Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.9 MEDIUM
CVE-2026-47741 — Shopper: Race condition on Discount.usage_limit allows silent over-redemption

Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, CreateOrderFromCartAction::execute previously created the Order row before checking and incrementing the discount's total_use counter. Un…

Remote | Race Condition
May 29, 2026 May 29, 2026
May 29, 2026
May 29, 2026
8.1 HIGH
CVE-2026-47740 — Shopper: Authorization bypass in multiple Livewire admin components

Shopper is a Headless e-commerce Admin Panel. Prior to 2.8.0, Multiple Filament actions on the admin Order detail and Order shipments table were callable by an authenticated low-privilege user withou…

Remote | Authorization
May 29, 2026 May 29, 2026
May 29, 2026
May 29, 2026
8.5 HIGH
CVE-2026-46372 — SillyTavern: SSRF in SearXNG Search Proxy via Unvalidated baseUrl

SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to 1.18.0,…

sillytavern | Remote | Server-Side Request Forgery
May 29, 2026 May 29, 2026
May 29, 2026
May 29, 2026
5.3 MEDIUM
CVE-2026-46344 — liboqs: Heap-buffer-overflow in XMSS verification path via OID-controlled parameter misma…

liboqs is a C-language cryptographic library that provides implementations of post-quantum cryptography algorithms. Prior to 0.16.0, an out-of-bounds read has been identified in the XMSS and XMSS^MT …

liboqs | Remote | Memory Corruption
May 29, 2026 May 29, 2026
May 29, 2026
May 29, 2026
6.9 MEDIUM
CVE-2026-44652 — SillyTavern: SSRF vulnerability in the CORS proxy middleware

SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to 1.18.0,…

sillytavern | Remote | Server-Side Request Forgery
May 29, 2026 May 29, 2026
May 29, 2026
May 29, 2026
6.9 MEDIUM
CVE-2026-44651 — SillyTavern: Reflected XSS vulnerability in the CORS proxy middleware

SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to 1.18.0,…

sillytavern | Remote | Server-Side Request Forgery
May 29, 2026 May 29, 2026
May 29, 2026
May 29, 2026
9.1 CRITICAL
CVE-2026-44650 — SillyTavern: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal…

SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to 1.18.0,…

sillytavern | Remote | Misconfiguration
May 29, 2026 May 29, 2026
May 29, 2026
May 29, 2026
9.8 CRITICAL
CVE-2026-44649 — SillyTavern: Authentication Bypass via SSO Header Injection

SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to 1.18.0,…

sillytavern | Remote | Authentication
May 29, 2026 May 29, 2026
May 29, 2026
May 29, 2026
7.5 HIGH
CVE-2026-44648 — SillyTavern: Existing sessions are not invalidated after password change, allowing sessio…

SillyTavern is a locally installed user interface that allows users to interact with text generation large language models, image generation engines, and text-to-speech voice models. Prior to 1.18.0,…

sillytavern | Remote | Authentication
May 29, 2026 May 29, 2026
May 29, 2026
May 29, 2026
5.9 MEDIUM
CVE-2026-44611 — MacGregor Voyage Data Recorder (VDR) G4e Use of Password Hash With Insufficient Computati…

Danelec MacGregor Voyage Data Recorder passwords are stored with a hashing method which limits password length and is susceptible to brute force attacks.

| Authentication
May 29, 2026 May 29, 2026
May 29, 2026
May 29, 2026
5.3 MEDIUM
CVE-2026-44518 — liboqs: XMSS Buffer Overread Bug

liboqs is a C-language cryptographic library that provides implementations of post-quantum cryptography algorithms. Prior to 0.16.0, an out-of-bounds read has been identified in the XMSS and XMSS^MT …

liboqs | Remote | Memory Corruption
May 29, 2026 May 29, 2026
May 29, 2026
May 29, 2026
5.9 MEDIUM
CVE-2026-42951 — MacGregor Voyage Data Recorder (VDR) G4e Insufficiently Protected Credentials

An authenticated user can download a backup of the Danelec MacGregor Voyage Data Recorder device which includes account data and password hashes.

| Information Disclosure
May 29, 2026 May 29, 2026
May 29, 2026
May 29, 2026
8.7 HIGH
CVE-2026-42941 — MacGregor Voyage Data Recorder (VDR) G4e Use of Default Credentials

The Danelec MacGregor Voyage Data Recorder device includes a default username and password, with no enforced password change.

| Authentication
May 29, 2026 May 29, 2026
May 29, 2026
May 29, 2026
8.7 HIGH
CVE-2026-42929 — MacGregor Voyage Data Recorder (VDR) G4e Use of Hard-coded Credentials

Danelec MacGregor Voyage Data Recorder includes default accounts with hard-coded credentials.

| Authentication
May 29, 2026 May 29, 2026
May 29, 2026
May 29, 2026
6.9 MEDIUM
CVE-2026-40425 — MacGregor Voyage Data Recorder (VDR) G4e Files or Directories Accessible to External Part…

The administrator account for the Danelec MacGregor Voyage Data Recorder web interface can directly edit sensitive files related to authentication, potentially changing the root password.

| Authorization
May 29, 2026 May 29, 2026
May 29, 2026
May 29, 2026
9.8 CRITICAL
CVE-2026-7786 — Jinan USR IOT Technology Limited (PUSR) USR-W610 RS232/485 to Wi-Fi/Ethernet Converter Us…

Jinan USR IOT Technology Limited (PUSR) USR-W610 RS232/485 to Wi-Fi/Ethernet Converter device firmware contains plaintext administrative credentials embedded in the firmware image. These credentials …

Remote | Authentication
May 29, 2026 May 29, 2026
May 29, 2026
May 29, 2026
8.4 HIGH
CVE-2026-6824 — CP Plus 8 Ch. Network Video Recorder Cross-site Scripting

A stored cross-site scripting (XSS) vulnerability exists in certain 1xxx series NVR devices due to insufficient sanitization of user-supplied input in specific functional modules. Attackers can injec…

Remote | Cross-Site Scripting
May 29, 2026 May 29, 2026
May 29, 2026
May 29, 2026
8.8 HIGH
CVE-2026-5768 — Fourth Frontier Frontier X Mobile Application, Frontier X2 Missing Authentication for Cri…

The Frontier X2 device allows unauthenticated BLE read/write access to critical GATT characteristics without enforcing pairing authentication or authorization. This allows attackers within BLE range …

| Authentication
May 29, 2026 May 29, 2026
May 29, 2026
May 29, 2026
9.1 CRITICAL
CVE-2026-5386 — KMW CCTV Security Cameras Unverified Password Change

The affected KMW CCTV Security Cameras are vulnerable to a critical unauthenticated password reset. This flaw allows an attacker to remotely reset the administrator password to a known value without …

Remote | Authentication
May 29, 2026 May 29, 2026
May 29, 2026
May 29, 2026
7.7 HIGH
CVE-2026-47179 — Arcane: Authenticated Arbitrary Host File Read via Docker Compose Include Directives in A…

Arcane is an interface for managing Docker containers, images, networks, and volumes. Prior to 1.19.4, ProjectService.GetProjectFileContent returns the contents of any Docker Compose include directiv…

arcane | Remote | Path Traversal
May 29, 2026 May 29, 2026
May 29, 2026
May 29, 2026
Showing 20 of 6956 Results