Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-31069 — BillaBear SQL Injection Vulnerability

BillaBear (all versions prior to Jan 2026) contains a SQL Injection vulnerability in the EventRepository. User-controlled input from metric filter names and aggregation properties is directly interpo…

| Injection
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
0.0 NA
CVE-2026-30117 — Scalar Astro Arbitrary File Upload Vulnerability

scalar/astro v0.1.13 was discovered to contain an arbitrary file upload vulnerability in the the scalar_url query parameter of the Scalar Proxy endpoint. This vulnerability allows attackers to execut…

| Injection
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
0.0 NA
CVE-2026-30118 — Scalar Astro SSRF

scalar/astro v0.1.13 was discovered to contain a Server-Side Request Forgery (SSRF) in the scalar_url query parameter of the Scalar Proxy endpoint. This vulnerability allows unauthenticated attackers…

| Server-Side Request Forgery
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
0.0 NA
CVE-2026-31072 — Apache APScheduler Python RCE via Insecure Deserialization

The JSONSerializer and CBORSerializer in APScheduler (all versions including 3.10.x and 4.0.0a5) are vulnerable to Remote Code Execution (RCE) via Insecure Deserialization. The unmarshal_object funct…

| Injection
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
0.0 NA
CVE-2026-31071 — LalanaChami Pharmacy Management System Unauthenticated API Endpoint Vulnerability

API endpoints in LalanaChami Pharmacy Management System (commit 5c3d028) lack authentication middleware. Unauthenticated remote attackers can exploit this to dump all user records (including bcrypt p…

| Authentication
May 19, 2026 May 19, 2026
May 19, 2026
May 19, 2026
7.1 HIGH
CVE-2026-30950 — AutoGPT has Authenticated Session Hijacking via IDOR

AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Versions 0.6.36 through 0.6.50 are vulnerable to Authenticated Session Hijac…

Remote | Authentication
May 18, 2026 May 19, 2026
May 18, 2026
May 19, 2026
3.9 LOW
CVE-2026-27964 — FacturaScripts: Reflected Cross-Site Scripting (XSS) via Cookie Manipulation

FacturaScripts is an open source accounting and invoicing software. Versions 2025.7 and prior contain a Reflected Cross-Site Scripting (XSS) vulnerability through the fsNick cookie parameter. The app…

facturascripts | Cross-Site Scripting
May 18, 2026 May 19, 2026
May 18, 2026
May 19, 2026
6.5 MEDIUM
CVE-2026-27892 — FacturaScripts: Unstripped Image Metadata (EXIF) Leakage via Library Module File Upload/D…

FacturaScripts is an open source accounting and invoicing software. In versions prior to 2026, the Library module stores and serves uploaded images byte-for-byte, without stripping EXIF/XMP/IPTC meta…

facturascripts | Remote | Information Disclosure
May 18, 2026 May 19, 2026
May 18, 2026
May 19, 2026
7.2 HIGH
CVE-2026-27891 — Remote Code Execution (RCE) via Zip Slip in Plugin Upload Mechanism

FacturaScripts is an open source accounting and invoicing software. Versions 2026 and below contain a critical vulnerability in the Plugins::add() function. The system fails to properly validate the …

facturascripts | Remote | Path Traversal
May 18, 2026 May 19, 2026
May 18, 2026
May 19, 2026
6.5 MEDIUM
CVE-2026-27737 — BigBlueButton has Stored XSS in bbb-playback replay

BigBlueButton is an open-source virtual classroom. In versions prior to 3.0.19, the recording playback (presentation format) was not sanitizing user's input in public chat. This allowed for a malicio…

Remote | Cross-Site Scripting
May 18, 2026 May 19, 2026
May 18, 2026
May 19, 2026
8.6 HIGH
CVE-2026-8851 — SOGo < 5.12.8 SQL Injection via addUserInAcls endpoint

SOGo versions 5.12.7 and prior contains a SQL injection vulnerability in the Access Control List management functionality that allows authenticated users to extract arbitrary data from the database b…

