Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.0 MEDIUM
CVE-2026-43979 — Local Deep Research: HTML Injection via Unescaped User Input in PDF Export (`pdf_service.…

Local Deep Research is an AI-powered research assistant for deep, iterative research. Prior to 1.6.0, PDFService._markdown_to_html() constructs an HTML document by interpolating user-controlled value…

local_deep_research | Remote | Cross-Site Scripting
May 28, 2026 Jun 01, 2026
May 28, 2026
Jun 01, 2026
8.8 HIGH
CVE-2026-43000 — OpenStack Keystone Trust Delegation Privilege Escalation Vulnerability

An issue was discovered in OpenStack Keystone before 29.0.2. When combined with an application credential impersonation vulnerability, an attacker with the member role on a project can escalate to ad…

keystone | Remote | Authorization
May 28, 2026 Jun 02, 2026
May 28, 2026
Jun 02, 2026
8.8 HIGH
CVE-2026-42999 — OpenStack Keystone JSON Injection Vulnerability

An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone RBAC policy enforcer in enforce_call unconditionally merges the raw JSON request body into the policy enforcement dictionary …

keystone | Remote | Authorization
May 28, 2026 Jun 02, 2026
May 28, 2026
Jun 02, 2026
8.8 HIGH
CVE-2026-42998 — OpenStack Keystone Credential Authentication Impersonation

An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone application credential authentication plugin does not verify that the user supplied in the authentication request matches the…

keystone | Remote | Authentication
May 28, 2026 Jun 02, 2026
May 28, 2026
Jun 02, 2026
7.3 HIGH
CVE-2026-30761 — SourceBans Material Admin File Upload RCE

An arbitrary file upload vulnerability in the pages/admin.uploadmapimg.php component of SourceBans Material Admin v1.1.6 allows attackers to execute arbitrary code via uploading a crafted image file.

Remote | Misconfiguration
May 28, 2026 May 29, 2026
May 28, 2026
May 29, 2026
7.3 HIGH
CVE-2026-30760 — SourceBans Material Admin Unauthenticated Arbitrary Data Manipulation Vulnerability

An issue in SourceBans Material Admin before v.1.1.6 (3ecd95e) allows attackers to manipulate arbitrary user data in the web app via a crafted XAJAX call.

Remote | Injection
May 28, 2026 May 29, 2026
May 28, 2026
May 29, 2026
5.0 MEDIUM
CVE-2026-46561 — pyLoad: SSRF via HTTP Redirect Bypass in parse_urls API

pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, the PREREQFUNCTION-based private IP check was not applied to HTTPRequest (used by the parse_urls API). An…

pyload | Remote | Server-Side Request Forgery
May 28, 2026 May 29, 2026
May 28, 2026
May 29, 2026
9.1 CRITICAL
CVE-2026-45787 — electerm's encrypt method not safe enough

electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.9.5, deterministic AES-192-CBC with a fixed zero IV, constant KDF salt, and no MAC leads to confid…

electerm | Remote | Cryptography
May 28, 2026 Jun 03, 2026
May 28, 2026
Jun 03, 2026
9.6 CRITICAL
CVE-2026-45374 — CodeWhale: task_create Insecure Defaults Enable RCE via Prompt Injection in Project Files

CodeWhale is a DeepSeek + MiMo coding agent in terminal. Prior to 0.8.26, the task_create tool spawns durable sub-agents that inherit two insecure defaults, allow_shell defaults to true (config.rs:14…

Remote | Misconfiguration
May 28, 2026 May 30, 2026
May 28, 2026
May 30, 2026
7.4 HIGH
CVE-2026-45373 — CodeWhale: SSRF‌ IPV6 bypass

CodeWhale is a DeepSeek + MiMo coding agent in terminal. Prior to 0.8.26, although SSRF is validated against hostnames that resolve to private IPv6 addresses, when providing the IPV6 in‌‌ URL‌ as htt…

Remote | Server-Side Request Forgery
May 28, 2026 May 30, 2026
May 28, 2026
May 30, 2026
9.3 CRITICAL
CVE-2026-45353 — electerm: Local code through electerm's single-instance socket

electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. From 3.0.6 to 3.8.8, This vulnerability is fixed in 3.9.0.

