Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.8 HIGH
CVE-2026-7432 — Ivanti Secure Access Client Privilege Escalation Vulnerability

A race condition in Ivanti Secure Access Client before 22.8R6 allows a locally authenticated user to escalate privileges to SYSTEM

windows secure_access_client | Race Condition
May 12, 2026 May 12, 2026
May 12, 2026
May 12, 2026
4.4 MEDIUM
CVE-2026-7431 — Ivanti Secure Access Client Privilege Escalation

An incorrect permission assignment for critical resource of Ivanti Secure Access Client   before 22.8R6 allows a local authenticated user to read or modify sensitive log data via write access to a sh…

windows secure_access_client | Misconfiguration
May 12, 2026 May 12, 2026
May 12, 2026
May 12, 2026
8.2 HIGH
CVE-2026-6866 — Initialization of a Resource with an Insecure Default vulnerability on EcoStruxure™ Panel…

CWE-1188 Initialization of a Resource with an Insecure Default vulnerability exists that could cause unauthorized disclosure of sensitive information when credentials revert to initial settings in ra…

Remote | Authentication
May 12, 2026 May 12, 2026
May 12, 2026
May 12, 2026
4.7 MEDIUM
CVE-2026-5061 — Consul-template vulnerable to sandbox path bypass in file helper via a symlink attack

The consul-template library before version 0.42.0 is vulnerable to a sandbox path bypass in the file template helper that may allow reading an out-of-sandbox file. This vulnerability (CVE-2026-5061) …

terraform_provider | Path Traversal
May 12, 2026 May 13, 2026
May 12, 2026
May 13, 2026
8.5 HIGH
CVE-2026-43983 — Pocket ID: OIDC refresh token flow bypasses authorization revocation, account disabling, …

Pocket ID is an OIDC provider that allows users to authenticate with their passkeys to your services. Prior to 2.6.0, The createTokenFromRefreshToken function (oidc_service.go) validates the refresh …

pocket_id | Remote | Authentication
May 12, 2026 May 13, 2026
May 12, 2026
May 13, 2026
7.3 HIGH
CVE-2026-43939 — YAF.NET: Stored XSS in Forum Thread Posts/Replies Allowing Arbitrary JavaScript Execution…

YetAnotherForum.NET (YAF.NET) is a C# ASP.NET forum. Prior to 4.0.5 and 3.2.12, the thread posting and reply feature accepts user-supplied content via a a post or reply that is stored server-side and…

Remote | Cross-Site Scripting
May 12, 2026 May 13, 2026
May 12, 2026
May 13, 2026
8.1 HIGH
CVE-2026-43938 — YAF.NET: Unauthenticated Stored Second-Order XSS in Admin Event Log via Reflected `User-A…

YetAnotherForum.NET (YAF.NET) is a C# ASP.NET forum. Prior to 4.0.5 and 3.2.12, the application's database logger (YAFNET.Core/Logger/DbLogger.cs) captures the incoming request's User-Agent header in…

Remote | Cross-Site Scripting
May 12, 2026 May 12, 2026
May 12, 2026
May 12, 2026
8.8 HIGH
CVE-2026-43937 — YAF.NET: Pre-Handler Authorization Bypass on Admin Pages Enabling Blind SQL Execution via…

YetAnotherForum.NET (YAF.NET) is a C# ASP.NET forum. Prior to 4.0.5, Any admin OnPost… handler executes its side effects before the ResultFilterAttribute rewrites the response to a 302 to /Info/4. Th…

Remote | Injection
May 12, 2026 May 12, 2026
May 12, 2026
May 12, 2026
8.2 HIGH
CVE-2026-42260 — Open-WebSearch: SSRF in `fetchWebContent` MCP tool: bracketed IPv6 literals and non-resol…

Open-WebSearch is a multi-engine MCP server, CLI, and local daemon for agent web search and content retrieval. Prior to 2.1.7, isPublicHttpUrl / assertPublicHttpUrl in src/utils/urlSafety.ts do not r…

Remote | Server-Side Request Forgery
May 12, 2026 May 12, 2026
May 12, 2026
May 12, 2026
7.5 HIGH
CVE-2026-32687 — SQL injection via channel name in Postgrex.Notifications.listen/3 and unlisten/3

Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in elixir-ecto postgrex ('Elixir.Postgrex.Notifications' module) allows SQL Injection. The channel …

postgrex | Injection
May 12, 2026 May 13, 2026
May 12, 2026
May 13, 2026
5.4 MEDIUM
CVE-2025-70842 — FluentCMS Stored Cross-Site Scripting (XSS)

A Stored Cross-Site Scripting (XSS) vulnerability was discovered in the File Management module of FluentCMS 1.2.3. The flaw allows an authenticated administrator to upload crafted SVG files containin…

Remote | Cross-Site Scripting
May 12, 2026 May 13, 2026
May 12, 2026
May 13, 2026
5.3 MEDIUM
CVE-2026-8391 — Other issue in the JavaScript Engine component

Other issue in the JavaScript Engine component. This vulnerability was fixed in Firefox 150.0.3.

firefox | Remote
May 12, 2026 May 13, 2026
May 12, 2026
May 13, 2026
0.0 NA
CVE-2026-8390 — Use-after-free in the JavaScript: WebAssembly component

Use-after-free in the JavaScript: WebAssembly component. This vulnerability was fixed in Firefox 150.0.3.

firefox | Memory Corruption
May 12, 2026 May 12, 2026
May 12, 2026
May 12, 2026
7.3 HIGH
CVE-2026-8389 — JIT miscompilation in the JavaScript Engine: JIT component

JIT miscompilation in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 150.0.3.

firefox | Remote | Memory Corruption
May 12, 2026 May 13, 2026
May 12, 2026
May 13, 2026
6.5 MEDIUM
CVE-2026-8388 — Incorrect boundary conditions in the JavaScript Engine: JIT component

Incorrect boundary conditions in the JavaScript Engine: JIT component. This vulnerability was fixed in Firefox 150.0.3.

firefox | Remote | Memory Corruption
May 12, 2026 May 12, 2026
May 12, 2026
May 12, 2026
7.1 HIGH
CVE-2026-6865 — Improper Limitation of a Pathname to a Restricted Directory Vulnerability on Multiple Pro…

CWE-22: Improper Limitation of a Pathname to a Restricted Directory (“Path Traversal”) vulnerability that could cause unauthorized access to sensitive files when user-supplied input is improperly han…

Remote | Path Traversal
May 12, 2026 May 12, 2026
May 12, 2026
May 12, 2026
9.1 CRITICAL
CVE-2026-45091 — sealed-env: TOTP secret embedded in unseal token payload (enterprise mode)

sealed-env is a cross-stack, zero-trust secret management library for Node.js and Java/Spring Boot. In sealed-env enterprise mode, versions 0.1.0-alpha.1 through 0.1.0-alpha.3 embedded the operator's…

Remote | Information Disclosure
May 12, 2026 May 12, 2026
May 12, 2026
May 12, 2026
2.1 LOW
CVE-2026-43930 — Parse Server: MFA SMS one-time password accepted twice under concurrent login

Parse Server is an open source backend that can be deployed to any infrastructure that can run Node.js. Prior to 8.6.76 and 9.9.0-alpha.2, a race condition in the MFA SMS one-time password (OTP) logi…

parse-server | Remote | Race Condition
May 12, 2026 May 12, 2026
May 12, 2026
May 12, 2026
8.7 HIGH
CVE-2026-43916 — pam_authnft: Heap buffer overflow in NETLINK_SOCK_DIAG reply walker

pam_authnft is a PAM session module binding nftables firewall rules to authenticated sessions via cgroupv2 inodes. Prior to 0.2.0-alpha, a heap buffer over-read in peer_lookup_tcp (src/peer_lookup.c:…

Remote | Memory Corruption
May 12, 2026 May 12, 2026
May 12, 2026
May 12, 2026
4.3 MEDIUM
CVE-2026-42006 — Proxmox IMAP Memory Consumption Vulnerability (Arbitrary Bracing)

An attacker can cause uncontrolled memory usage with excessive bracing over IMAP. The fix in CVE-2026-27857 was incomplete, only blocking one way of doing this, so there was still another way left op…

Remote | Denial of Service
May 12, 2026 May 12, 2026
May 12, 2026
May 12, 2026
Showing 20 of 6333 Results