Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.8 HIGH
CVE-2026-43985 — Taultulli has CSRF in /configUpdate via missing anti-CSRF and method restriction that all…

Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Versions prior to 2.17.1 expose `configUpdate` as a state-changing administrator endpoint, but the route does not enforc…

Remote | Cross-Site Request Forgery
Jun 04, 2026 Jun 04, 2026
Jun 04, 2026
Jun 04, 2026
8.9 HIGH
CVE-2026-43984 — Tautulli has stored XSS in logFile via guest-controlled log_js_errors input

Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Versions prior to 2.17.1 expose `log_js_errors` to any authenticated user, including guest users when guest access is en…

Remote | Cross-Site Scripting
Jun 04, 2026 Jun 04, 2026
Jun 04, 2026
Jun 04, 2026
5.3 MEDIUM
CVE-2026-41178 — OpenTelemetry-Go's baggage parsing no longer caps raw header length

OpenTelemetry-Go is the Go implementation of OpenTelemetry. Versions 1.41.0 and 1.43.0 removed raw-length rejection and it causes `Parse` to process arbitrarily large/invalid baggage headers and log …

Remote | Denial of Service
Jun 04, 2026 Jun 04, 2026
Jun 04, 2026
Jun 04, 2026
5.4 MEDIUM
CVE-2026-40930 — LIBPNG: Chunk smuggling in push-mode APNG parser via unconsumed chunk body

LIBPNG is a reference library for use in applications that process PNG (Portable Network Graphics) raster image files. In version 1.8.0, three inter-frame chunk discard paths in the push-mode APNG pa…

Remote | Memory Corruption
Jun 04, 2026 Jun 04, 2026
Jun 04, 2026
Jun 04, 2026
0.0 NA
CVE-2026-38570 — bacnet_stack Out-of-bounds Read

bacnet_stack 1.3.1 contains an Out-of-bounds Read in bacnet_tag_number_decode which allows attackers to cause a denial of service.

| Denial of Service
Jun 04, 2026 Jun 04, 2026
Jun 04, 2026
Jun 04, 2026
0.0 NA
CVE-2026-36182 — GNCC GP5 Weak Password Hashing

GNCC GP5 v7.1.76 was discovered to utilize a weak hashing algorithm to protect the root password, possibly allowing attackers to obtain root credentials and privileges via a bruteforce attack.

| Cryptography
Jun 04, 2026 Jun 04, 2026
Jun 04, 2026
Jun 04, 2026
9.0 CRITICAL
CVE-2026-10868 — MISP user edit endpoint mass assignment vulnerability allows unauthorized user account mo…

A mass assignment vulnerability exists in the MISP user edit functionality due to insufficient filtering of user-supplied fields in UsersController::edit(). When processing edit requests, the applica…

Remote | Authorization
Jun 04, 2026 Jun 04, 2026
Jun 04, 2026
Jun 04, 2026
6.5 MEDIUM
CVE-2026-10815 — LakshayD02 Hostel-Management-System-PHP Admin Dashboard index.php authorization

A vulnerability was found in LakshayD02 Hostel-Management-System-PHP up to f87e67c283bab6f718faf2fec6ae39a13bd7036b. This issue affects some unknown processing of the file hostel/index.php of the com…

Remote | Authorization
Jun 04, 2026 Jun 04, 2026
Jun 04, 2026
Jun 04, 2026
4.5 MEDIUM
CVE-2026-10814 — milvus-io milvus Grantee ID Hash kv_catalog.go weak hash

A vulnerability has been found in milvus-io milvus up to 2.6.13. This vulnerability affects unknown code of the file internal/metastore/kv/rootcoord/kv_catalog.go of the component Grantee ID Hash Han…

| Cryptography
Jun 04, 2026 Jun 04, 2026
Jun 04, 2026
Jun 04, 2026
3.6 LOW
CVE-2026-10813 — LMCache KV Cache utils.py hex_hash_to_int16 weak hash

A flaw has been found in LMCache up to 0.4.6. This affects the function hex_hash_to_int16 of the file lmcache/integration/vllm/utils.py of the component KV Cache Handler. Executing a manipulation can…

| Cryptography
Jun 04, 2026 Jun 04, 2026
Jun 04, 2026
Jun 04, 2026
5.3 MEDIUM
CVE-2026-47707 — Strawberry GraphQL's Bypass of MaxAliasesLimiter via Fragment Spreads leading to GraphQL …