May 28, 2026 Jun 03, 2026
May 28, 2026
Jun 03, 2026
8.7 HIGH
CVE-2026-45348 — pyLoad: Stored XSS in Downloads view via unsanitized link URL in packages.js template lit…

pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, the packages.js template at src/pyload/webui/app/themes/modern/templates/js/packages.js:172 interpolates …

pyload | Remote | Cross-Site Scripting
May 28, 2026 May 29, 2026
May 28, 2026
May 29, 2026
9.6 CRITICAL
CVE-2026-45323 — MeshCore Card: XSS vulnerability through meshcore node name

MeshCore Card provides MeshCore Lovelace card for Home Assistant. Prior to 0.3.3, Meshcore node names are rendered without HTML escaping in meshcore-card, allowing any node within direct or indirect …

meshcore_card | Remote | Cross-Site Scripting
May 28, 2026 Jun 03, 2026
May 28, 2026
Jun 03, 2026
9.6 CRITICAL
CVE-2026-45311 — CodeWhale: run_tests Tool Enables RCE via Malicious Repository Without Approval

CodeWhale is a DeepSeek + MiMo coding agent in terminal. From 0.3.0 to 0.8.23, the run_tests tool executes cargo test in the workspace with ApprovalRequirement::Auto, meaning it runs without any user…

Remote | Misconfiguration
May 28, 2026 Jun 01, 2026
May 28, 2026
Jun 01, 2026
7.4 HIGH
CVE-2026-45310 — CodeWhale: SSRF via HTTP Redirect Bypass in fetch_url Tool

CodeWhale is a DeepSeek + MiMo coding agent in terminal. Prior to 0.8.22, the fetch_url tool validates the initial URL's resolved IP address against a restricted-IP blocklist (is_restricted_ip()) to …

Remote | Server-Side Request Forgery
May 28, 2026 May 30, 2026
May 28, 2026
May 30, 2026
6.1 MEDIUM
CVE-2026-45307 — Speakr: Open redirect in is_safe_url via parser mismatch on next parameter

Speakr is a personal, self-hosted web application designed for transcribing audio recordings. Prior to 0.8.20-alpha, the is_safe_url() helper used to validate post-login redirect targets applied urlj…

Remote | Server-Side Request Forgery
May 28, 2026 Jun 01, 2026
May 28, 2026
Jun 01, 2026
6.5 MEDIUM
CVE-2026-45306 — pyLoad: Incomplete Fix for CVE-2026-33509 -storage_folder Bypass via Session Directory

pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, the fix for CVE-2026-33509 prevents setting storage_folder inside PKGDIR or userdir, but does NOT protect…

pyload | Remote | Path Traversal
May 28, 2026 May 29, 2026
May 28, 2026
May 29, 2026
5.3 MEDIUM
CVE-2026-45297 — Cross-tenant IDOR on feature-flag and assist-stats routes via {project_id} case mismatch

OpenReplay is a self-hosted session replay suite. Prior to 1.26.0, there is a cross-tenant IDOR on feature-flag and assist-stats routes via {project_id} case mismatch. ProjectAuthorizer.__call__ (OSS…

openreplay | Remote | Authorization
May 28, 2026 May 28, 2026
May 28, 2026
May 28, 2026
7.7 HIGH
CVE-2026-45296 — OpenReplay: Cross-tenant information disclosure in app_apikey projectKey routes via missi…

OpenReplay is a self-hosted session replay suite. Prior to 1.26.0, OpenReplay's Python API exposes several app_apikey routes that trust a caller-provided projectKey after validating only that the API…

openreplay | Remote | Authorization
May 28, 2026 May 28, 2026
May 28, 2026
May 28, 2026
9.4 CRITICAL
CVE-2026-45058 — electerm: Import unsafe bookmark data could lead to unsafe operation when click local typ…

electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. In 3.8.8 and earlier, there is persistent local-pty code execution via imported bookmarks or compromised sync…

electerm | Remote | Injection
May 28, 2026 Jun 01, 2026
May 28, 2026
Jun 01, 2026
Showing 20 of 7215 Results