Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.1 HIGH
CVE-2026-32991 — Apache Team Privilege Escalation Vulnerability

Improper authorization checks of team members privileges allow a team member to escalate privileges to the team owner account.

Remote | Authorization
May 13, 2026 May 14, 2026
May 13, 2026
May 14, 2026
8.1 HIGH
CVE-2026-29206 — Apache sqloptimizer SQL Injection Vulnerability

Insufficient sanitization of SQL queries in the `sqloptimizer` utility script allows SQL Injections on behalf of the root user if Slow Query logging is enabled.

Remote | Injection
May 13, 2026 May 14, 2026
May 13, 2026
May 14, 2026
9.1 CRITICAL
CVE-2026-45158 — OPNsense: Command Injection via Attacker-Controlled DHCP Config

OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.8, unsanitized user input is passed to the DHCP configuration of the configured interface, which is processed by a shell scrip…

opnsense | Remote | Injection
May 13, 2026 May 15, 2026
May 13, 2026
May 15, 2026
7.5 HIGH
CVE-2026-44478 — hoppscotch: Unauthenticated Onboarding Config Disclosure via Empty Recovery Token

hoppscotch is an open source API development ecosystem. The fix for CVE-2026-28215 in version 2026.2.0 addresses the unauthenticated POST /v1/onboarding/config endpoint by checking onboardingComplete…

hoppscotch | Remote | Information Disclosure
May 13, 2026 May 15, 2026
May 13, 2026
May 15, 2026
7.8 HIGH
CVE-2026-44471 — gitoxide: Symlink prefix-reuse allows worktree escape during checkout

gitoxide is an implementation of git written in Rust. Prior to 0.21.1, a malicious tree can be constructed that will, when checked out with gitoxide, permit writing an attacker-controlled symlink int…

gix-date gix-fs | Path Traversal
May 13, 2026 May 28, 2026
May 13, 2026
May 28, 2026
6.5 MEDIUM
CVE-2026-44448 — ERPNext: Unauthorised Document modification due to missing validation

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.102.0 and 16.11.0, certain endpoints failed to enforce proper authorization checks, allowing users to modify data beyo…

erpnext | Remote | Authorization
May 13, 2026 May 15, 2026
May 13, 2026
May 15, 2026
8.8 HIGH
CVE-2026-44447 — ERPNext: Possibility of SQL Injection due to missing validation

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 16.9.0, some endpoints were vulnerable to SQL injection through specially crafted requests, which would allow a malicious…

erpnext | Remote | Injection
May 13, 2026 May 14, 2026
May 13, 2026
May 14, 2026
8.8 HIGH
CVE-2026-44446 — ERPNext: Possibility of SQL Injection due to missing validation

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.104.3 and 16.14.0, some endpoints were vulnerable to SQL injection through specially crafted requests, which would all…

erpnext | Remote | Injection
May 13, 2026 May 14, 2026
May 13, 2026
May 14, 2026
6.5 MEDIUM
CVE-2026-44445 — ERPNext: XML External Entity (XEE) Reference Vulnerability in the EDI Module

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.104.3 and 16.12.0, an improper restriction of XML external entity (XXE) reference vulnerability in the EDI Module enab…

erpnext | Remote | XML External Entity
May 13, 2026 May 14, 2026
May 13, 2026
May 14, 2026
9.9 CRITICAL
CVE-2026-44442 — ERPNext: Unauthorised Document modification due to missing validation

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 16.9.1, certain endpoints failed to enforce proper authorization checks, allowing users to modify data beyond their permi…

erpnext | Remote | Authorization
May 13, 2026 May 14, 2026
May 13, 2026
May 14, 2026
5.0 MEDIUM
CVE-2026-44441 — ERPNext: Possible SSRF by any authenticated user

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.106.0 and 16.16.0, a malicious user could send a crafted request to an endpoint, which would lead to the server making…

erpnext | Remote | Server-Side Request Forgery
May 13, 2026 May 14, 2026
May 13, 2026
May 14, 2026
6.5 MEDIUM
CVE-2026-44440 — ERPNext: Path Traversal Leading to Sensitive File Exposure

