Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.1 HIGH
CVE-2026-39977 — flatpak-builder has a path traversal leading to arbitrary file read on host when installi…

flatpak-builder is a tool to build flatpaks from source. From 1.4.5 to before 1.4.8, the license-files manifest key takes an array of paths to user defined licence files relative to the source direct…

flatpak-builder | Remote | Path Traversal
Apr 09, 2026 Apr 16, 2026
Apr 09, 2026
Apr 16, 2026
8.1 HIGH
CVE-2026-35577 — Missing Host Header Validation in Apollo MCP Server for Localhost Deployments

Apollo MCP Server is a Model Context Protocol server that exposes GraphQL operations as MCP tools. Prior to version 1.7.0, the Apollo MCP Server did not validate the Host header on incoming HTTP requ…

apollo_mcp_server | Remote | Misconfiguration
Apr 09, 2026 Apr 17, 2026
Apr 09, 2026
Apr 17, 2026
8.8 HIGH
CVE-2026-35063 — Missing Authorization in OpenPLC_V3

OpenPLC_V3 REST API endpoint checks for JWT presence but never verifies the caller's role. Any authenticated user with role=user can delete any other user, including administrators, by specifying the…

openplc_v3_firmware openplc_v3 | Remote | Authentication
Apr 09, 2026 Apr 16, 2026
Apr 09, 2026
Apr 16, 2026
7.8 HIGH
CVE-2026-34734 — HDF5: H5T__conv_struct Use After Free

HDF5 is software for managing data. In 1.14.1-2 and earlier, a heap-use-after-free was found in the h5dump helper utility. An attacker who can supply a malicious h5 file can trigger a heap use-after-…

hdf5 | Memory Corruption
Apr 09, 2026 Apr 14, 2026
Apr 09, 2026
Apr 14, 2026
6.5 MEDIUM
CVE-2026-34500 — Apache Tomcat: OCSP checks sometimes soft-fail with FFM even when soft-fail is disabled

CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled and FFM is used in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M14 through 11.0.20…

tomcat | Remote | Authentication
Apr 09, 2026 Apr 14, 2026
Apr 09, 2026
Apr 14, 2026
7.5 HIGH
CVE-2026-34487 — Apache Tomcat: Cloud membership for clustering component exposed the Kubernetes bearer to…

Insertion of Sensitive Information into Log File vulnerability in the cloud membership for clustering component of Apache Tomcat exposed the Kubernetes bearer token. This issue affects Apache Tomcat…

tomcat | Remote | Information Disclosure
Apr 09, 2026 Apr 14, 2026
Apr 09, 2026
Apr 14, 2026
7.5 HIGH
CVE-2026-34486 — Apache Tomcat: Fix for CVE-2026-29146 allowed bypass of EncryptInterceptor

Missing Encryption of Sensitive Data vulnerability in Apache Tomcat due to the fix for CVE-2026-29146 allowing the bypass of the EncryptInterceptor. This issue affects Apache Tomcat: 11.0.20, 10.1.5…

tomcat | Remote | Cryptography
Apr 09, 2026 Apr 14, 2026
Apr 09, 2026
Apr 14, 2026
7.5 HIGH
CVE-2026-34483 — Apache Tomcat: Incomplete escaping of JSON access logs

Improper Encoding or Escaping of Output vulnerability in the JsonAccessLogValve component of Apache Tomcat. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.20, from 10.1.0-M1 through 1…

tomcat | Remote | Information Disclosure
Apr 09, 2026 Apr 14, 2026
Apr 09, 2026
Apr 14, 2026
5.3 MEDIUM
CVE-2026-32990 — Apache Tomcat: Fix for CVE-2025-66614 is incomplete

Improper Input Validation vulnerability in Apache Tomcat due to an incomplete fix of CVE-2025-66614. This issue affects Apache Tomcat: from 11.0.15 through 11.0.19, from 10.1.50 through 10.1.52, fro…

tomcat | Remote | Injection
Apr 09, 2026 Apr 14, 2026
Apr 09, 2026
Apr 14, 2026
7.8 HIGH
CVE-2026-29923 — PowerStrip Local Privilege Escalation (LPE)

The pstrip64.sys driver in EnTech Taiwan PowerStrip <=3.90.736 allows local users to escalate privileges to SYSTEM via a crafted IOCTL request enabling unprivileged users to map arbitrary physical me…

| Memory Corruption
Apr 09, 2026 Apr 14, 2026
Apr 09, 2026
Apr 14, 2026
7.5 HIGH
CVE-2026-29146 — Apache Tomcat: EncryptInterceptor vulnerable to padding oracle attack by default