Remote | Injection
May 18, 2026 May 19, 2026
May 18, 2026
May 19, 2026
9.8 CRITICAL
CVE-2026-8838 — Remote Code Execution via eval() Injection in amazon-redshift-python-driver

Unsafe use of Python's eval() on server-received data in the vector_in() function in amazon-redshift-python-driver before 2.1.14 allows a rogue server or man-in-the-middle actor to execute arbitrary …

Remote | Injection
May 18, 2026 May 19, 2026
May 18, 2026
May 19, 2026
7.0 HIGH
CVE-2026-4137 — Incomplete Fix for CVE-2025-10279: Insecure Temporary Directory Permissions in mlflow/mlf…

In mlflow/mlflow versions prior to 3.11.0, the `get_or_create_nfs_tmp_dir()` function in `mlflow/utils/file_utils.py` creates temporary directories with world-writable permissions (0o777), and the `_…

| Misconfiguration
May 18, 2026 May 19, 2026
May 18, 2026
May 19, 2026
9.9 CRITICAL
CVE-2026-27130 — Dokploy has Command Injection in its Service Operations

Dokploy is a free, self-hostable Platform as a Service (PaaS). Versions 0.26.6 and below have OS command injection through the appName parameter. 3 chained issues cause this problem: inadequate input…

Remote | Injection
May 18, 2026 May 19, 2026
May 18, 2026
May 19, 2026
8.6 HIGH
CVE-2026-26978 — Free PBX backup: Deserialization of Untrusted Data in admin/modules/backup/Models/BackupS…

FreePBX is an open source IP PBX. In versions below 16.0.71 and 17.0.6, the backup module does not properly sanitize data during restore operations, potentially leading to compromise if the backup co…

Remote | Injection
May 18, 2026 May 19, 2026
May 18, 2026
May 19, 2026
9.8 CRITICAL
CVE-2026-25244 — WebdriverIO has Command Injection in the BrowserStack Service

WebdriverIO is a test automation framework for unit, e2e and component testing using WebDriver, WebDriver BiDi and Appium. Versions below 9.24.0 contain a command injection vulnerability leading to r…

Remote | Injection
May 18, 2026 May 19, 2026
May 18, 2026
May 19, 2026
8.2 HIGH
CVE-2026-22810 — Joplin: Path traversal in OneNote importer allows overwriting arbitrary files

Joplin is an open source note-taking and to-do application that organises notes and lists into notebooks. Versions prior to 3.5.7 contain a path traversal vulnerability in the importer which allows o…

| Path Traversal
May 18, 2026 May 19, 2026
May 18, 2026
May 19, 2026
7.8 HIGH
CVE-2026-47092 — Claude HUD 0.0.12 Arbitrary Command Execution via COMSPEC Environment Variable

Claude HUD through 0.0.12, patched in commit 234d9aa, contains a command injection vulnerability that allows local attackers to execute arbitrary commands by manipulating the COMSPEC environment vari…

| Injection
May 18, 2026 May 18, 2026
May 18, 2026
May 18, 2026
4.8 MEDIUM
CVE-2026-47091 — Claude HUD 0.0.12 Path Traversal via transcript_path

Claude HUD through 0.0.12, patched in commit 234d9aa, contains a path traversal vulnerability that allows attackers to read arbitrary files by supplying an unvalidated transcript_path value via stdin…

| Path Traversal
May 18, 2026 May 18, 2026
May 18, 2026
May 18, 2026
4.6 MEDIUM
CVE-2026-47090 — Claude HUD 0.0.12 Terminal Injection via OSC 8 Hyperlinks

Claude HUD through 0.0.12, patched in commit 234d9aa, constructs OSC 8 terminal hyperlink escape sequences using raw cwd and branchUrl values without stripping control characters or encoding embedded…

| Misconfiguration
May 18, 2026 May 18, 2026
May 18, 2026
May 18, 2026
Showing 20 of 6343 Results