ERPNext is a free and open source Enterprise Resource Planning tool. Prior to 15.101.1 and 16.10.0, an Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability on …

erpnext | Remote | Path Traversal
May 13, 2026 May 14, 2026
May 13, 2026
May 14, 2026
7.5 HIGH
CVE-2026-44439 — LookyLoo - PlaywrightCapture permits access to local files and internal network resources…

PlaywrightCapture is a simple replacement for splash using playwright. Prior to 1.39.6, PlaywrightCapture did not sufficiently restrict navigations and resource requests initiated by rendered pages. …

playwright_capture | Remote | Server-Side Request Forgery
May 13, 2026 May 28, 2026
May 13, 2026
May 28, 2026
6.9 MEDIUM
CVE-2026-44437 — Angular SSR: Open Redirect and Request Steering via Encoded X-Forwarded-Prefix

The Angular SSR is a server-rise rendering tool for Angular applications. From 19.0.0-next.0 to before 19.2.25, 20.3.25, 21.2.9, and 22.0.0-next.7, a vulnerability exists in the X-Forwarded-Prefix he…

angular_cli | Remote | Path Traversal
May 13, 2026 May 28, 2026
May 13, 2026
May 28, 2026
6.5 MEDIUM
CVE-2026-44426 — ShellHub: Cross-tenant IDOR in `GET /api/namespaces/:tenant` via API Key bypasses member…

ShellHub is a centralized SSH gateway. Prior to 0.24.2, GET /api/namespaces/:tenant returns the full namespace object — including the members list (user IDs, e-mails, roles), settings, and device cou…

shellhub | Remote | Information Disclosure
May 13, 2026 May 14, 2026
May 13, 2026
May 14, 2026
5.4 MEDIUM
CVE-2026-44425 — ShellHub: Crash-DoS via field injection in filter and sort-by parameters

ShellHub is a centralized SSH gateway. Prior to 0.24.2, the device list endpoint accepts user-controlled identifiers in the the name field of each filter property in the base64-encoded filter query p…

shellhub | Remote | Injection
May 13, 2026 May 18, 2026
May 13, 2026
May 18, 2026
6.5 MEDIUM
CVE-2026-44424 — ShellHub: Cross-tenant IDOR in `GET /api/devices/:uid` discloses device data of any names…

ShellHub is a centralized SSH gateway. Prior to 0.24.2, GET /api/devices/:uid returns the full device object whenever the caller is authenticated, without verifying that the device belongs to the cal…

shellhub | Remote | Authorization
May 13, 2026 May 18, 2026
May 13, 2026
May 18, 2026
6.5 MEDIUM
CVE-2026-44423 — ShellHub: Cross-tenant IDOR in `GET /api/sessions/:uid` discloses SSH session data

ShellHub is a centralized SSH gateway. Prior to 0.24.2, GET /api/sessions/:uid returns the full session object for any authenticated caller, without scoping by the caller's tenant. An authenticated u…

shellhub | Remote | Information Disclosure
May 13, 2026 May 15, 2026
May 13, 2026
May 15, 2026
8.5 HIGH
CVE-2026-44369 — CVAT: Stored XSS via annotation guides

CVAT is an open source interactive video and image annotation tool for computer vision. From 2.5.0 to 2.63.0, an attacker who is able to create or edit an annotation guide on a task is able to add ma…

computer_vision_annotation_tool | Remote | Cross-Site Scripting
May 13, 2026 May 14, 2026
May 13, 2026
May 14, 2026
6.5 MEDIUM
CVE-2026-44195 — OPNsense: Authentication lockout bypass

OPNsense is a FreeBSD based firewall and routing platform. Prior to 26.1.7, a logic flaw in the OPNsense lockout_handler allows an unauthenticated attacker to continuously reset the authentication fa…

opnsense | Remote | Authentication
May 13, 2026 May 15, 2026
May 13, 2026
May 15, 2026
Showing 20 of 7159 Results