Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.5 MEDIUM
CVE-2026-4683 — Smartcat Translator for WPML <= 3.1.77 - Missing Authorization to Unauthenticated Plugin …

The Smartcat Translator for WPML plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'routeData' REST endpoint in all versions up to, and …

Remote | Authentication
May 15, 2026 May 15, 2026
May 15, 2026
May 15, 2026
8.6 HIGH
CVE-2026-44088 — Remote Code Execution in SzafirHost

SzafirHost verifies the signature of the downloaded JAR file using class JarInputStream (reading from the beginning of the file), but loads classes using class JarFile/URLClassLoader (reading the Cen…

Remote | Supply Chain
May 15, 2026 May 15, 2026
May 15, 2026
May 15, 2026
8.7 HIGH
CVE-2026-8654 — Delphix Command Injection Vulnerability

Improper input validation in Delphix Continuous Data connectors allows an authenticated user to execute arbitrary operating system commands on the staging or target host.

Remote | Injection
May 15, 2026 May 15, 2026
May 15, 2026
May 15, 2026
6.4 MEDIUM
CVE-2026-6646 — The7 <= 14.3.2 - Authenticated (Contributor+) Stored Cross-Site Scripting via Shortcode '…

The The7 theme for WordPress is vulnerable to Stored Cross-Site Scripting via the 'dt_default_button' shortcode in all versions up to, and including, 14.3.2. This is due to insufficient input sanitiz…

Remote | Cross-Site Scripting
May 15, 2026 May 15, 2026
May 15, 2026
May 15, 2026
8.1 HIGH
CVE-2026-4094 — FOX – Currency Switcher Professional for WooCommerce <= 1.4.5 - Missing Authorization to …

The FOX – Currency Switcher Professional for WooCommerce plugin for WordPress is vulnerable to unauthorized data loss due to a missing capability check on the 'admin_head' function in all versions up…

Remote | Authorization
May 15, 2026 May 15, 2026
May 15, 2026
May 15, 2026
7.8 HIGH
CVE-2026-41702 — TOCTOU local privilege escalation vulnerability

VMware Fusion contains a TOCTOU (Time-of-check Time-of-use) vulnerability that occurs during an operation performed by a SETUID binary. A malicious actor with local non-administrative user privileges…

| Race Condition
May 15, 2026 May 15, 2026
May 15, 2026
May 15, 2026
0.0 NA
CVE-2026-43490 — ksmbd: validate inherited ACE SID length

In the Linux kernel, the following vulnerability has been resolved: ksmbd: validate inherited ACE SID length smb_inherit_dacl() walks the parent directory DACL loaded from the security descriptor x…

| Memory Corruption
May 15, 2026 May 15, 2026
May 15, 2026
May 15, 2026
8.1 HIGH
CVE-2026-28761 — Musetheque V4 Cross-Site Request Forgery (CSRF)

Cross-site request forgery vulnerability exists in Musetheque V4 Information Disclosure for IPKNOWLEDGE V4L1 rev2203.0 and earlier. If a user views a malicious page while logged-in to the affected pr…

Remote | Cross-Site Request Forgery
May 15, 2026 May 15, 2026
May 15, 2026
May 15, 2026
5.4 MEDIUM
CVE-2026-24662 — Musetheque V4 Cross-Site Scripting (XSS)

Cross-site scripting vulnerability exists in Musetheque V4 Information Disclosure for IPKNOWLEDGE V4L1 rev2203.0 and earlier. If a file containing malicious contents is uploaded, an arbitrary script …

Remote | Cross-Site Scripting
May 15, 2026 May 15, 2026
May 15, 2026
May 15, 2026
9.2 CRITICAL
CVE-2026-0481 — AMD Device Metrics Exporter Unauthenticated Remote Configuration Manipulation Vulnerabili…

Unrestricted IP address binding in the AMD Device Metrics Exporter (ROCm ecosystem) could allow a remote attacker to perform unauthorized changes to the GPU configuration, potentially resulting in lo…

