Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.3 MEDIUM
CVE-2025-15634 — HCL BigFix WebUI is affected by a missing authorization vulnerability

A missing authorization vulnerability in HCL BigFix WebUI allows an authenticated user without proper permissions to view sensitive environmental information via direct URL access to the unauthorized…

Remote | Authorization
May 09, 2026 May 09, 2026
May 09, 2026
May 09, 2026
5.3 MEDIUM
CVE-2025-15633 — HCL BigFix WebUI is affected by an improper authorization vulnerability

An improper authorization vulnerability in HCL BigFix WebUI allows an authenticated user without Master Operator privileges to access internal data (site names, versions, and configuration variables)…

Remote | Authorization
May 09, 2026 May 09, 2026
May 09, 2026
May 09, 2026
6.9 MEDIUM
CVE-2026-8209 — Gibbon Path Traversal DOS

Gibbon versions before v30.0.01 are affected by a path traversal vulnerability resulting in DOS by attempting extraction of web application PHP files, failed .zip extraction results in deletion of th…

Remote | Path Traversal
May 09, 2026 May 09, 2026
May 09, 2026
May 09, 2026
8.9 HIGH
CVE-2026-8208 — Gibbon Local File Inclusion Remote Command Execution

Gibbon versions before v30.0.01 are affected by a local file inclusion vulnerability resulting in RCE by changing the report archive directory and forcing interpretation of a user provided .zip as PH…

Remote | Path Traversal
May 09, 2026 May 09, 2026
May 09, 2026
May 09, 2026
8.7 HIGH
CVE-2026-42461 — Arcane Vulnerable to Unauthenticated Disclosure of Custom Compose Template Content (incl.…

Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to version 1.18.0, four GET endpoints under /api/templates* in Arcane's Huma backend are registered without…

Remote | Authorization
May 09, 2026 May 09, 2026
May 09, 2026
May 09, 2026
7.8 HIGH
CVE-2026-42301 — Improper Input Validation leading to Improper Control of Generation of Code ('Code Inject…

pyp2spec generates working Fedora RPM spec file for Python projects. Prior to version 0.14.1, pyp2spec was writing PyPI package metadata (e.g. the summary field) into the generated spec file without …

| Misconfiguration
May 09, 2026 May 09, 2026
May 09, 2026
May 09, 2026
8.5 HIGH
CVE-2026-42297 — Argo Workflows Is Missing Authorization in Sync ConfigMap Provider

Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. From version 4.0.0 to before version 4.0.5, the Sync Service's ConfigMap-backed provid…

Remote | Authorization
May 09, 2026 May 09, 2026
May 09, 2026
May 09, 2026
8.1 HIGH
CVE-2026-42296 — Argo Workflows has incomplete fix for CVE-2026-31892: hostNetwork, securityContext, servi…

Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Prior to versions 3.7.14 and 4.0.5, a user with create Workflow permission can bypass …

Remote | Authorization
May 09, 2026 May 09, 2026
May 09, 2026
May 09, 2026
8.5 HIGH
CVE-2026-42295 — Argo Workflows: Exposure of artifact repository credentials

Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. From version 4.0.0 to before version 4.0.5, the workflow executor logs all artifact re…

Remote | Information Disclosure
May 09, 2026 May 09, 2026
May 09, 2026
May 09, 2026
8.2 HIGH
CVE-2026-42294 — Argo Workflows: Unauthenticated Memory Exhaustion (DoS) in Webhook Interceptor

Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. Prior to versions 3.7.14 and 4.0.5, the Webhook Interceptor loads the entire request b…

Remote | Denial of Service
May 09, 2026 May 09, 2026
May 09, 2026
May 09, 2026
2.3 LOW
CVE-2026-42183 — Argo Workflows: SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go)

Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. From version 4.0.0 to before version 4.0.5, a nil pointer dereference in server/auth/g…

Remote | Denial of Service
May 09, 2026 May 09, 2026
May 09, 2026
May 09, 2026
5.3 MEDIUM
CVE-2026-42174 — Kirby: User avatar creation, replacement and deletion are not gated by user update permis…

Kirby is an open-source content management system. Prior to versions 4.9.0 and 5.4.0, user avatar creation, replacement and deletion are not gated by user update permissions. This issue has been patc…

Remote | Authorization
May 09, 2026 May 09, 2026
May 09, 2026
May 09, 2026
7.1 HIGH
CVE-2026-42137 — Kirby: `pages.access/list` and `files.access/list` permissions are not consistently check…

Kirby is an open-source content management system. Prior to versions 4.9.0 and 5.4.0, `pages.access/list` and `files.access/list` permissions are not consistently checked in the Panel and REST API. T…

Remote | Authorization
May 09, 2026 May 09, 2026
May 09, 2026
May 09, 2026
7.1 HIGH
CVE-2026-42069 — Kirby: Read access to site, user and role information is not gated by permissions

Kirby is an open-source content management system. Prior to versions 4.9.0 and 5.4.0, read access to site, user and role information is not gated by permissions. This issue has been patched in versio…

Remote | Authorization
May 09, 2026 May 09, 2026
May 09, 2026
May 09, 2026
5.3 MEDIUM
CVE-2026-42051 — Kirby: System API endpoint leaks license data and installed version to authenticated users

Kirby is an open-source content management system. Prior to versions 4.9.0 and 5.4.0, the system API endpoint leaks license data and installed version to authenticated users. This issue has been patc…

Remote | Information Disclosure
May 09, 2026 May 09, 2026
May 09, 2026
May 09, 2026
7.5 HIGH
CVE-2026-41311 — LiquidJS is vulnerable to Denial of Service via circular block reference in layout

LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. Prior to version 10.25.7, a circular block reference in {% layout %} / {% block %} causes an infinite recursive loo…

Remote | Denial of Service
May 09, 2026 May 09, 2026
May 09, 2026
May 09, 2026
8.7 HIGH
CVE-2026-41163 — bubblewrap vulnerable to privilege escalation in setuid mode via ptrace

bubblewrap is a low-level unprivileged sandboxing tool. From version 0.11.0 to before version 0.11.2, if bubblewrap is installed in setuid mode then the user can use ptrace to attach to bubblewrap an…

Remote | Misconfiguration
May 09, 2026 May 09, 2026
May 09, 2026
May 09, 2026
0.0 NA
CVE-2026-42560 — auth: Patreon provider assigns the same local user ID to every authenticated Patreon acco…

auth provides authentication via oauth2, direct and email. From versions 1.18.0 to before 1.25.2 and 2.0.0 to before 2.1.2, the Patreon OAuth provider maps every authenticated Patreon account to the …

| Authentication
May 09, 2026 May 09, 2026
May 09, 2026
May 09, 2026
0.0 NA
CVE-2026-42311 — Pillow: OOB Write with Invalid PSD Tile Extents (Integer Overflow)

Pillow is a Python imaging library. From version 10.3.0 to before version 12.2.0, processing a malicious PSD file could lead to memory corruption, potentially resulting in a crash or arbitrary code e…

| Memory Corruption
May 09, 2026 May 09, 2026
May 09, 2026
May 09, 2026
0.0 NA
CVE-2026-42310 — Pillow: PDF Parsing Trailer Infinite Loop (DoS)

Pillow is a Python imaging library. From version 4.2.0 to before version 12.2.0, an attacker can supply a malicious PDF that causes the process to hang indefinitely, consuming 100% CPU and making the…

| Denial of Service
May 09, 2026 May 09, 2026
May 09, 2026
May 09, 2026
Showing 20 of 5790 Results