Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.9 MEDIUM
CVE-2026-8106 — Reflected HTML injection vulnerability in GitHub Enterprise Server Management Console log…

A reflected HTML injection vulnerability was identified in the GitHub Enterprise Server Management Console login page that could allow credential theft. The redirect_to query parameter on the /setup/…

Remote | Cross-Site Scripting
May 07, 2026 May 07, 2026
May 07, 2026
May 07, 2026
7.9 HIGH
CVE-2026-8034 — Server-side request forgery vulnerability in GitHub Enterprise Server notebook viewer via…

A server-side request forgery (SSRF) vulnerability was identified in the GitHub Enterprise Server notebook viewer that allowed an attacker to access internal services by exploiting URL parser confusi…

Remote | Server-Side Request Forgery
May 07, 2026 May 07, 2026
May 07, 2026
May 07, 2026
9.3 CRITICAL
CVE-2026-7891 — Mendix Studio Pro Anonymous User Role Inheritance Authorization Bypass

The VerySecureApp made by DIVD using Mendix Studio Pro 11.8.0 Beta allows unintended data exposure due to authorization misconfiguration. The VerySecureApp allows anonymous users of the MyFirstModule…

Remote | Authorization
May 07, 2026 May 07, 2026
May 07, 2026
May 07, 2026
6.3 MEDIUM
CVE-2026-7541 — Denial of service vulnerability in GitHub Enterprise Server allowed service disruption vi…

A denial of service vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to cause service disruption by sending crafted requests with deeply nested JSON p…

Remote | Denial of Service
May 07, 2026 May 07, 2026
May 07, 2026
May 07, 2026
6.3 MEDIUM
CVE-2026-6736 — Authentication bypass vulnerability in GitHub Enterprise Server allowed creation of local…

An authentication bypass vulnerability was identified in GitHub Enterprise Server that allowed an unauthenticated attacker to create a local user account, bypassing the configured external identity p…

Remote | Authentication
May 07, 2026 May 07, 2026
May 07, 2026
May 07, 2026
10.0 CRITICAL
CVE-2026-42826 — Azure DevOps Information Disclosure Vulnerability

Exposure of sensitive information to an unauthorized actor in Azure DevOps allows an unauthorized attacker to disclose information over a network.

May 07, 2026 May 07, 2026
May 07, 2026
May 07, 2026
6.1 MEDIUM
CVE-2026-41929 — Vvveb < 1.0.8.2 Unauthenticated Reflected XSS via Visual Editor

Vvveb before 1.0.8.2 contains an unauthenticated reflected cross-site scripting vulnerability in the visual editor preview renderer that allows attackers to execute arbitrary JavaScript by manipulati…

Remote | Cross-Site Scripting
May 07, 2026 May 07, 2026
May 07, 2026
May 07, 2026
5.3 MEDIUM
CVE-2026-41928 — Vvveb < 1.0.8.2 Information Disclosure via Cron Controller

Vvveb before 1.0.8.2 contains an information disclosure vulnerability in the cron controller that allows unauthenticated attackers to retrieve the application's secret cron key. Attackers can access …

Remote | Information Disclosure
May 07, 2026 May 07, 2026
May 07, 2026
May 07, 2026
8.1 HIGH
CVE-2026-41105 — Azure Monitor Action Group Notification System Elevation of Privilege Vulnerability

Server-side request forgery (ssrf) in Azure Notification Service allows an authorized attacker to elevate privileges over a network.

May 07, 2026 May 07, 2026
May 07, 2026
May 07, 2026
6.3 MEDIUM
CVE-2026-40214 — OpenStack Cyborg Accelerator Request API Cross-Tenant Denial of Service

In OpenStack Cyborg before 16.0.1, the Accelerator Request (ARQ) API does not enforce project ownership at any layer. The project_id column in the database is never populated (NULL for every ARQ), da…

Remote | Authorization
May 07, 2026 May 07, 2026
May 07, 2026
May 07, 2026
7.4 HIGH
CVE-2026-40213 — OpenStack Cyborg Default Policy Authorization Bypass

OpenStack Cyborg before 16.0.1 uses rule:allow (check_str='@') as the default policy for multiple API endpoints. This unconditionally authorizes any request carrying a valid Keystone token regardless…

Remote | Authorization
May 07, 2026 May 07, 2026
May 07, 2026
May 07, 2026
8.6 HIGH
CVE-2026-35435 — Azure AI Foundry Elevation of Privilege Vulnerability

Improper access control in Azure AI Foundry M365 published agents allows an unauthorized attacker to elevate privileges over a network.

May 07, 2026 May 07, 2026
May 07, 2026
May 07, 2026
9.6 CRITICAL
CVE-2026-35428 — Azure Cloud Shell Spoofing Vulnerability

Improper neutralization of special elements used in a command ('command injection') in Azure Cloud Shell allows an unauthorized attacker to perform spoofing over a network.

May 07, 2026 May 07, 2026
May 07, 2026
May 07, 2026
8.2 HIGH
CVE-2026-34327 — Microsoft Partner Center Spoofing Vulnerability

Externally controlled reference to a resource in another sphere in Microsoft Partner Center allows an unauthorized attacker to perform spoofing over a network.

May 07, 2026 May 07, 2026
May 07, 2026
May 07, 2026
9.0 CRITICAL
CVE-2026-33844 — Azure Managed Instance for Apache Cassandra Remote Code Execution Vulnerability

Improper input validation in Azure Managed Instance for Apache Cassandra allows an authorized attacker to execute code over a network.

May 07, 2026 May 07, 2026
May 07, 2026
May 07, 2026
9.6 CRITICAL
CVE-2026-33823 — Microsoft Team Events Portal Information Disclosure Vulnerability

Improper authorization in Microsoft Teams allows an authorized attacker to disclose information over a network.

May 07, 2026 May 07, 2026
May 07, 2026
May 07, 2026
7.5 HIGH
CVE-2026-33111 — Copilot Chat (Microsoft Edge) Information Disclosure Vulnerability

Improper neutralization of special elements used in a command ('command injection') in Copilot Chat (Microsoft Edge) allows an unauthorized attacker to disclose information over a network.

May 07, 2026 May 07, 2026
May 07, 2026
May 07, 2026
9.9 CRITICAL
CVE-2026-33109 — Azure Managed Instance for Apache Cassandra Remote Code Execution Vulnerability

Improper access control in Azure Managed Instance for Apache Cassandra allows an authorized attacker to execute code over a network.

May 07, 2026 May 07, 2026
May 07, 2026
May 07, 2026
8.8 HIGH
CVE-2026-32207 — Azure Machine Learning Notebook Spoofing Vulnerability

Improper neutralization of input during web page generation ('cross-site scripting') in Azure Machine Learning allows an unauthorized attacker to perform spoofing over a network.

May 07, 2026 May 07, 2026
May 07, 2026
May 07, 2026
7.5 HIGH
CVE-2026-26164 — M365 Copilot Information Disclosure Vulnerability

Improper neutralization of special elements in output used by a downstream component ('injection') in M365 Copilot allows an unauthorized attacker to disclose information over a network.

May 07, 2026 May 07, 2026
May 07, 2026
May 07, 2026
Showing 20 of 5843 Results