Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.9 MEDIUM
CVE-2026-39935 — XSS-via-i18n in localised wiki names

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foundation Mediawiki - CampaignEvents Extension allows Cross-Site Scripting (XSS).T…

Remote | Cross-Site Scripting
Apr 07, 2026 Apr 07, 2026
Apr 07, 2026
Apr 07, 2026
6.9 MEDIUM
CVE-2025-20628 — Insufficient granularity of access control for Remote Connector Servers in client mode

An insufficient granularity of access control vulnerability exists in PingIDM (formerly ForgeRock Identity Management) where administrators cannot properly configure access rules for Remote Connector…

Remote | Authorization
Apr 07, 2026 Apr 07, 2026
Apr 07, 2026
Apr 07, 2026
5.4 MEDIUM
CVE-2026-4065 — Smart Slider 3 <= 3.5.1.33 - Missing Authorization to Authenticated (Contributor+) Slider…

The Smart Slider 3 plugin for WordPress is vulnerable to unauthorized access and modification of data due to missing capability checks on multiple wp_ajax_smart-slider3 controller actions in all vers…

Remote | Authorization
Apr 07, 2026 Apr 07, 2026
Apr 07, 2026
Apr 07, 2026
8.8 HIGH
CVE-2026-39937 — Global vanishing does not completely remove user email

Improper removal of sensitive information before storage or transfer vulnerability in The Wikimedia Foundation Mediawiki - CentralAuth Extension allows Resource Leak Exposure.This issue affects non r…

Remote | Information Disclosure
Apr 07, 2026 Apr 07, 2026
Apr 07, 2026
Apr 07, 2026
6.9 MEDIUM
CVE-2026-39934 — Growth Experiments ReassignMenteesJob runs as an infinite loop

Loop with unreachable exit condition ('infinite loop') vulnerability in The Wikimedia Foundation Mediawiki - GrowthExperiments Extension allows Leveraging Time-of-Check and Time-of-Use (TOCTOU) Race …

Remote | Race Condition
Apr 07, 2026 Apr 07, 2026
Apr 07, 2026
Apr 07, 2026
10.0 CRITICAL
CVE-2026-39933 — Multiple XSS vulnerabilities in GlobalWatchlist

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foundation Mediawiki - GlobalWatchlist Extension allows Cross-Site Scripting (XSS).…

Remote | Cross-Site Scripting
Apr 07, 2026 Apr 07, 2026
Apr 07, 2026
Apr 07, 2026
9.1 CRITICAL
CVE-2026-39847 — Emmett has a path traversal in internal assets handler

Emmett is a full-stack Python web framework designed with simplicity. From 2.5.0 to before 2.8.1, the RSGI static handler for Emmett's internal assets (/__emmett__ paths) is vulnerable to path traver…

Remote | Path Traversal
Apr 07, 2026 Apr 07, 2026
Apr 07, 2026
Apr 07, 2026
9.0 CRITICAL
CVE-2026-39846 — SiYuan affected by Remote Code Execution in the Electron desktop client via stored XSS in…

SiYuan is a personal knowledge management system. Prior to 3.6.4, a malicious note synced to another user can trigger remote code execution in the SiYuan Electron desktop client. The root cause is th…

siyuan | Remote | Cross-Site Scripting
Apr 07, 2026 Apr 08, 2026
Apr 07, 2026
Apr 08, 2026
7.6 HIGH
CVE-2026-35568 — MCP Java-SDK has a DNS Rebinding Vulnerability

MCP Java SDK is the official Java SDK for Model Context Protocol servers and clients. Prior to 1.0.0, the java-sdk contains a DNS rebinding vulnerability. This vulnerability allows an attacker to acc…

Remote | Server-Side Request Forgery
Apr 07, 2026 Apr 07, 2026
Apr 07, 2026
Apr 07, 2026
6.2 MEDIUM
CVE-2026-35406 — Aardvark-dns has incorrect error handling for malformed tcp packets

Aardvark-dns is an authoritative dns server for A/AAAA container records. From 1.16.0 to 1.17.0, a truncated TCP DNS query followed by a connection reset causes aardvark-dns to enter an unrecoverable…

aardvark-dns | Denial of Service
Apr 07, 2026 Apr 07, 2026
Apr 07, 2026
Apr 07, 2026
2.8 LOW
CVE-2026-34781 — Electron crashes in clipboard.readImage() on malformed clipboard image data

