Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
4.7 MEDIUM
CVE-2026-34258 — Content Spoofing vulnerability in SAPUI5 (Search UI)

SAPUI5 (Search UI) allows an unauthenticated attacker to manipulate specific URL parameters on the Search UI to include malicious content. Successful exploitation may mislead victim users into clicki…

Remote | Cross-Site Scripting
May 12, 2026 May 12, 2026
May 12, 2026
May 12, 2026
4.7 MEDIUM
CVE-2026-27682 — Reflected Cross-Site Scripting (XSS) vulnerability in SAP NetWeaver Application Server AB…

Due to a reflected cross-site scripting (XSS) vulnerability in SAP NetWeaver Application Server ABAP (Applications based on Business Server Pages), an unauthenticated attacker could craft a URL that …

Remote | Cross-Site Scripting
May 12, 2026 May 12, 2026
May 12, 2026
May 12, 2026
5.4 MEDIUM
CVE-2026-0502 — Cross Site Request Forgery (CSRF) in SAP BusinessObjects Business Intelligence Platform

Due to insufficient CSRF protection in SAP BusinessObjects Business Intelligence Platform ,an authenticated user could be tricked by an attacker to send unintended requests to the web server. This ha…

businessobjects_business_intelligence_platform | Remote | Cross-Site Request Forgery
May 12, 2026 May 12, 2026
May 12, 2026
May 12, 2026
0.0 NA
CVE-2026-45393 — Apache HTTP Server SSRF

Reserved. Details will be published at disclosure.

May 12, 2026 May 12, 2026
May 12, 2026
May 12, 2026
0.0 NA
CVE-2026-45392 — Apache HTTP Server Remote Code Execution Vulnerability

Reserved. Details will be published at disclosure.

May 12, 2026 May 12, 2026
May 12, 2026
May 12, 2026
0.0 NA
CVE-2026-45391 — Apache Apache HTTP Server Remote Code Execution

Reserved. Details will be published at disclosure.

May 12, 2026 May 12, 2026
May 12, 2026
May 12, 2026
3.2 LOW
CVE-2026-45362 — Sangoma Switchvox SIP Authentication Credential Exposure

Sangoma Switchvox before 8.4 places cleartext SIP authentication credentials in a backup file.

switchvox | Authentication
May 12, 2026 May 12, 2026
May 12, 2026
May 12, 2026
9.6 CRITICAL
CVE-2026-45321 — Malware in 42 @tanstack/* packages exfiltrates cloud credentials, GitHub tokens, and SSH …

On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated via the legitimate …

Remote | Supply Chain
May 12, 2026 May 12, 2026
May 12, 2026
May 12, 2026
4.3 MEDIUM
CVE-2026-8349 — omec-project amf NGAP Message memory corruption

A flaw has been found in omec-project amf up to 2.1.1. This vulnerability affects unknown code of the component NGAP Message Handler. Executing a manipulation can lead to memory corruption. The attac…

Remote | Memory Corruption
May 12, 2026 May 12, 2026
May 12, 2026
May 12, 2026
8.8 HIGH
CVE-2026-8346 — D-Link DIR-816 portForward command injection

A vulnerability was detected in D-Link DIR-816 1.10CNB05_R1B011D88210. This affects the function portForward. Performing a manipulation of the argument ip_address results in command injection. The at…

dir-816_firmware dir-816 | Remote | Injection
May 12, 2026 May 12, 2026
May 12, 2026
May 12, 2026
8.8 HIGH
CVE-2026-8345 — D-Link DIR-816 singlePortForward sub_445E7C command injection

A security vulnerability has been detected in D-Link DIR-816 1.10CNB05_R1B011D88210. Affected by this issue is the function sub_445E7C of the file /goform/singlePortForward. Such manipulation of the …

dir-816_firmware dir-816 | Remote | Injection
May 11, 2026 May 12, 2026
May 11, 2026
May 12, 2026
7.3 HIGH
CVE-2026-43914 — Vaultwarden: Brute-force protection bypass vulnerability

Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.35.4, there is a security vulnerability in Vaultwarden that allows bypassing the login brute-force protection if email 2fa is …

vaultwarden | Remote | Authentication
May 11, 2026 May 12, 2026
May 11, 2026
May 12, 2026
8.1 HIGH
CVE-2026-43913 — Vaultwarden: Unconfirmed Owner Can Purge Entire Organization Vault

Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.35.5, Vaultwarden allows an unconfirmed organization owner to purge the entire organization vault. The organization invite flo…

vaultwarden | Remote | Authorization
May 11, 2026 May 11, 2026
May 11, 2026
May 11, 2026
8.7 HIGH
CVE-2026-43912 — Vaultwarden: Cross-Org Group Binding Enables Unauthorized Read And Write Access Into Anot…

Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.35.5, Vaultwarden does not enforce that a groups_users.users_organizations_uuid entry belongs to the same organization as grou…

vaultwarden | Remote | Authorization
May 11, 2026 May 12, 2026
May 11, 2026
May 12, 2026
6.8 MEDIUM
CVE-2026-43911 — Vaultwarden: Refresh tokens not invalidated on security stamp rotation

Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.35.5, refresh tokens are not invalidated when the user's security_stamp is rotated by some security-sensitive operations (pass…

vaultwarden | Remote | Authentication
May 11, 2026 May 12, 2026
May 11, 2026
May 12, 2026
6.8 MEDIUM
CVE-2026-43901 — Wireshark MCP: Arbitrary file write via export_objects when WIRESHARK_MCP_ALLOWED_DIRS is…

Wireshark MCP is an MCP Server that turns tshark into a structured analysis interface, then layers in optional Wireshark suite utilities. In 1.1.5 and earlier, wireshark-mcp exposes a wireshark_expor…

Remote | Path Traversal
May 11, 2026 May 12, 2026
May 11, 2026
May 12, 2026
9.3 CRITICAL
CVE-2026-43900 — DeepChat: Persistent DOM XSS via HTML Entity Encoding in `<antArtifact>` SVG Rendering (B…

DeepChat is an open-source artificial intelligence agent platform that unifies models, tools, and agents. Prior to v1.0.4-beta.1, a Cross-Site Scripting (XSS) vulnerability exists due to a discrepanc…

deepchat | Remote | Cross-Site Scripting
May 11, 2026 May 12, 2026
May 11, 2026
May 12, 2026
9.6 CRITICAL
CVE-2026-43899 — DeepChat: Incomplete Fix for CVE-2025-55733 leads to Remote Code Execution via Markdown L…

DeepChat is an open-source artificial intelligence agent platform that unifies models, tools, and agents. Prior to v1.0.4-beta.1, An incomplete mitigation for CVE-2025-55733 leaves DeepChat vulnerabl…

deepchat | Remote | Misconfiguration
May 11, 2026 May 12, 2026
May 11, 2026
May 12, 2026
5.3 MEDIUM
CVE-2026-42554 — Fiber: XSS in AutoFormat Content Negotiation

Fiber is a web framework for Go. Prior to 2.52.12 and 3.1.0, Cross-Site Scripting vulnerability in Go Fiber allows a remote attacker to inject arbitrary HTML/JavaScript by supplying Accept: text/html…

fiber | Remote | Cross-Site Scripting
May 11, 2026 May 11, 2026
May 11, 2026
May 11, 2026
8.6 HIGH
CVE-2026-34963 — barebox EFI PE Loader Memory Safety Vulnerabilities

barebox version prior to 2026.04.0 contains multiple memory-safety vulnerabilities in the EFI PE loader in efi/loader/pe.c where integer overflow in virtual image size computation using 32-bit arithm…

| Memory Corruption
May 11, 2026 May 11, 2026
May 11, 2026
May 11, 2026
Showing 20 of 6287 Results