Remote | Misconfiguration
May 15, 2026 May 15, 2026
May 15, 2026
May 15, 2026
7.3 HIGH
CVE-2025-54518 — AMD Zen 2 CPU Cache Privilege Escalation

Improper isolation of shared resources within the CPU operation cache on Zen 2-based products could allow an attacker to corrupt instructions executed at a different privilege level, potentially resu…

| Memory Corruption
May 15, 2026 May 15, 2026
May 15, 2026
May 15, 2026
2.0 LOW
CVE-2025-52532 — AMD MxGPU-Virtualization Driver Heap-Based Buffer Overflow

A race condition in the MxGPU-Virtualization driver’s ioctl path caused by concurrent unsynchronized access to the global variable amdgv_cmd in an unlocked ioctl handler could be exploited by an atta…

| Race Condition
May 15, 2026 May 15, 2026
May 15, 2026
May 15, 2026
7.0 HIGH
CVE-2024-36334 — AMD Radeon RGB Tool Cryptographic Signature Verification Bypass

Improper verification of cryptographic signature in the Radeon RGB tool could allow a malicious file placed in the installation directory to be run with elevated privileges potentially leading to arb…

| Cryptography
May 15, 2026 May 15, 2026
May 15, 2026
May 15, 2026
7.0 HIGH
CVE-2024-36333 — AMD Cleanup Utility DLL Hijacking Privilege Escalation Vulnerability

A DLL hijacking vulnerability in the AMD Cleanup Utility could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution.

| Misconfiguration
May 15, 2026 May 15, 2026
May 15, 2026
May 15, 2026
8.8 HIGH
CVE-2024-36323 — Apache JPEG HW Register Space Isolation Bypass

Improper isolation of VCN-JPEG HW register space could allow a malicious Guest Virtual Machine (VM) or a process to perform unauthorized access to the register space of the JPEG cores assigned a vict…

| Misconfiguration
May 15, 2026 May 15, 2026
May 15, 2026
May 15, 2026
1.8 LOW
CVE-2024-21950 — Cisco Remote Management Firmware Out-of-Bounds Read Vulnerability

An out of bounds read in the remote management firmware could allow a privileged attacker read a limited section of memory outside of established bounds potentially resulting in loss of confidentiali…

| Memory Corruption
May 15, 2026 May 15, 2026
May 15, 2026
May 15, 2026
8.5 HIGH
CVE-2026-7373 — Metasploit Pro on Windows: Local Privilege Escalation via OpenSSL Configuration File Load…

Rapid7 Metasploit Pro is vulnerable to a local privilege escalation attack that allows users to gain SYSTEM level control of a Windows host. Upon startup the metasploitPostgreSQL service the subseque…

| Misconfiguration
May 15, 2026 May 15, 2026
May 15, 2026
May 15, 2026
8.6 HIGH
CVE-2026-2652 — Authentication Bypass in mlflow/mlflow

A vulnerability in mlflow/mlflow versions 3.9.0 and earlier allows unauthenticated access to certain FastAPI routes when the server is started with authentication enabled (`--app-name basic-auth`) an…

Remote | Authentication
May 15, 2026 May 15, 2026
May 15, 2026
May 15, 2026
1.8 LOW
CVE-2026-0428 — "Qualcomm TEE SOC Driver SRIOV Chiplet Registers Write Remote Code Execution Vulnerabilit…

Insufficient parameter sanitization in TEE SOC Driver could allow an attacker to issue a malformed DRV_SOC_CMD_ID_SRIOV_COPY_VF_CHIPLET_REGS to write invalid data to a remote Die, potentially resulti…

| Injection
May 15, 2026 May 15, 2026
May 15, 2026
May 15, 2026
4.6 MEDIUM
CVE-2026-0427 — NVIDIA GPU Firmware Register Escalation Vulnerability

Improper cleanup of shared register resources in GPU firmware could allow an admin-privileged attacker from a Guest Virtual machine (VM) to access these shared resources from another Guest VM, potent…

| Misconfiguration
May 15, 2026 May 15, 2026
May 15, 2026
May 15, 2026
Showing 20 of 6343 Results