Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-42308 — Pillow: Integer overflow when processing fonts

Pillow is a Python imaging library. Prior to version 12.2.0, if a font advances for each glyph by an exceeding large amount, when Pillow keeps track of the current position, it may lead to an integer…

| Memory Corruption
May 09, 2026 May 09, 2026
May 09, 2026
May 09, 2026
0.0 NA
CVE-2026-42309 — Pillow: Heap buffer overflow with nested list coordinates

Pillow is a Python imaging library. From version 11.2.1 to before version 12.2.0, passing nested lists as coordinates to APIs that accept coordinates such as ImagePath.Path, ImageDraw.ImageDraw.polyg…

| Memory Corruption
May 09, 2026 May 09, 2026
May 09, 2026
May 09, 2026
7.0 HIGH
CVE-2026-8207 — Gibbon SQL Injection Vulnerability

Gibbon versions before v30.0.01 are affected by an authenticated SQL Injection vulnerability by abusing the Tracking/graphing https://github.com/GibbonEdu/core/blob/c431e25fdc874adece5d2dc7e408e9aa2…

Remote | Injection
May 09, 2026 May 09, 2026
May 09, 2026
May 09, 2026
5.3 MEDIUM
CVE-2026-7652 — LatePoint <= 5.5.0 - Unauthenticated Account Takeover via Weak Password Recovery Mechanism

The LatePoint plugin for WordPress is vulnerable to Account Takeover via Weak Password Recovery Mechanism in the unauthenticated guest booking flow in versions up to, and including, 5.5.0 This is due…

Remote | Authentication
May 09, 2026 May 09, 2026
May 09, 2026
May 09, 2026
4.3 MEDIUM
CVE-2026-6667 — PgBouncer missing authorization check in KILL_CLIENT admin command

PgBouncer before 1.25.2 did not perform an appropriate authorization check for the KILL_CLIENT admin command. All users with access to the administration console (which itself requires authorization)…

| Authorization
May 09, 2026 May 09, 2026
May 09, 2026
May 09, 2026
5.9 MEDIUM
CVE-2026-6666 — PgBouncer crash in kill_pool_logins_server_error

A possible null pointer reference in PgBouncer before 1.25.2 could lead to a crash, if a server sends an error response without SQLSTATE field.

| Denial of Service
May 09, 2026 May 09, 2026
May 09, 2026
May 09, 2026
8.1 HIGH
CVE-2026-6665 — PgBouncer buffer overflow in SCRAM

The SCRAM code in PgBouncer before 1.25.2 did not check the return value of strlcat() correctly when building the contents of the SCRAM client-final-message. A malicious backend that sends a SCRAM se…

| Memory Corruption
May 09, 2026 May 09, 2026
May 09, 2026
May 09, 2026
7.5 HIGH
CVE-2026-6664 — PgBouncer integer overflow in PgBouncer network packet parsing

An integer overflow in network packet parsing code in PgBouncer before 1.25.2 bypasses a boundary check and can lead to a crash. An unauthenticated remote attacker can crash PgBouncer with a malforme…

| Denial of Service
May 09, 2026 May 09, 2026
May 09, 2026
May 09, 2026
8.6 HIGH
CVE-2026-41705 — Spring AI MilvusVectorStore Filter Expression Injection

Spring AI's MilvusVectorStore#doDelete(List) implementation is vulnerable to filter-expression injection via unsanitized document IDs. Spring AI 1.0.x: affected from 1.0.0 through latest 1.0.x; upgra…

Remote | Injection
May 09, 2026 May 09, 2026
May 09, 2026
May 09, 2026
9.1 CRITICAL
CVE-2026-44313 — LinkWarden: Server-Side Request Forgery (SSRF) in Link Creation via fetchTitleAndHeaders …

Linkwarden is a self-hosted, open-source collaborative bookmark manager to collect, organize and archive webpages. Prior to version 2.13.0, a Server-Side Request Forgery (SSRF) vulnerability in the f…

