Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.0 CRITICAL
CVE-2026-42571 — Privilege Escalation Attack affecting Pelican Web UI

Pelican is a platform for creating data federations. From versions 7.21.0 to before 7.21.5, 7.22.0 to before 7.22.3, 7.23.0 to before 7.23.3, and 7.24.0 to before 7.24.2, there is a a privilege escal…

Remote | Authorization
May 09, 2026 May 09, 2026
May 09, 2026
May 09, 2026
9.4 CRITICAL
CVE-2026-42569 — phpvms: /importer authorization bypass causing full database wipe

phpVMS is a PHP application to run and simulate an airline. Prior to version 7.0.6, a critical vulnerability in phpVMS allowed unauthenticated access to a legacy import feature. This issue has been p…

phpvms | Remote | Authentication
May 09, 2026 May 09, 2026
May 09, 2026
May 09, 2026
8.3 HIGH
CVE-2026-42562 — Plainpad: Privilege Escalation via Writable Admin Field in Profile Update (Access Control)

Plainpad is a self hosted note taking app. Prior to version 1.1.1, Plainpad allows a low-privilege authenticated user to self-escalate to administrator by submitting admin=true in PUT /api.php/v1/use…

Remote | Authorization
May 09, 2026 May 09, 2026
May 09, 2026
May 09, 2026
6.3 MEDIUM
CVE-2026-42333 — quarkus-openapi-generator has overly broad path-parameter matching that sends authenticat…

Quarkus OpenAPI Generator is Quarkus' extensions for generation of Rest Clients and server stubs generation. Prior to versions 2.11.1-lts, 2.16.0-lts, and 2.17.0, the generated authentication filter …

Remote | Authentication
May 09, 2026 May 09, 2026
May 09, 2026
May 09, 2026
5.8 MEDIUM
CVE-2026-42258 — net-imap: Command Injection via unvalidated Symbol inputs

Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.4.24, 0.5.14, and 0.6.4, symbol arguments to commands are vulnerable to a CRLF Injection…

| Injection
May 09, 2026 May 09, 2026
May 09, 2026
May 09, 2026
5.8 MEDIUM
CVE-2026-42257 — net-imap: Command Injection via "raw" arguments to multiple commands

Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.4.24, 0.5.14, and 0.6.4, several Net::IMAP commands accept a raw string argument that is…

| Injection
May 09, 2026 May 09, 2026
May 09, 2026
May 09, 2026
6.0 MEDIUM
CVE-2026-42256 — net-imap: Denial of service via high iteration count for `SCRAM-*` authentication

Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. From versions 0.4.0 to before 0.4.24, 0.5.0 to before 0.5.14, and 0.6.0 to before 0.6.4, when authenticating…

Remote | Denial of Service
May 09, 2026 May 09, 2026
May 09, 2026
May 09, 2026
7.6 HIGH
CVE-2026-42246 — net-imap vulnerable to STARTTLS stripping via invalid response timing

Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.3.10, 0.4.24, 0.5.14, and 0.6.4, a man-in-the-middle attacker can cause Net::IMAP#startt…

Remote | Cryptography
May 09, 2026 May 09, 2026
May 09, 2026
May 09, 2026
2.3 LOW
CVE-2026-42245 — net-imap: Quadratic complexity when reading response literals

Net::IMAP implements Internet Message Access Protocol (IMAP) client functionality in Ruby. Prior to versions 0.4.24, 0.5.14, and 0.6.4, Net::IMAP::ResponseReader has quadratic time complexity when re…

Remote | Denial of Service
May 09, 2026 May 09, 2026
May 09, 2026
May 09, 2026
8.7 HIGH
CVE-2026-41893 — Signal K Server's WebSocket Login Endpoint Lacks Rate Limiting (Credential Brute-Force)

Signal K Server is a server application that runs on a central hub in a boat. Prior to version 2.25.0, the HTTP login endpoints (POST /login and POST /signalk/v1/auth/login) are protected by express-…

signal_k_server | Remote | Authentication
May 09, 2026 May 09, 2026
May 09, 2026
May 09, 2026
6.5 MEDIUM
CVE-2026-8193 — Akaunting Invoice PDF Rendering dompdf.php server-side request forgery

