Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.5 HIGH
CVE-2026-6067 — CVE-2026-6067

A heap buffer overflow vulnerability exists in the Netwide Assembler (NASM) due to a lack of bounds checking in the obj_directive() function. This vulnerability can be exploited by a user assembling …

netwide_assembler nasm | Remote | Memory Corruption
Apr 10, 2026 Apr 23, 2026
Apr 10, 2026
Apr 23, 2026
8.8 HIGH
CVE-2026-40217 — LiteLLM Arbitrary Code Execution Vulnerability

LiteLLM through 2026-04-08 allows remote attackers to execute arbitrary code via bytecode rewriting at the /guardrails/test_custom_code URI.

litellm | Remote | Injection
Apr 10, 2026 Apr 27, 2026
Apr 10, 2026
Apr 27, 2026
7.8 HIGH
CVE-2026-33092 — Acronis True Image OEM/MacOS Privilege Escalation

Local privilege escalation due to improper handling of environment variables. The following products are affected: Acronis True Image OEM (macOS) before build 42571, Acronis True Image (macOS) before…

true_image | Misconfiguration
Apr 10, 2026 Apr 13, 2026
Apr 10, 2026
Apr 13, 2026
7.5 HIGH
CVE-2025-5804 — WordPress Case Theme User < 1.0.4 - Local File Inclusion Vulnerability

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in Case Themes Case Theme User case-theme-user allows PHP Local File Inclusion.Th…

Remote | Path Traversal
Apr 10, 2026 Apr 24, 2026
Apr 10, 2026
Apr 24, 2026
7.1 HIGH
CVE-2025-58920 — WordPress Cerato theme <= 2.2.18 - Reflected Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Zootemplate Cerato cerato allows Reflected XSS.This issue affects Cerato: from n/a through <= 2.2…

Remote | Cross-Site Scripting
Apr 10, 2026 Apr 24, 2026
Apr 10, 2026
Apr 24, 2026
8.1 HIGH
CVE-2025-58913 — WordPress VideoPro theme <= 2.3.8.1 - Local File Inclusion vulnerability

Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in CactusThemes VideoPro videopro allows PHP Local File Inclusion.This issue affe…

Remote | Path Traversal
Apr 10, 2026 Apr 24, 2026
Apr 10, 2026
Apr 24, 2026
6.4 MEDIUM
CVE-2026-5774 — Juju API Server Denial of Service and Authentication Replay via Unsynchronized Token Map

Improper synchronization of the userTokens map in the API server in Canonical Juju 4.0.5, 3.6.20, and 2.9.56 may allow an authenticated user to possibly cause a denial of service on the server or pos…

juju | Remote | Race Condition
Apr 10, 2026 Apr 22, 2026
Apr 10, 2026
Apr 22, 2026
9.9 CRITICAL
CVE-2026-5412 — Juju CloudSpec API could leak senstive information

In Juju versions prior to 2.9.57 and 3.6.21, an authorization issue exists in the Controller facade. An authenticated user can call the CloudSpec API method to extract the cloud credentials used to b…

juju | Remote | Authorization
Apr 10, 2026 Apr 30, 2026
Apr 10, 2026
Apr 30, 2026
Showing 20 of 5548 Results