Remote | Server-Side Request Forgery
May 09, 2026 May 09, 2026
May 09, 2026
May 09, 2026
8.8 HIGH
CVE-2026-42455 — LinkWarden: Stored XSS via Client-Side Archive Upload (Unsanitized HTML served from same …

Linkwarden is a self-hosted, open-source collaborative bookmark manager to collect, organize and archive webpages. In versions 2.14.0 and prior, the archive upload endpoint (POST /api/v1/archives/[li…

Remote | Cross-Site Scripting
May 09, 2026 May 09, 2026
May 09, 2026
May 09, 2026
6.6 MEDIUM
CVE-2026-45130 — Vim: Heap Buffer Overflow in spell file loading

Vim is an open source, command line text editor. Prior to version 9.2.0450, a heap buffer overflow exists in read_compound() in src/spellfile.c when loading a crafted spell file (.spl) with UTF-8 enc…

| Memory Corruption
May 08, 2026 May 08, 2026
May 08, 2026
May 08, 2026
3.8 LOW
CVE-2026-44987 — SysReptor: Privilege Escalation from User Admin to Superuser

SysReptor is a fully customizable pentest reporting platform. Prior to version 2026.29, users with "User Admin" permissions can change the email addresses of users with "Superuser" permissions. If th…

Remote | Authentication
May 08, 2026 May 08, 2026
May 08, 2026
May 08, 2026
4.6 MEDIUM
CVE-2026-44656 — Vim: OS Command Injection via 'path' completion

Vim is an open source, command line text editor. Prior to version 9.2.0435, an OS command injection vulnerability exists in Vim's :find command-line completion. When the path option contains backtick…

| Injection
May 08, 2026 May 08, 2026
May 08, 2026
May 08, 2026
2.3 LOW
CVE-2026-44286 — FastGPT: SSRF Vulnerability in Laf Workflow Node via Missing Internal Address Validation

FastGPT is an AI Agent building platform. Prior to version 4.14.17, an unauthenticated Server-Side Request Forgery (SSRF) vulnerability allows attackers (or authenticated users with App editing privi…

Remote | Server-Side Request Forgery
May 08, 2026 May 08, 2026
May 08, 2026
May 08, 2026
6.3 MEDIUM
CVE-2026-44284 — FastGPT: Stored MCP tool URL SSRF in FastGPT workflow execution

FastGPT is an AI Agent building platform. Prior to version 4.14.17, FastGPT had an inconsistent SSRF protection gap in MCP tool URL handling. The direct MCP preview/run endpoints already rejected int…

Remote | Server-Side Request Forgery
May 08, 2026 May 08, 2026
May 08, 2026
May 08, 2026
8.9 HIGH
CVE-2026-42556 — Postiz stored XSS in public preview page

Postiz is an AI social media scheduling tool. From version 2.21.6 to before version 2.21.7, any authenticated user who can create a post can store arbitrary HTML in post content by tampering their ow…

Remote | Cross-Site Scripting
May 08, 2026 May 08, 2026
May 08, 2026
May 08, 2026
4.3 MEDIUM
CVE-2026-42456 — AnythingLLM: Cross-User TTS Audio Disclosure via Chat ID (IDOR)

AnythingLLM is an application that turns pieces of content into context that any LLM can use as references during chatting. Prior to version 1.12.1, GET /api/workspace/:slug/tts/:chatId in AnythingLL…

Remote | Authorization
May 08, 2026 May 08, 2026
May 08, 2026
May 08, 2026
9.9 CRITICAL
CVE-2026-42454 — Termix: OS Command Injection in Docker Container Management Endpoints

Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to version 2.1.0, all Docker container management endpoints in Termix interpolate t…

Remote | Injection
May 08, 2026 May 08, 2026
May 08, 2026
May 08, 2026
8.7 HIGH
CVE-2026-42453 — Termix: Command injection in extractArchive/compressFiles via double-quote escaping bypass

Termix is a web-based server management platform with SSH terminal, tunneling, and file editing capabilities. Prior to version 2.1.0, the extractArchive and compressFiles endpoints in file-manager.ts…

Remote | Injection
May 08, 2026 May 08, 2026
May 08, 2026
May 08, 2026
Showing 20 of 5790 Results