Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.4 MEDIUM
CVE-2026-44993 — OpenClaw < 2026.4.20 - Direct Message Misclassification in Feishu Card Actions

OpenClaw before 2026.4.20 contains a message classification vulnerability in Feishu card-action callbacks that misclassifies direct messages as group conversations. Attackers can bypass dmPolicy enfo…

openclaw | Remote | Misconfiguration
May 11, 2026 May 12, 2026
May 11, 2026
May 12, 2026
5.0 MEDIUM
CVE-2026-44992 — OpenClaw 2026.4.5 < 2026.4.20 - MiniMax API Host Override via Workspace dotenv

OpenClaw versions 2026.4.5 before 2026.4.20 contain an environment variable injection vulnerability allowing workspace dotenv to override MINIMAX_API_HOST. Attackers can redirect credentialed MiniMax…

openclaw | Injection
May 11, 2026 May 12, 2026
May 11, 2026
May 12, 2026
4.2 MEDIUM
CVE-2026-44991 — OpenClaw < 2026.4.21 - Authorization Bypass in Owner-Enforced Commands via Wildcard Chann…

OpenClaw before 2026.4.21 contains an authorization bypass vulnerability in command-auth.ts that allows non-owner senders to execute owner-enforced slash commands when wildcard inbound senders are co…

openclaw | Remote | Authorization
May 11, 2026 May 12, 2026
May 11, 2026
May 12, 2026
5.4 MEDIUM
CVE-2026-44777 — jq: stack overflow in module loading on mutual `include`

jq is a command-line JSON processor. In 1.8.2rc1 and earlier, the ordinary module loader recurses without cycle detection when two otherwise valid modules include each other.

jq | Misconfiguration
May 11, 2026 May 11, 2026
May 11, 2026
May 11, 2026
4.7 MEDIUM
CVE-2026-44659 — Zen Browser Mac - Address Bar Spoofing via Long Subdomain

Zen is a firefox-based browser. Prior to 1.19.12b, the ZEN Browser incorrectly truncates long hostnames in the address bar and shows only the attacker-controlled prefix of the subdomain, hiding the a…

Remote | Information Disclosure
May 11, 2026 May 11, 2026
May 11, 2026
May 11, 2026
2.4 LOW
CVE-2026-44658 — Zen Browser: RSS Live-Folder Item URLs Are Not Scheme-Restricted Before Trusted Tab Creat…

Zen is a firefox-based browser. Prior to 1.19.12b, RSS feed URLs entered by the user are validated to http: or https: in promptForFeedUrl, but item links inside the feed are not subject to the same r…

Remote | Misconfiguration
May 11, 2026 May 11, 2026
May 11, 2026
May 11, 2026
8.2 HIGH
CVE-2026-44413 — JetBrains TeamCity Authentication Bypass Vulnerability

In JetBrains TeamCity before 2026.1 2025.11.5 authenticated users could expose server API to unauthorised access

teamcity | Remote | Authentication
May 11, 2026 May 12, 2026
May 11, 2026
May 12, 2026
5.3 MEDIUM
CVE-2026-44226 — pyLoad: Unauthenticated traceback disclosure via global exception handler in WebUI

pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, pyload-ng WebUI returns full Python traceback details to clients on unhandled exceptions. Because /web/<p…

pyload | Remote | Information Disclosure
May 11, 2026 May 11, 2026
May 11, 2026
May 11, 2026
5.3 MEDIUM
CVE-2026-43995 — Flowise: SSRF Protection Bypass via Direct node-fetch / axios Usage (Patch Enforcement Fa…

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, multiple tool implementations directly import and invoke raw HTTP clients (node-fetch, axios) …

flowise | Remote | Server-Side Request Forgery
May 11, 2026 May 11, 2026
May 11, 2026
May 11, 2026
6.2 MEDIUM
CVE-2026-43896 — jq: Stack Overflow in Recursive Object Merge

jq is a command-line JSON processor. In 1.8.1 and earlier, unbounded recursion in jv_object_merge_recursive() allows a crafted jq program to crash the process with a segfault. The function is reachab…

jq | Denial of Service
May 11, 2026 May 12, 2026
May 11, 2026
May 12, 2026
4.4 MEDIUM
CVE-2026-43895 — jq: Embedded NUL in jq import paths causes local redaction-policy bypass and preserves se…

