Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
2.7 LOW
CVE-2026-5375 — runZero Platform API credential information leak

An issue that could allow a user with access to a credential to view sensitive fields through an API response has been resolved. This is an instance of CWE-200: Exposure of Sensitive Information to a…

Remote | Information Disclosure
Apr 07, 2026 Apr 07, 2026
Apr 07, 2026
Apr 07, 2026
5.8 MEDIUM
CVE-2026-5374 — runZero Platform MCP information leak

An issue that allowed MCP agents to access remediation and asset information from outside of the authorized organization scope has been resolved. This is an instance of CWE-863: Incorrect Authorizati…

Remote | Authorization
Apr 07, 2026 Apr 07, 2026
Apr 07, 2026
Apr 07, 2026
8.1 HIGH
CVE-2026-5373 — runZero Platform superuser privilege escalation

An issue that allowed all-organization administrators to promote accounts to superuser status has been resolved. This is an instance of CWE-269: Improper Privilege Management, and has an estimated CV…

Remote | Authorization
Apr 07, 2026 Apr 07, 2026
Apr 07, 2026
Apr 07, 2026
6.4 MEDIUM
CVE-2026-5372 — runZero Platform SQL injection in saved queries

An issue that allowed a SQL injection attack vector related to saved queries (introduced in version 4.0.260123.0). This is an instance of CWE-89: Improper Neutralization of Special Elements used in a…

Remote | Injection
Apr 07, 2026 Apr 07, 2026
Apr 07, 2026
Apr 07, 2026
8.2 HIGH
CVE-2026-4740 — Rhacm: open cluster management (ocm): cross-cluster privilege escalation via improper kub…

A flaw was found in Open Cluster Management (OCM), the technology underlying Red Hat Advanced Cluster Management (ACM). Improper validation of Kubernetes client certificate renewal allows a managed c…

| Authentication
Apr 07, 2026 Apr 07, 2026
Apr 07, 2026
Apr 07, 2026
2.7 LOW
CVE-2026-4292 — Privilege abuse in ModelAdmin.list_editable

An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. Admin changelist forms using `ModelAdmin.list_editable` incorrectly allowed new instances to be created via for…

Remote | Authorization
Apr 07, 2026 Apr 07, 2026
Apr 07, 2026
Apr 07, 2026
0.0 NA
CVE-2026-4277 — Privilege abuse in GenericInlineModelAdmin

An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. Add permissions on inline model instances were not validated on submission of forged `POST` data in `GenericInl…

| Authorization
Apr 07, 2026 Apr 07, 2026
Apr 07, 2026
Apr 07, 2026
0.0 NA
CVE-2026-3902 — ASGI header spoofing via underscore/hyphen conflation

An issue was discovered in 6.0 before 6.0.4, 5.2 before 5.2.13, and 4.2 before 4.2.30. `ASGIRequest` allows a remote attacker to spoof headers by exploiting an ambiguous mapping of two header variant…

| Misconfiguration
Apr 07, 2026 Apr 07, 2026
Apr 07, 2026
Apr 07, 2026
7.5 HIGH
CVE-2026-35485 — text-generation-webui has a Path Traversal in load_grammar() — arbitrary file read withou…

text-generation-webui is an open-source web interface for running Large Language Models. Prior to 4.3, an unauthenticated path traversal vulnerability in load_grammar() allows reading any file on the…

Remote | Path Traversal
Apr 07, 2026 Apr 07, 2026
Apr 07, 2026
Apr 07, 2026
5.3 MEDIUM
CVE-2026-35484 — text-generation-webui has a Path Traversal in load_preset() — .yaml file read without aut…

text-generation-webui is an open-source web interface for running Large Language Models. Prior to 4.3, an unauthenticated path traversal vulnerability in load_preset() allows reading any .yaml file o…

Remote | Path Traversal
Apr 07, 2026 Apr 07, 2026
Apr 07, 2026
Apr 07, 2026
5.3 MEDIUM
CVE-2026-35483 — text-generation-webui has a Path Traversal in load_template() — .jinja/.yaml/.yml file re…

text-generation-webui is an open-source web interface for running Large Language Models. Prior to 4.3, an unauthenticated path traversal vulnerability in load_template() allows reading files with .ji…