Padding Oracle vulnerability in Apache Tomcat's EncryptInterceptor with default configuration. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, from 10.0.0-M1 through 10.1.52, from …

tomcat | Remote | Cryptography
Apr 09, 2026 Apr 14, 2026
Apr 09, 2026
Apr 14, 2026
9.1 CRITICAL
CVE-2026-29145 — Apache Tomcat, Apache Tomcat Native: OCSP checks sometimes soft-fail even when soft-fail …

CLIENT_CERT authentication does not fail as expected for some scenarios when soft fail is disabled vulnerability in Apache Tomcat, Apache Tomcat Native. This issue affects Apache Tomcat: from 11.0.0…

tomcat tomcat_native | Remote | Authentication
Apr 09, 2026 Apr 14, 2026
Apr 09, 2026
Apr 14, 2026
7.5 HIGH
CVE-2026-29129 — Apache Tomcat: TLS cipher order is not preserved

Configured cipher preference order not preserved vulnerability in Apache Tomcat. This issue affects Apache Tomcat: from 11.0.16 through 11.0.18, from 10.1.51 through 10.1.52, from 9.0.114 through 9.…

tomcat | Remote | Cryptography
Apr 09, 2026 Apr 14, 2026
Apr 09, 2026
Apr 14, 2026
6.1 MEDIUM
CVE-2026-25854 — Apache Tomcat: Occasionally open redirect

Occasional URL redirection to untrusted Site ('Open Redirect') vulnerability in Apache Tomcat via the LoadBalancerDrainingValve. This issue affects Apache Tomcat: from 11.0.0-M1 through 11.0.18, fro…

tomcat | Remote | Misconfiguration
Apr 09, 2026 Apr 14, 2026
Apr 09, 2026
Apr 14, 2026
7.5 HIGH
CVE-2026-24880 — Apache Tomcat: Request smuggling via invalid chunk extension

Inconsistent Interpretation of HTTP Requests ('HTTP Request/Response Smuggling') vulnerability in Apache Tomcat via invalid chunk extension. This issue affects Apache Tomcat: from 11.0.0-M1 through …

tomcat | Remote | Misconfiguration
Apr 09, 2026 Apr 14, 2026
Apr 09, 2026
Apr 14, 2026
9.8 CRITICAL
CVE-2025-13926 — Contemporary Controls BASC 20T Reliance on Untrusted Inputs in a Security Decision

An attacker could use data obtained by sniffing the network traffic to forge packets in order to make arbitrary requests to Contemporary Controls BASC 20T.

Remote | Authentication
Apr 09, 2026 Apr 13, 2026
Apr 09, 2026
Apr 13, 2026
9.1 CRITICAL
CVE-2026-39912 — v2board / Xboard Authentication Token Exposure via loginWithMailLink

V2Board 1.6.1 through 1.7.4 and Xboard through 0.1.9 expose authentication tokens in HTTP response bodies of the loginWithMailLink endpoint when the login_with_mail_link_enable feature is active. Una…

Remote | Authentication
Apr 09, 2026 Apr 15, 2026
Apr 09, 2026
Apr 15, 2026
9.2 CRITICAL
CVE-2026-35556 — Plaintext storage of a password in OpenPLC_V3

OpenPLC_V3 is vulnerable to a Plaintext Storage of a Password vulnerability that could allow an attacker to retrieve credentials and access sensitive information.

openplc_v3_firmware openplc_v3 | Remote | Cryptography
Apr 09, 2026 Apr 16, 2026
Apr 09, 2026
Apr 16, 2026
6.1 MEDIUM
CVE-2026-35195 — Wasmtime has an out-of-bounds write or crash when transcoding component model strings

Wasmtime is a runtime for WebAssembly. Prior to 24.0.7, 36.0.7, 42.0.2, and 43.0.1, Wasmtime's implementation of transcoding strings between components contains a bug where the return value of a gues…

wasmtime | Remote | Memory Corruption
Apr 09, 2026 Apr 15, 2026
Apr 09, 2026
Apr 15, 2026
7.5 HIGH
CVE-2026-35186 — Wasmtime has an improperly masked return value from `table.grow` with Winch compiler back…

Wasmtime is a runtime for WebAssembly. From 25.0.0 to before 36.0.7, 42.0.2, and 43.0.1, Wasmtime's Winch compiler backend contains a bug where translating the table.grow operator causes the result t…

wasmtime | Remote | Denial of Service
Apr 09, 2026 Apr 15, 2026
Apr 09, 2026
Apr 15, 2026
Showing 20 of 6501 Results