jq is a command-line JSON processor. In 1.8.1 and earlier, jq accepts embedded NUL bytes in import paths at the jq-language level, but later resolves those paths through C string operations during mo…

jq | Misconfiguration
May 11, 2026 May 11, 2026
May 11, 2026
May 11, 2026
6.2 MEDIUM
CVE-2026-43894 — jq: Wild stack write via signed-integer overflow in decNumber D2U() macro

jq is a command-line JSON processor. In 1.8.1 and earlier, when decNumberFromString is given a number literal of INT_MAX-1 (2147483646) digits, the D2U() macro overflows during signed-int arithmetic.…

jq | Memory Corruption
May 11, 2026 May 11, 2026
May 11, 2026
May 11, 2026
8.1 HIGH
CVE-2026-43640 — Bitwarden Server < 2026.4.1 Authentication Bypass via SCIM API Key

Bitwarden Server prior to v2026.4.1 does not require master-password re-authentication when retrieving or rotating an organization's SCIM API key, allowing an authenticated user with SCIM management …

server | Remote | Authentication
May 11, 2026 May 11, 2026
May 11, 2026
May 11, 2026
8.0 HIGH
CVE-2026-43639 — Bitwarden Server < 2026.4.0 Missing Authorization via Provider Clients

Bitwarden Server prior to v2026.4.0 contains a missing authorization vulnerability that allows a provider service user to add an arbitrary organization to their provider via `POST /providers/{provide…

server | Remote | Authorization
May 11, 2026 May 11, 2026
May 11, 2026
May 11, 2026
5.4 MEDIUM
CVE-2026-43638 — Bitwarden Server < 2026.4.1 Missing Authorization via Organization Cipher Import

Bitwarden Server prior to v2026.4.1 contains a missing authorization vulnerability that allows any authenticated user to write ciphers into an arbitrary organization via `POST /ciphers/import-organiz…

server | Remote | Authorization
May 11, 2026 May 11, 2026
May 11, 2026
May 11, 2026
2.3 LOW
CVE-2026-42865 — Inbox Zero: Cross-account cleaner email stream exposure

Inbox Zero is an AI personal assistant for email. Prior to 2.29.3, the cleaner email stream endpoint used a shared Redis subscription listener, which could deliver thread events for one authenticated…

Remote | Information Disclosure
May 11, 2026 May 11, 2026
May 11, 2026
May 11, 2026
8.5 HIGH
CVE-2026-42860 — Open edx Enterprise Service: SSRF via SAML metadata URL in sync_provider_data endpoint

The Open edx Enterprise Service app provides enterprise features to the Open edX platform. From 7.0.2 to 7.0.4, the sync_provider_data endpoint in SAMLProviderDataViewSet fetches SAML metadata from a…

Remote | Server-Side Request Forgery
May 11, 2026 May 12, 2026
May 11, 2026
May 12, 2026
8.1 HIGH
CVE-2026-42859 — Neat VNC: Buffer overflow due to oversized RSA public keys

Neat VNC is a VNC server library. Prior to 0.9.6, a pre-authentication stack buffer overflow exists in neatvnc in the RSA-AES security type handler. An unauthenticated remote attacker who can reach t…

neatvnc | Remote | Memory Corruption
May 11, 2026 May 11, 2026
May 11, 2026
May 11, 2026
8.5 HIGH
CVE-2026-42858 — Open edX Platform: Server-Side Request Forgery (SSRF) in SAML Provider Data Sync Endpoint

Open edX Platform enables the authoring and delivery of online learning at any scale. The sync_provider_data endpoint in SAMLProviderDataViewSet allows authenticated Enterprise Admin users to supply …

openedx | Remote | Server-Side Request Forgery
May 11, 2026 May 12, 2026
May 11, 2026
May 12, 2026
4.6 MEDIUM
CVE-2026-42857 — Open edX Platform: Stored CSS Injection in Email Notifications via Incomplete HTML Saniti…

Open edX Platform enables the authoring and delivery of online learning at any scale. The HTML sanitizer clean_thread_html_body() used for discussion notification emails fails to remove <style> tags …

openedx | Remote | Cross-Site Scripting
May 11, 2026 May 12, 2026
May 11, 2026
May 12, 2026
Showing 20 of 6193 Results