Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.5 MEDIUM
CVE-2026-8318 — VectifyAI PageIndex PDF Table of Contents page_index.py toc_transformer infinite loop

A security flaw has been discovered in VectifyAI PageIndex up to f50e52975313c6716c02b20a119577a1929decba. Affected by this vulnerability is the function toc_transformer of the file pageindex/page_in…

Remote | Denial of Service
May 11, 2026 May 11, 2026
May 11, 2026
May 11, 2026
8.7 HIGH
CVE-2026-7790 — Unbounded chunk-size hex digits in cowlib cause quadratic CPU and memory DoS

Uncontrolled Resource Consumption vulnerability in ninenines cowlib (cow_http_te module) allows Excessive Allocation. The chunked transfer-encoding parser in cow_http_te accepts an unbounded number …

cowlib | Remote | Denial of Service
May 11, 2026 May 11, 2026
May 11, 2026
May 11, 2026
7.1 HIGH
CVE-2026-45224 — Crabbox < 0.9.0 Path Traversal via Islo Provider Workspace Resolution

Crabbox before 0.9.0 contains a path traversal vulnerability in the Islo provider's workspace path resolution that allows attackers to supply absolute or relative paths that resolve outside the inten…

| Path Traversal
May 11, 2026 May 12, 2026
May 11, 2026
May 12, 2026
8.8 HIGH
CVE-2026-45223 — Crabbox < 0.9.0 Authentication Bypass via Admin Claim Injection

Crabbox before 0.9.0 contains an authentication bypass vulnerability in the coordinator user-token verification path where the verifyUserToken() function fails to reject payloads containing an admin …

Remote | Authentication
May 11, 2026 May 12, 2026
May 11, 2026
May 12, 2026
6.9 MEDIUM
CVE-2026-45222 — Summarize Insecure Daemon Configuration File Permissions

Summarize versions through 0.14.1, fixed in commit 0cfb0fb, creates the daemon configuration directory and file with default filesystem permissions that may be world-readable on Unix-like systems, al…

| Misconfiguration
May 11, 2026 May 11, 2026
May 11, 2026
May 11, 2026
2.1 LOW
CVE-2026-43969 — Cookie Request Header Injection via Unvalidated Encoder in cow_cookie:cookie/1

Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability in ninenines cowlib allows HTTP request splitting and cookie smuggling via unvalidated cookie name and value fields. cow_co…

cowlib | Injection
May 11, 2026 May 11, 2026
May 11, 2026
May 11, 2026
6.3 MEDIUM
CVE-2026-43968 — CR Injection in SSE Encoder Enables Event Splitting via cow_sse:event/1

Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability in ninenines cowlib allows SSE event splitting and injection via unvalidated field values. cow_sse:event/1 in cowlib guards…

cowlib | Remote | Injection
May 11, 2026 May 12, 2026
May 11, 2026
May 12, 2026
6.9 MEDIUM
CVE-2026-42871 — WeGIA: Error Handling familiar_docfamiliar

WeGIA is a web manager for charitable institutions. In versions prior to 3.7.0, atendido/familiar_docfamiliar.php displays an overly descriptive error message, including database-related details. Thi…

wegia | Remote | Information Disclosure
May 11, 2026 May 11, 2026
May 11, 2026
May 11, 2026
6.7 MEDIUM
CVE-2026-42866 — Tookie: Arbitrary file write via path traversal in -u username / -U userfile output filen…

Tookie is a advanced OSINT information gathering tool. Prior to 4.1fix, modules/modules.py's write_txt, write_csv, write_json, and (commented-but-shipping) scan_file helpers open their output as open…

| Path Traversal
May 11, 2026 May 11, 2026
May 11, 2026
May 11, 2026
9.9 CRITICAL
CVE-2026-42864 — FireFighter: Unauthenticated SSRF in Raid jira_bot endpoint allows IAM credential theft

FireFighter is an incident management application. Prior to 0.0.54, the POST /api/v2/firefighter/raid/jira_bot endpoint (CreateJiraBotView) is reachable without authentication (permission_classes = […