A weakness has been identified in Akaunting 3.1.21. This issue affects some unknown processing of the file config/dompdf.php of the component Invoice PDF Rendering. Executing a manipulation can lead …

Remote | Server-Side Request Forgery
May 09, 2026 May 09, 2026
May 09, 2026
May 09, 2026
6.5 MEDIUM
CVE-2026-8192 — Wavlink NU516U1 adm.cgi wzdap os command injection

A security flaw has been discovered in Wavlink NU516U1 M16U1_V240425. This vulnerability affects the function wzdap of the file /cgi-bin/adm.cgi. Performing a manipulation of the argument EncrypType/…

Remote | Injection
May 09, 2026 May 09, 2026
May 09, 2026
May 09, 2026
6.5 MEDIUM
CVE-2026-8191 — Wavlink NU516U1 adm.cgi wifi_region os command injection

A vulnerability was identified in Wavlink NU516U1 M16U1_V240425. This affects the function wifi_region of the file /cgi-bin/adm.cgi. Such manipulation of the argument skiplist1/skiplist2 leads to os …

Remote | Injection
May 09, 2026 May 09, 2026
May 09, 2026
May 09, 2026
6.5 MEDIUM
CVE-2026-8190 — Wavlink NU516U1 adm.cgi wan os command injection

A vulnerability was determined in Wavlink NU516U1 M16U1_V240425. Affected by this issue is the function wan of the file /cgi-bin/adm.cgi. This manipulation of the argument ppp_username/ppp_passwd/rwa…

Remote | Injection
May 09, 2026 May 09, 2026
May 09, 2026
May 09, 2026
6.5 MEDIUM
CVE-2026-8189 — Wavlink NU516U1 adm.cgi wzdrepeater os command injection

A vulnerability was found in Wavlink NU516U1 M16U1_V240425. Affected by this vulnerability is the function wzdrepeater of the file /cgi-bin/adm.cgi. The manipulation of the argument wlan_bssid/sel_Au…

Remote | Injection
May 09, 2026 May 09, 2026
May 09, 2026
May 09, 2026
6.5 MEDIUM
CVE-2026-8188 — Wavlink NU516U1 adm.cgi change_wifi_password os command injection

A vulnerability has been found in Wavlink NU516U1 M16U1_V240425. Affected is the function change_wifi_password of the file /cgi-bin/adm.cgi. The manipulation of the argument wl_channel/wl_Pass/Encryp…

Remote | Injection
May 09, 2026 May 09, 2026
May 09, 2026
May 09, 2026
5.3 MEDIUM
CVE-2026-8198 — Activity Logs, User Activity Tracking, Multisite Activity Log from Logtivity <= 3.3.6 - U…

The Activity Logs, User Activity Tracking, Multisite Activity Log from Logtivity plugin for WordPress is vulnerable to Authentication Bypass to Information Disclosure in versions up to, and including…

Remote | Authentication
May 09, 2026 May 09, 2026
May 09, 2026
May 09, 2026
6.9 MEDIUM
CVE-2026-8186 — Open5GS NF client.c ogs_sbi_client_send_via_scp_or_sepp out-of-bounds

A vulnerability was detected in Open5GS up to 2.7.7. This affects the function ogs_sbi_client_send_via_scp_or_sepp in the library lib/sbi/client.c of the component NF. Performing a manipulation resul…

open5gs | Remote | Memory Corruption
May 09, 2026 May 09, 2026
May 09, 2026
May 09, 2026
6.9 MEDIUM
CVE-2026-8187 — Open5GS UPF gtp-path.c _gtpv1_u_recv_cb resource consumption

A flaw has been found in Open5GS up to 2.7.7. This impacts the function _gtpv1_u_recv_cb of the file src/upf/gtp-path.c of the component UPF. Executing a manipulation can lead to resource consumption…

open5gs | Remote | Denial of Service
May 09, 2026 May 09, 2026
May 09, 2026
May 09, 2026
6.3 MEDIUM
CVE-2026-8185 — UGREEN CM933 Administrative missing authentication

A security vulnerability has been detected in UGREEN CM933 1.1.59.4319. The impacted element is an unknown function of the component Administrative Interface. Such manipulation leads to missing authe…

| Authentication
May 09, 2026 May 09, 2026
May 09, 2026
May 09, 2026
Showing 20 of 5481 Results