Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.1 HIGH
CVE-2026-37532 — AGL agl-service-can Heap Buffer Over-Read Vulnerability in isotp-c Library

AGL agl-service-can-low-level thru 17.1.12 contains a heap buffer over-read in the isotp-c library. In isotp_continue_receive (receive.c:87-89), the payload_length for a Single Frame is extracted fro…

| Memory Corruption
May 01, 2026 May 01, 2026
May 01, 2026
May 01, 2026
9.8 CRITICAL
CVE-2026-37531 — Apache Gears Zip Slip Path Traversal with TOCTOU Race Condition

AGL app-framework-main thru 17.1.12 contains a Zip Slip path traversal vulnerability (CWE-22) combined with a TOCTOU race condition (CWE-367) in the widget installation flow. The is_valid_filename fu…

Remote | Path Traversal
May 01, 2026 May 01, 2026
May 01, 2026
May 01, 2026
7.5 HIGH
CVE-2026-37530 — AGL agl-service-can-low-level Stack Buffer Overflow Vulnerability

AGL agl-service-can-low-level thru 17.1.12 contains a stack buffer overflow in the uds-c library. The send_diagnostic_request function in uds.c allocates a 6-byte stack buffer (MAX_DIAGNOSTIC_PAYLOAD…

Remote | Memory Corruption
May 01, 2026 May 01, 2026
May 01, 2026
May 01, 2026
7.8 HIGH
CVE-2026-37526 — AGL app-framework-binder afb-daemon Privilege Escalation Vulnerability

AGL app-framework-binder (afb-daemon) through v19.90.0 allows any local process to execute privileged supervision commands (Exit, Do, Sclose, Config, Trace, Debug, Token, slist) without authenticatio…

| Authorization
May 01, 2026 May 01, 2026
May 01, 2026
May 01, 2026
7.8 HIGH
CVE-2026-37525 — AGL app-framework-binder (afb-daemon) Privilege Escalation Vulnerability

AGL app-framework-binder (afb-daemon) through v19.90.0 contains a privilege escalation vulnerability in the supervision Do command. The on_supervision_call function in src/afb-supervision.c explicitl…

| Authorization
May 01, 2026 May 01, 2026
May 01, 2026
May 01, 2026
4.3 MEDIUM
CVE-2026-7586 — Open5GS AMF nudm-handler.c ogs_id_get_value denial of service

A weakness has been identified in Open5GS up to 2.7.7. Affected is the function ogs_id_get_value of the file /src/amf/nudm-handler.c of the component AMF. This manipulation causes denial of service. …

open5gs | Remote | Denial of Service
May 01, 2026 May 01, 2026
May 01, 2026
May 01, 2026
4.3 MEDIUM
CVE-2026-7585 — Open5GS AMF nudm-handler.c amf_nudm_sdm_handle_provisioned denial of service

A vulnerability was determined in Open5GS up to 2.7.7. The impacted element is the function amf_nudm_sdm_handle_provisioned of the file /src/amf/nudm-handler.c of the component AMF. Executing a manip…

open5gs | Remote | Denial of Service
May 01, 2026 May 01, 2026
May 01, 2026
May 01, 2026
5.5 MEDIUM
CVE-2026-42481 — Open CASCADE Technology (OCCT) Geometry Library IGES/STEP File Parsing vulnerabilities

Open CASCADE Technology (OCCT) V8_0_0_rc5 contains multiple vulnerabilities in its IGES and STEP file parsers that can be triggered by crafted IGES or STEP files. These issues include an out-of-bound…

| Memory Corruption
May 01, 2026 May 01, 2026
May 01, 2026
May 01, 2026
5.5 MEDIUM
CVE-2026-42480 — Open CASCADE Technology (OCCT) VRML Parser Stack-Based Out-of-Bounds Read Denial of Servi…

A stack-based out-of-bounds read vulnerability in VrmlData_Scene::ReadLine in the VRML parser in Open CASCADE Technology (OCCT) V8_0_0_rc5 allows attackers to cause a denial of service via a crafted …

| Memory Corruption
May 01, 2026 May 01, 2026
May 01, 2026
May 01, 2026
6.5 MEDIUM
CVE-2026-42475 — MixPHP Framework SQL Injection

SQL injection vulnerability in MixPHP Framework 2.x thru 2.2.17 via crafted `on` array to the joinOn function in BuildHelper.php.