Remote | Authentication
May 11, 2026 May 11, 2026
May 11, 2026
May 11, 2026
7.5 HIGH
CVE-2026-8305 — OpenClaw bluebubbles Webhook monitor.ts handleBlueBubblesWebhookRequest improper authenti…

A vulnerability was detected in OpenClaw up to 2026.1.24. The impacted element is the function handleBlueBubblesWebhookRequest of the file extensions/bluebubbles/src/monitor.ts of the component blueb…

openclaw | Remote | Authentication
May 11, 2026 May 11, 2026
May 11, 2026
May 11, 2026
5.1 MEDIUM
CVE-2026-7308 — Nexus Repository 3 - Stored Cross-Site Scripting (XSS) via HTML Browse Page

An authenticated user with upload permission to a hosted repository can store content that causes arbitrary JavaScript to execute in the browser of any user who browses that repository directory via …

nexus_repository_manager | Remote | Cross-Site Scripting
May 11, 2026 May 11, 2026
May 11, 2026
May 11, 2026
6.3 MEDIUM
CVE-2026-7210 — The expat and elementtree parsers use insufficient entropy for XML hash-flooding protecti…

`xml.parsers.expat` and `xml.etree.ElementTree` use insufficient entropy for Expat hash-flooding protection, which allows a crafted XML document to trigger hash flooding.\r\n\r\nFully mitigating this…

python | Remote | Denial of Service
May 11, 2026 May 12, 2026
May 11, 2026
May 12, 2026
2.3 LOW
CVE-2026-5266 — Wikimedia Foundation Echo Sensitive Information Exposure

Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation Echo. This vulnerability is associated with program files includes/Api/ApiEchoNotifications.Php. …

Remote | Information Disclosure
May 11, 2026 May 12, 2026
May 11, 2026
May 12, 2026
0.0 NA
CVE-2026-5172 — CVE-2026-5172

A buffer overflow in dnsmasq’s extract_addresses() function allows an attacker to trigger a heap out-of-bounds read and crash by exploiting a malformed DNS response, enabling extract_name() to advanc…

| Memory Corruption
May 11, 2026 May 12, 2026
May 11, 2026
May 12, 2026
5.3 MEDIUM
CVE-2026-4893 — CVE-2026-4893

An information disclosure vulnerability in dnsmasq allows remote attackers to bypass source checks via a crafted DNS packet with RFC 7871 client subnet information.

Remote | Information Disclosure
May 11, 2026 May 12, 2026
May 11, 2026
May 12, 2026
8.4 HIGH
CVE-2026-4892 — CVE-2026-4892

A heap-based out-of-bounds write vulnerability in the DHCPv6 implementation of dnsmasq allows local attackers to execute arbitrary code with root privileges via a crafted DHCPv6 packet.

| Memory Corruption
May 11, 2026 May 12, 2026
May 11, 2026
May 12, 2026
5.3 MEDIUM
CVE-2026-4891 — CVE-2026-4891

A heap-based out-of-bounds read vulnerability in the DNSSEC validation of dnsmasq allows remote attackers to cause a denial of service via a crafted DNS packet.

Remote | Denial of Service
May 11, 2026 May 12, 2026
May 11, 2026
May 12, 2026
7.5 HIGH
CVE-2026-4890 — CVE-2026-4890

A Denial of Service (DoS) vulnerability in the DNSSEC validation of dnsmasq allows remote attackers to cause a denial of service via a crafted DNS packet.

Remote | Denial of Service
May 11, 2026 May 12, 2026
May 11, 2026
May 12, 2026
8.8 HIGH
CVE-2026-45006 — OpenClaw < 2026.4.23 - Unsafe Config Mutation via Gateway Tool Denylist Bypass

OpenClaw before 2026.4.23 contains an improper access control vulnerability in the gateway tool's config.apply and config.patch operations that allows compromised models to write unsafe configuration…

openclaw | Remote | Authorization
May 11, 2026 May 12, 2026
May 11, 2026
May 12, 2026
Showing 20 of 6264 Results