Remote | Path Traversal
Apr 07, 2026 Apr 07, 2026
Apr 07, 2026
Apr 07, 2026
6.2 MEDIUM
CVE-2026-35480 — go-ipld-prime's DAG-CBOR decoder unbounded memory allocation from CBOR headers

go-ipld-prime is an implementation of the InterPlanetary Linked Data (IPLD) spec interfaces, a batteries-included codec implementations of IPLD for CBOR and JSON, and tooling for basic operations on …

| Denial of Service
Apr 07, 2026 Apr 07, 2026
Apr 07, 2026
Apr 07, 2026
7.5 HIGH
CVE-2026-35464 — pyLoad has an incomplete fix for CVE-2026-33509: unprotected storage_folder enables arbit…

pyLoad is a free and open-source download manager written in Python. The fix for CVE-2026-33509 added an ADMIN_ONLY_OPTIONS set to block non-admin users from modifying security-critical config option…

Remote | Authentication
Apr 07, 2026 Apr 07, 2026
Apr 07, 2026
Apr 07, 2026
8.8 HIGH
CVE-2026-35463 — pyLoad has Improper Neutralization of Special Elements used in an OS Command

pyLoad is a free and open-source download manager written in Python. In 0.5.0b3.dev96 and earlier, the ADMIN_ONLY_OPTIONS protection mechanism restricts security-critical configuration values (reconn…

Remote | Misconfiguration
Apr 07, 2026 Apr 07, 2026
Apr 07, 2026
Apr 07, 2026
4.3 MEDIUM
CVE-2026-35462 — Papra Does Not Reject Expired API Keys

Papra is a minimalistic document management and archiving platform. Prior to 26.4.0, API keys with an expiresAt date are never validated against the current time during authentication. Any API key — …

Remote | Authentication
Apr 07, 2026 Apr 07, 2026
Apr 07, 2026
Apr 07, 2026
5.0 MEDIUM
CVE-2026-35461 — Papra has a Blind Server-Side Request Forgery (SSRF) via Webhook URL

Papra is a minimalistic document management and archiving platform. Prior to 26.4.0, the Papra webhook system allows authenticated users to register arbitrary URLs as webhook endpoints with no valida…

Remote | Server-Side Request Forgery
Apr 07, 2026 Apr 07, 2026
Apr 07, 2026
Apr 07, 2026
4.3 MEDIUM
CVE-2026-35460 — Papra has an HTML Injection in Transactional Emails via Unescaped User Display Name

Papra is a minimalistic document management and archiving platform. Prior to 26.4.0, transactional email templates in Papra interpolate user.name directly into HTML without escaping or sanitization. …

Remote | Cross-Site Scripting
Apr 07, 2026 Apr 07, 2026
Apr 07, 2026
Apr 07, 2026
8.7 HIGH
CVE-2026-35458 — Gotenberg has a ReDoS via extraHttpHeaders scope feature

Gotenberg is an API for converting document formats. In 8.29.1 and earlier, Gotenberg uses dlclark/regexp2 to compile user-supplied scope patterns without setting a proper timeout. Users with access …

Remote | Denial of Service
Apr 07, 2026 Apr 07, 2026
Apr 07, 2026
Apr 07, 2026
8.2 HIGH
CVE-2026-35457 — libp2p-rust has unbounded rendezvous DISCOVER cookies enable remote memory exhaustion

libp2p-rust is the official rust language Implementation of the libp2p networking stack. Prior to 0.17.1, the rendezvous server stores pagination cookies without bounds. An unauthenticated peer can r…

Remote | Denial of Service
Apr 07, 2026 Apr 07, 2026
Apr 07, 2026
Apr 07, 2026
7.5 HIGH
CVE-2026-35405 — libp2p-rendezvous: Unlimited namespace registrations per peer enables OOM DoS on rendezvo…

libp2p-rust is the official rust language Implementation of the libp2p networking stack. Prior to 0.17.1, libp2p-rendezvous server has no limit on how many namespaces a single peer can register. A m…

Remote | Denial of Service
Apr 07, 2026 Apr 07, 2026
Apr 07, 2026
Apr 07, 2026
Showing 20 of 6107 Results