Remote | Injection
May 01, 2026 May 01, 2026
May 01, 2026
May 01, 2026
6.5 MEDIUM
CVE-2026-42474 — MixPHP Framework SQL Injection Vulnerability

SQL injection vulnerability in MixPHP Framework 2.x thru 2.2.17 via crafted `data` array to the data function in BuildHelper.php.

Remote | Injection
May 01, 2026 May 01, 2026
May 01, 2026
May 01, 2026
9.8 CRITICAL
CVE-2026-42473 — MixPHP unserialize() Remote Code Execution Vulnerability

Unsafe deserialization vulnerability in MixPHP Framework 2.x thru 2.2.17. The session and cache handlers use unserialize() on data from the filesystem in the FileHandler object.

Remote | Misconfiguration
May 01, 2026 May 01, 2026
May 01, 2026
May 01, 2026
9.8 CRITICAL
CVE-2026-42472 — MixPHP Framework Unserialize Remote Code Execution

Unsafe deserialization vulnerability in MixPHP Framework 2.x thru 2.2.17. The session and cache handlers use unserialize() on data from Redis in the RedisHandler object.

Remote | Injection
May 01, 2026 May 01, 2026
May 01, 2026
May 01, 2026
8.1 HIGH
CVE-2026-42471 — MixPHP Framework Deserialization Remote Code Execution

Unsafe deserialization vulnerability in MixPHP Framework 2.x thru 2.2.17. The sync-invoke client (Connection.php:76) calls unserialize() on data received from the server response, enabling client-sid…

Remote | Injection
May 01, 2026 May 01, 2026
May 01, 2026
May 01, 2026
7.5 HIGH
CVE-2026-37554 — "Vanetza V2X Denial of Service Vulnerability"

An issue was discovered in Vanetza V2X v26.02 allowing remote unauthorized attackers to cause a denial of service. The vulnerability exists in the GeoNetworking packet processing pipeline where OpenS…

Remote | Denial of Service
May 01, 2026 May 01, 2026
May 01, 2026
May 01, 2026
8.4 HIGH
CVE-2026-37552 — MixPHP Framework Deserialization Remote Code Execution (RCE)

Unsafe deserialization vulnerability in MixPHP Framework 2.x thru 2.2.17. The sync-invoke TCP server (Server.php:87) receives data from a TCP socket, passes it directly to Opis\Closure\unserialize(),…

| Injection
May 01, 2026 May 01, 2026
May 01, 2026
May 01, 2026
4.9 MEDIUM
CVE-2026-37505 — V2Board SQL Injection

SQL Injection via ORDER BY clause in V2Board thru 1.7.4. In app/Http/Controllers/Admin/UserController.php, the sort parameter from user input is passed directly to User::orderBy($sort, $sortType) wit…

Remote | Injection
May 01, 2026 May 01, 2026
May 01, 2026
May 01, 2026
5.3 MEDIUM
CVE-2026-37504 — V2Board Server Token Exposure

Sensitive server_token exposed via GET parameter in V2Board thru 1.7.4. In app/Http/Controllers/Server/UniProxyController.php, the server authentication token is accepted via GET parameter transmissi…

Remote | Information Disclosure
May 01, 2026 May 01, 2026
May 01, 2026
May 01, 2026
6.9 MEDIUM
CVE-2026-37503 — V2Board XSS

Cross-Site Scripting (XSS) in V2Board thru 1.7.4. The custom_html field in theme configuration is rendered using Blade unescaped output in public/theme/v2board/dashboard.blade.php. An admin can injec…

Remote | Cross-Site Scripting
May 01, 2026 May 01, 2026
May 01, 2026
May 01, 2026
4.3 MEDIUM
CVE-2026-23866 — WhatsApp iOS/Android Media Content URL Injection Vulnerability

Incomplete validation of AI rich response messages for Instagram Reels in WhatsApp for iOS v2.25.8.0 to v2.26.15.72 and WhatsApp for Android v2.25.8.0 to v2.26.7.10 could have allowed a user to trigg…

whatsapp | Remote | Misconfiguration
May 01, 2026 May 01, 2026
May 01, 2026
May 01, 2026
Showing 20 of 5845 Results