Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.8 CRITICAL
CVE-2026-44887 — Unauthenticated RCE via Python Config File Injection in SaveConfigFile() (Path)

Pi.Alert is a WIFI / LAN intruder detector with web service monitoring. Prior to 2026-05-07, Pi.Alert's web-based configuration editor allows arbitrary Python code to be injected into pialert.conf. S…

Remote | Injection
May 27, 2026 May 29, 2026
May 27, 2026
May 29, 2026
8.7 HIGH
CVE-2026-44886 — Pi.Alert: Web Interface Vulnerable to Unauthenticated Blind SQL Injection

Pi.Alert is a WIFI / LAN intruder detector with web service monitoring. From 2024-06-29 to before 2026-05-07, the web application endpoint is vulnerable to SQL injection. The /pialert/php/server/devi…

Remote | Injection
May 27, 2026 May 29, 2026
May 27, 2026
May 29, 2026
7.8 HIGH
CVE-2026-44724 — systeminformation: Linux command injection in networkInterfaces() via unsanitized Network…

systeminformation is a System and OS information library for node.js. From 4.17.0 to 5.31.5, on Linux, systeminformation is vulnerable to command injection in networkInterfaces() when an active Netwo…

systeminformation | Injection
May 27, 2026 Jun 01, 2026
May 27, 2026
Jun 01, 2026
6.1 MEDIUM
CVE-2026-44681 — Authlib: Open Redirect in Authlib OIDC Implicit/Hybrid Authorization

Authlib is a Python library which builds OAuth and OpenID Connect servers. Prior to 1.6.12 and 1.7.1, an unauthenticated open redirect in Authlib's OpenIDImplicitGrant and OpenIDHybridGrant authoriza…

authlib | Remote | Misconfiguration
May 27, 2026 Jun 02, 2026
May 27, 2026
Jun 02, 2026
9.3 CRITICAL
CVE-2026-44590 — Sherlock: Command Injection via pull_request_target in validate_modified_targets.yml

Sherlock hunts down social media accounts by username across social networks. Prior to 0.16.1, the GitHub Actions workflow validate_modified_targets.yml is vulnerable to command injection via the pul…

Remote | Injection
May 27, 2026 May 29, 2026
May 27, 2026
May 29, 2026
5.4 MEDIUM
CVE-2026-42877 — FacturaScripts: Stored XSS via product reference in sales/purchases

FacturaScripts is an open source accounting and invoicing software. In 2025.92 and earlier, a stored Cross-Site Scripting (XSS) vulnerability exists in the product search modal of sales (Core/Lib/Aja…

facturascripts | Remote | Cross-Site Scripting
May 27, 2026 May 29, 2026
May 27, 2026
May 29, 2026
8.7 HIGH
CVE-2026-42197 — RELATE Vulnerable to Stored XSS via Unprivileged User Profile

RELATE is a web-based courseware package. Versions prior to commit 555f0efb1c5bd7531c07cd73724d7e566a81f620 have a stored cross-site scripting vulnerability that allows any enrolled student to execut…

relate | Remote | Cross-Site Scripting
May 27, 2026 Jun 01, 2026
May 27, 2026
Jun 01, 2026
3.7 LOW
CVE-2026-33552 — Northern.tech Mender Enterprise Server Authentication Bypass

Northern.tech Mender Enterprise Server before 4.1.1 has Incorrect Access Control.

Remote | Authorization
May 27, 2026 Jun 01, 2026
May 27, 2026
Jun 01, 2026
Showing 20 of 7868 Results