Strawberry GraphQL is a library for creating GraphQL APIs. In versions 0.172.0 through0.315.6, the MaxAliasesLimiter extension in Strawberry fails to account for the multiplicative/amplification effe…

Remote | Denial of Service
Jun 04, 2026 Jun 04, 2026
Jun 04, 2026
Jun 04, 2026
5.3 MEDIUM
CVE-2026-47706 — Strawberry GraphQL has a Circular Fragment Reference DOS

Strawberry GraphQL is a library for creating GraphQL APIs. In versions 0.71.0 through 0.315.6, the QueryDepthLimiter extension is vulnerable to an Application-level DOS due to a lack of cycle detecti…

Remote | Denial of Service
Jun 04, 2026 Jun 04, 2026
Jun 04, 2026
Jun 04, 2026
3.1 LOW
CVE-2026-45739 — Strawberry GraphQL: Default GraphiQL may expose HTTP headers in URLs

Strawberry GraphQL is a library for creating GraphQL APIs. In versions 0.288.4 through 0.315.3, Strawberry's bundled GraphiQL template wrote values from the GraphiQL headers editor into the browser U…

strawberry_graphql | Remote | Information Disclosure
Jun 04, 2026 Jun 04, 2026
Jun 04, 2026
Jun 04, 2026
8.9 HIGH
CVE-2026-41065 — Tautulli Vulnerable to Unauthenticated/Authenticated Remote Code Execution via Newsletter…

Tautulli is a Python based monitoring and tracking tool for Plex Media Server. Versions prior to 2.17.1 are vulnerable to remote code execution via the newsletter custom template directory feature. O…

Remote | Authentication
Jun 04, 2026 Jun 04, 2026
Jun 04, 2026
Jun 04, 2026
0.0 NA
CVE-2026-36180 — GNCC GP5 Runtime Integrity Bypass Leading to File System Modification

A lack of runtime integrity in GNCC GP5 v7.1.76 allows physically-proximate attackers to bypass file system read-only protections and modify system files and binaries for the duration of a boot sessi…

| Misconfiguration
Jun 04, 2026 Jun 04, 2026
Jun 04, 2026
Jun 04, 2026
4.6 MEDIUM
CVE-2026-36178 — GNCC GP5: Cryptographic Material Leakage After Factory Reset

The factory reset functionality in GNCC GP5 v7.1.76 fails to clear sensitive cryptographic material in the JFFS2 configuration partition, possibly allowing attackers to recover and obtain sensitive u…

| Cryptography
Jun 04, 2026 Jun 04, 2026
Jun 04, 2026
Jun 04, 2026
7.1 HIGH
CVE-2026-36176 — GNCC GP5 Plaintext Storage of Backblaze B2 Upload URLs

GNCC GP5 v7.1.76 was discovered to store pre-signed Backblaze B2 upload URLs (PUT requests) in plaintext to the serial console. This allows physically-proximate attackers to extract these active toke…

| Information Disclosure
Jun 04, 2026 Jun 04, 2026
Jun 04, 2026
Jun 04, 2026
6.8 MEDIUM
CVE-2026-36175 — GNCC GP5 U-Boot Authentication Bypass leading to Root Access

An issue in the U-Boot component of GNCC GP5 v7.1.76 allows physically-proximate attackers to bypass authentication and gain root access via interrupting the boot sequence and injecting a crafted str…

| Authentication
Jun 04, 2026 Jun 04, 2026
Jun 04, 2026
Jun 04, 2026
0.0 NA
CVE-2026-36174 — GNCC GP5 Plaintext Sensitive Wireless Information Storage

GNCC GP5 v7.1.76 was discovered to store sensitive wireless network information in plaintext during routine operations to the serial console. This issue allows physically-proximate attackers to obtai…

| Information Disclosure
Jun 04, 2026 Jun 04, 2026
Jun 04, 2026
Jun 04, 2026
9.6 CRITICAL
CVE-2026-35906 — T3 Technology CPE Command Injection

An undocumented debug CGI endpoint in T3 Technology CPE models T625Pro v1.0.07, T6825G v1.0.03 allows unauthenticated attackers to execute arbitrary system commands as root via supplying a crafted HT…

Remote | Authentication
Jun 04, 2026 Jun 04, 2026
Jun 04, 2026
Jun 04, 2026
Showing 20 of 7151 Results