Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.3 HIGH
CVE-2026-9334 — Cpanel::JSON::XS versions before 4.41 for Perl allow type confusion via duplicate object …

Cpanel::JSON::XS versions before 4.41 for Perl allow type confusion via duplicate object keys when dupkeys_as_arrayref is enabled. decode_hv() collapses duplicate object keys into an array reference…

Remote | Memory Corruption
Jun 03, 2026 Jun 03, 2026
Jun 03, 2026
Jun 03, 2026
7.5 HIGH
CVE-2026-10694 — SourceCodester Online Food Ordering System index.php include file inclusion

A vulnerability was detected in SourceCodester Online Food Ordering System 2.0. Affected by this issue is the function include of the file /index.php. The manipulation of the argument page results in…

online_food_ordering_system | Remote | Path Traversal
Jun 03, 2026 Jun 03, 2026
Jun 03, 2026
Jun 03, 2026
6.5 MEDIUM
CVE-2026-10693 — SourceCodester Online Boat Reservation System Administrative Endpoint improper authorizat…

A security vulnerability has been detected in SourceCodester Online Boat Reservation System 1.0. Affected by this vulnerability is an unknown functionality of the component Administrative Endpoint. T…

online_boat_reservation_system | Remote | Authorization
Jun 03, 2026 Jun 03, 2026
Jun 03, 2026
Jun 03, 2026
4.3 MEDIUM
CVE-2026-9732 — EmergencyWP <= 1.4.2 - Cross-Site Request Forgery to Plugin Settings Update

The EmergencyWP – Dead Man's switch & legacy deliverance plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.4.2. This is due to missing or incorr…

Remote | Cross-Site Request Forgery
Jun 03, 2026 Jun 03, 2026
Jun 03, 2026
Jun 03, 2026
4.4 MEDIUM
CVE-2026-7421 — Passeum Ticketing <= 1.0 - Authenticated (Administrator+) Stored Cross-Site Scripting via…

The Passeum Ticketing plugin for WordPress is vulnerable to Stored Cross-Site Scripting in all versions up to, and including, 1.0. This is due to the `get_shop_url()` method returning the `shop_name`…

Remote | Cross-Site Scripting
Jun 03, 2026 Jun 03, 2026
Jun 03, 2026
Jun 03, 2026
4.3 MEDIUM
CVE-2026-10692 — johnhuang316 code-index-mcp search_code_advanced is_safe_regex_pattern redos

A weakness has been identified in johnhuang316 code-index-mcp up to 2.14.0. Affected is the function is_safe_regex_pattern of the component search_code_advanced. Executing a manipulation of the argum…

code-index-mcp | Remote | Denial of Service
Jun 03, 2026 Jun 03, 2026
Jun 03, 2026
Jun 03, 2026
4.3 MEDIUM
CVE-2026-10691 — wonderwhy-er DesktopCommanderMCP start_search search-manager.ts redos

A security flaw has been discovered in wonderwhy-er DesktopCommanderMCP up to 0.2.38. This impacts an unknown function of the file src/search-manager.ts of the component start_search. Performing a ma…

desktopcommandermcp | Remote | Denial of Service
Jun 03, 2026 Jun 03, 2026
Jun 03, 2026
Jun 03, 2026
6.5 MEDIUM
CVE-2026-10690 — wonderwhy-er DesktopCommanderMCP read_file filesystem.ts readFileFromUrl server-side requ…

A vulnerability was identified in wonderwhy-er DesktopCommanderMCP 0.2.37. This affects the function readFileFromUrl of the file src/tools/filesystem.ts of the component read_file. Such manipulation …

desktopcommandermcp | Remote | Server-Side Request Forgery
Jun 03, 2026 Jun 03, 2026
Jun 03, 2026
Jun 03, 2026
0.0 NA
CVE-2026-46447 — OpenStack Ironic Boot Script Injection

OpenStack Ironic through 35.0.x allows Boot Script Injection.

| Injection
Jun 03, 2026 Jun 03, 2026
Jun 03, 2026
Jun 03, 2026
5.7 MEDIUM
CVE-2026-44654 — LibreChat: Shared-agent editor can globally delete owner's file records — breaks owner's …

LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. In versions up to and including 0.8.3, a shared-agent editor can delete file records through `DELETE /api/files` that the o…

librechat | Remote | Authorization
Jun 02, 2026 Jun 03, 2026
Jun 02, 2026
Jun 03, 2026
6.5 MEDIUM
CVE-2026-44653 — LibreChat Shared MCP Server View Leaks Decrypted Admin Secrets

LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. In versions up to and including 0.8.3, users with only `VIEW` access to an MCP server can retrieve the server's decrypted a…

librechat | Remote | Information Disclosure
Jun 02, 2026 Jun 03, 2026
Jun 02, 2026
Jun 03, 2026
5.3 MEDIUM
CVE-2026-42507 — Arbitrary inputs are included in errors without any escaping in net/textproto

When returning errors, functions in the net/textproto package would include its input as part of the error. This might allow an attacker to inject misleading content to errors that are printed or log…

go | Remote | Information Disclosure
Jun 02, 2026 Jun 03, 2026
Jun 02, 2026
Jun 03, 2026
7.5 HIGH
CVE-2026-42504 — Quadratic complexity in WordDecoder.DecodeHeader in mime

Decoding a maliciously-crafted MIME header containing many invalid encoded-words can consume excessive CPU.

go | Remote | Denial of Service
Jun 02, 2026 Jun 03, 2026
Jun 02, 2026
Jun 03, 2026
4.9 MEDIUM
CVE-2026-41412 — alf.io vulnerable to Arbitrary File Read and Exfil via simpleHttpClient Extension Script

alf.io is an open source ticket reservation system for conferences, trade shows, workshops, and meetups. Prior to version 2.0-M5-2606, the alf.io extension sandbox injects a fully-functional HTTP cli…

alf | Remote | Path Traversal
Jun 02, 2026 Jun 03, 2026
Jun 02, 2026
Jun 03, 2026
7.1 HIGH
CVE-2026-40108 — GLPI Vulnerable to Stored XSS in ITIL Costs

GLPI is a free asset and IT management software package. In versions 11.0.0 through 11.0.6, a technician can store an XSS payload in a ITIL costs. This issue has been fixed in version 11.0.7.

glpi | Remote | Cross-Site Scripting
Jun 02, 2026 Jun 02, 2026
Jun 02, 2026
Jun 02, 2026
8.0 HIGH
CVE-2026-35482 — alf.io has an Authenticated RCE via Extension Script Sandbox Escape

alf.io is an open source ticket reservation system for conferences, trade shows, workshops, and meetups. Prior to version 2.0-M5-2606, a sandbox escape vulnerability in the alf.io extension script en…

alf | Remote | Injection
Jun 02, 2026 Jun 03, 2026
Jun 02, 2026
Jun 03, 2026
9.6 CRITICAL
CVE-2026-32625 — LibreChat Exfiltrates Server Secrets via MCP Server URL Injection

LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. In versions up to and including 0.8.3, the Model Context Protocol (MCP) server integration resolves ${VAR} placeholders aga…

librechat | Remote | Misconfiguration
Jun 02, 2026 Jun 03, 2026
Jun 02, 2026
Jun 03, 2026
7.1 HIGH
CVE-2026-31942 — LibreChat has IDOR in API Keys Management that allows any authenticated user to overwrite…

LibreChat is an enhanced ChatGPT clone that supports multiple AI providers. In versions up to and including 0.7.6, an Insecure Direct Object Reference (IDOR) vulnerability exists in the API keys mana…

librechat | Remote | Authorization
Jun 02, 2026 Jun 02, 2026
Jun 02, 2026
Jun 02, 2026
0.0 NA
CVE-2026-27145 — Inefficient candidate hostname parsing in crypto/x509

(*x509.Certificate).VerifyHostname previously called matchHostnames in a loop over all DNS Subject Alternative Name (SAN) entries. This caused strings.Split(host, ".") to execute repeatedly on the sa…

go | Misconfiguration
Jun 02, 2026 Jun 02, 2026
Jun 02, 2026
Jun 02, 2026
8.2 HIGH
CVE-2026-25861 — QloApps 1.7.0 Weak Password Hashing via MD5 in Tools.php

QloApps through 1.7.0, fixed in commit 64e9722, contains a weak cryptographic algorithm vulnerability that allows attackers to compromise user credentials by exploiting the use of MD5 for password ha…

Remote | Cryptography
Jun 02, 2026 Jun 02, 2026
Jun 02, 2026
Jun 02, 2026
Showing 20 of 7137 Results