Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.3 HIGH
CVE-2026-4158 — KeePassXC OpenSSL Configuration Uncontrolled Search Path Element Local Privilege Escalati…

KeePassXC OpenSSL Configuration Uncontrolled Search Path Element Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations o…

keepassxc | Misconfiguration
Apr 11, 2026 Apr 11, 2026
Apr 11, 2026
Apr 11, 2026
7.5 HIGH
CVE-2026-4157 — ChargePoint Home Flex revssh Service Command Injection Remote Code Execution Vulnerability

ChargePoint Home Flex revssh Service Command Injection Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of…

home_flex_firmware | Injection
Apr 11, 2026 Apr 11, 2026
Apr 11, 2026
Apr 11, 2026
7.5 HIGH
CVE-2026-4156 — ChargePoint Home Flex OCPP getpreq Stack-based Buffer Overflow Remote Code Execution Vuln…

ChargePoint Home Flex OCPP getpreq Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installa…

home_flex_firmware | Memory Corruption
Apr 11, 2026 Apr 11, 2026
Apr 11, 2026
Apr 11, 2026
7.5 HIGH
CVE-2026-4155 — ChargePoint Home Flex Inclusion of Sensitive Information in Source Code Information Discl…

ChargePoint Home Flex Inclusion of Sensitive Information in Source Code Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected …

home_flex_firmware | Information Disclosure
Apr 11, 2026 Apr 11, 2026
Apr 11, 2026
Apr 11, 2026
7.8 HIGH
CVE-2026-4154 — GIMP XPM File Parsing Integer Overflow Remote Code Execution Vulnerability

GIMP XPM File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is…

gimp | Memory Corruption
Apr 11, 2026 Apr 11, 2026
Apr 11, 2026
Apr 11, 2026
7.8 HIGH
CVE-2026-4153 — GIMP PSP File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability

GIMP PSP File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User inte…

gimp | Memory Corruption
Apr 11, 2026 Apr 11, 2026
Apr 11, 2026
Apr 11, 2026
7.8 HIGH
CVE-2026-4152 — GIMP JP2 File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability

GIMP JP2 File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User inte…

gimp | Memory Corruption
Apr 11, 2026 Apr 11, 2026
Apr 11, 2026
Apr 11, 2026
7.8 HIGH
CVE-2026-4151 — GIMP ANI File Parsing Integer Overflow Remote Code Execution Vulnerability

GIMP ANI File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is…

gimp | Memory Corruption
Apr 11, 2026 Apr 11, 2026
Apr 11, 2026
Apr 11, 2026
7.8 HIGH
CVE-2026-4150 — GIMP PSD File Parsing Integer Overflow Remote Code Execution Vulnerability

GIMP PSD File Parsing Integer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of GIMP. User interaction is…

gimp | Memory Corruption
Apr 11, 2026 Apr 11, 2026
Apr 11, 2026
Apr 11, 2026
10.0 CRITICAL
CVE-2026-4149 — Sonos Era 300 SMB Response Out-Of-Bounds Access Remote Code Execution Vulnerability

Sonos Era 300 SMB Response Out-Of-Bounds Access Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Sonos Era 300. A…

era_300_firmware | Memory Corruption
Apr 11, 2026 Apr 11, 2026
Apr 11, 2026
Apr 11, 2026
2.9 LOW
CVE-2026-40354 — Flatpak xdg-desktop-portal Privilege Escalation Vulnerability

Flatpak xdg-desktop-portal before 1.20.4 and 1.21.x before 1.21.1 allows any Flatpak app to trash any file in the host context via a symlink attack on g_file_trash.

| Path Traversal
Apr 11, 2026 Apr 11, 2026
Apr 11, 2026
Apr 11, 2026
5.3 MEDIUM
CVE-2026-3691 — OpenClaw Client PKCE Verifier Information Disclosure Vulnerability

OpenClaw Client PKCE Verifier Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose stored credentials on affected installations of OpenClaw. User interaction i…

openclaw | Information Disclosure
Apr 11, 2026 Apr 11, 2026
Apr 11, 2026
Apr 11, 2026
7.4 HIGH
CVE-2026-3690 — OpenClaw Canvas Authentication Bypass Vulnerability

OpenClaw Canvas Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of OpenClaw. Authentication is not required to explo…

openclaw | Authentication
Apr 11, 2026 Apr 11, 2026
Apr 11, 2026
Apr 11, 2026
6.5 MEDIUM
CVE-2026-3689 — OpenClaw Canvas Path Traversal Information Disclosure Vulnerability

OpenClaw Canvas Path Traversal Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of OpenClaw. Authentication…

openclaw | Path Traversal
Apr 11, 2026 Apr 11, 2026
Apr 11, 2026
Apr 11, 2026
0.0 NA
CVE-2026-40199 — Net::CIDR::Lite versions before 0.23 for Perl mishandles IPv4 mapped IPv6 addresses, whic…

Net::CIDR::Lite versions before 0.23 for Perl mishandles IPv4 mapped IPv6 addresses, which may allow IP ACL bypass. _pack_ipv6() includes the sentinel byte from _pack_ipv4() when building the packed…

| Misconfiguration
Apr 10, 2026 Apr 10, 2026
Apr 10, 2026
Apr 10, 2026
0.0 NA
CVE-2026-40198 — Net::CIDR::Lite versions before 0.23 for Perl does not validate IPv6 group count, which m…

Net::CIDR::Lite versions before 0.23 for Perl does not validate IPv6 group count, which may allow IP ACL bypass. _pack_ipv6() does not check that uncompressed IPv6 addresses (without ::) have exactl…

| Misconfiguration
Apr 10, 2026 Apr 10, 2026
Apr 10, 2026
Apr 10, 2026
5.4 MEDIUM
CVE-2026-33119 — Microsoft Edge (Chromium-based) for Android Spoofing Vulnerability

User interface (ui) misrepresentation of critical information in Microsoft Edge (Chromium-based) allows an unauthorized attacker to perform spoofing over a network.

Apr 10, 2026 Apr 10, 2026
Apr 10, 2026
Apr 10, 2026
4.3 MEDIUM
CVE-2026-33118 — Microsoft Edge (Chromium-based) Spoofing Vulnerability

Microsoft Edge (Chromium-based) Spoofing Vulnerability

Apr 10, 2026 Apr 10, 2026
Apr 10, 2026
Apr 10, 2026
6.3 MEDIUM
CVE-2026-5724 — Missing Authentication on Streaming gRPC Replication Endpoint

The frontend gRPC server's streaming interceptor chain did not include the authorization interceptor. When a ClaimMapper and Authorizer are configured, unary RPCs enforce authentication and authoriza…

Remote | Authorization
Apr 10, 2026 Apr 10, 2026
Apr 10, 2026
Apr 10, 2026
5.3 MEDIUM
CVE-2026-40252 — Broken Access Control (IDOR) Leading to Cross-Tenant Application Access in FastGPT

FastGPT is an AI Agent building platform. Prior to 4.14.10.4, Broken Access Control vulnerability (IDOR/BOLA) allows any authenticated team to access and execute applications belonging to other teams…

fastgpt | Remote | Authorization
Apr 10, 2026 Apr 10, 2026
Apr 10, 2026
Apr 10, 2026
Showing 20 of 6347 Results