Cross-Site Scripting
May 11, 2026 May 12, 2026
May 11, 2026
May 12, 2026
6.8 MEDIUM
CVE-2026-45025 — WeGIA: Stored XSS in html/atendido/etapa_processo.php

WeGIA is a web manager for charitable institutions. In versions prior to 3.7.3, a Stored Cross-Site Scripting (XSS) vulnerability allows an authenticated user to inject malicious JavaScript into the …

wegia | Remote | Cross-Site Scripting
May 11, 2026 May 11, 2026
May 11, 2026
May 11, 2026
4.5 MEDIUM
CVE-2026-42887 — Audiobookshelf: Stored Cross-Site Scripting in Login Page Custom Message

Audiobookshelf is a self-hosted audiobook and podcast server. Prior to 2.33.0, a stored cross-site scripting (XSS) vulnerability exists in the Login Page due to improper sanitization of the authLogin…

audiobookshelf | Remote | Cross-Site Scripting
May 11, 2026 May 12, 2026
May 11, 2026
May 12, 2026
4.9 MEDIUM
CVE-2026-42886 — Audiobookshelf: Memory amplification DoS via oversized compressed details entry in backup…

Audiobookshelf is a self-hosted audiobook and podcast server. Prior to 2.32.2, the POST /api/backups/upload endpoint decompresses the details entry from an uploaded .audiobookshelf ZIP file entirely …

audiobookshelf | Remote | Denial of Service
May 11, 2026 May 12, 2026
May 11, 2026
May 12, 2026
Showing 20 of 6144 Results