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.5, 40.8.5, 41.1.0, and 42.0.0-alpha.5, apps that call clipboard.readImage() may b…

electron | Denial of Service
Apr 07, 2026 Apr 07, 2026
Apr 07, 2026
Apr 07, 2026
6.0 MEDIUM
CVE-2026-34765 — Electron named window.open targets not scoped to the opener's browsing context

Electron is a framework for writing cross-platform desktop applications using JavaScript, HTML and CSS. Prior to 39.8.5, 40.8.5, 41.1.0, and 42.0.0-alpha.5, when a renderer calls window.open() with a…

electron | Remote | Misconfiguration
Apr 07, 2026 Apr 07, 2026
Apr 07, 2026
Apr 07, 2026
8.7 HIGH
CVE-2026-34582 — Botan has a TLS 1.3 certificate authentication bypass

Botan is a C++ cryptography library. Prior to version 3.11.1, the TLS 1.3 implementation allowed ApplicationData records to be processed prior to the Finished message being received. A server which i…

botan | Remote | Authentication
Apr 07, 2026 Apr 07, 2026
Apr 07, 2026
Apr 07, 2026
9.3 CRITICAL
CVE-2026-34580 — Botan has a certificate authentication bypass due to trust anchor confusion

Botan is a C++ cryptography library. In 3.11.0, the function Certificate_Store::certificate_known had a misleading name; it would return true if any certificate in the store had a DN (and subject key…

botan | Remote | Authentication
Apr 07, 2026 Apr 07, 2026
Apr 07, 2026
Apr 07, 2026
6.3 MEDIUM
CVE-2026-34371 — LibreChat Affected by Arbitrary File Write via `execute_code` Artifact Filename Traversal

LibreChat is a ChatGPT clone with additional features. Prior to 0.8.4, LibreChat trusts the name field returned by the execute_code sandbox when persisting code-generated artifacts. On deployments us…

librechat | Remote | Path Traversal
Apr 07, 2026 Apr 07, 2026
Apr 07, 2026
Apr 07, 2026
8.7 HIGH
CVE-2026-34079 — Flatpak affected by arbitrary file deletion on the host filesystem

Flatpak is a Linux application sandboxing and distribution framework. Prior to 1.16.4, the caching for ld.so removes outdated cache files without properly checking that the app controlled path to the…

flatpak | Remote | Path Traversal
Apr 07, 2026 Apr 07, 2026
Apr 07, 2026
Apr 07, 2026
9.3 CRITICAL
CVE-2026-34078 — Flatpak has a complete sandbox escape leading to host file access and code execution in t…

Flatpak is a Linux application sandboxing and distribution framework. Prior to 1.16.4, the Flatpak portal accepts paths in the sandbox-expose options which can be app-controlled symlinks pointing at …

flatpak | Remote | Path Traversal
Apr 07, 2026 Apr 07, 2026
Apr 07, 2026
Apr 07, 2026
7.5 HIGH
CVE-2026-31790 — Incorrect Failure Handling in RSA KEM RSASVE Encapsulation

Issue summary: Applications using RSASVE key encapsulation to establish a secret encryption key can send contents of an uninitialized memory buffer to a malicious peer. Impact summary: The uninitial…

openssl | Remote | Memory Corruption
Apr 07, 2026 Apr 08, 2026
Apr 07, 2026
Apr 08, 2026
0.0 NA
CVE-2026-31789 — Heap Buffer Overflow in Hexadecimal Conversion

Issue summary: Converting an excessively large OCTET STRING value to a hexadecimal string leads to a heap buffer overflow on 32 bit platforms. Impact summary: A heap buffer overflow may lead to a cr…

openssl | Memory Corruption
Apr 07, 2026 Apr 07, 2026
Apr 07, 2026
Apr 07, 2026
0.0 NA
CVE-2026-28390 — Possible NULL Dereference When Processing CMS KeyTransportRecipientInfo

Issue summary: During processing of a crafted CMS EnvelopedData message with KeyTransportRecipientInfo a NULL pointer dereference can happen. Impact summary: Applications that process attacker-contr…

openssl | Denial of Service
Apr 07, 2026 Apr 07, 2026
Apr 07, 2026
Apr 07, 2026
Showing 20 of 6409 Results