Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.7 HIGH
CVE-2026-44593 — esm.sh: Legacy Route Path Traversal Can Lead to RCE

esm.sh is a no-build content delivery network (CDN) for web development. In 137 and earlier, the legacy router first retrieves a response from legacyServer, parses the incoming request path, and ulti…

esm.sh | Remote | Path Traversal
May 28, 2026 Jun 02, 2026
May 28, 2026
Jun 02, 2026
8.2 HIGH
CVE-2026-44358 — Espressif Shared GitHub DangerJS: Untrusted Search Path in DangerJS Action Entrypoint

Espressif Shared GitHub DangerJS is a reusable GitHub Action CI DangerJS workflow for Espressif GitHub projects. Prior to 1.0.1, the action's entrypoint.sh invoked DangerJS from the caller's workspac…

Remote | Supply Chain
May 28, 2026 Jun 01, 2026
May 28, 2026
Jun 01, 2026
7.5 HIGH
CVE-2026-41565 — CryptX versions before 0.088_001 for Perl have a stack buffer overflow in four AEAD decry…

CryptX versions before 0.088_001 for Perl have a stack buffer overflow in four AEAD decrypt_verify helpers. The gcm_decrypt_verify, ccm_decrypt_verify, chacha20poly1305_decrypt_verify and eax_decryp…

cryptx | Remote | Memory Corruption
May 28, 2026 May 29, 2026
May 28, 2026
May 29, 2026
8.8 HIGH
CVE-2026-35676 — phpMyFAQ - Unauthenticated Password Reset via User Password Update Endpoint

phpMyFAQ before 4.1.3 contains an unauthenticated password reset vulnerability in the user password update API endpoint that allows attackers to change account passwords without token validation. Att…

phpmyfaq | Remote | Authentication
May 28, 2026 May 28, 2026
May 28, 2026
May 28, 2026
8.8 HIGH
CVE-2026-35675 — phpMyFAQ - Authentication Bypass via Missing Password Reset Token in /api/user/password/u…

phpMyFAQ before 4.1.3 contains an authentication bypass vulnerability in the password reset endpoint that allows unauthenticated attackers to reset any user account password without token verificatio…

phpmyfaq | Remote | Authentication
May 28, 2026 May 29, 2026
May 28, 2026
May 29, 2026
8.7 HIGH
CVE-2026-35672 — phpMyFAQ - Authentication Bypass via Empty API Token

phpMyFAQ before 4.1.3 contains an authentication bypass vulnerability in API v4.0 where the default empty api.apiClientToken allows unauthenticated users to create and modify FAQ entries. Attackers c…

phpmyfaq | Remote | Authentication
May 28, 2026 May 28, 2026
May 28, 2026
May 28, 2026
8.8 HIGH
CVE-2026-35671 — phpMyFAQ - Insecure Direct Object Reference in User Password API

phpMyFAQ before 4.1.3 contains an insecure direct object reference vulnerability in the admin API user password endpoint that allows authenticated administrators to change any user's password without…

phpmyfaq | Remote | Authorization
May 28, 2026 May 30, 2026
May 28, 2026
May 30, 2026
2.9 LOW
CVE-2026-9828 — Logback deserialization whitelist bypass for java.lang and java.util

Deserialization of untrusted data vulnerability in QOS.CH Sarl logback logback-core (HardenedObjectInputStream (logback-core) modules) allows Object Injection albeit heavily restricted. More precise…

Remote | Injection
May 28, 2026 May 29, 2026
May 28, 2026
May 29, 2026
5.3 MEDIUM
CVE-2026-8990 — Authentication Bypass in Kidsview

A user with physical access to a smartphone can bypass authentication mechanism of Kidsview mobile application and grant himself full access to the device owner's account by interacting with applicat…

| Authentication
May 28, 2026 May 28, 2026
May 28, 2026
May 28, 2026
9.3 CRITICAL
CVE-2026-8980 — Privilege Escalation

The Mennekes Amtron series (firmware versions ≤ 5.22.3) is vulnerable to privilege escalation. An authenticated low-privileged user can change the passwords of the admin (operator) and manufacturer a…

Remote | Authorization
May 28, 2026 May 28, 2026
May 28, 2026
May 28, 2026
9.3 CRITICAL
CVE-2026-8979 — Authentication Bypass

The Mennekes Amtron series (firmware versions ≤ 5.22.3) is vulnerable to an authentication bypass. An unauthenticated remote attacker can change the password of the user account via a crafted POST re…

Remote | Authentication
May 28, 2026 May 28, 2026
May 28, 2026
May 28, 2026
8.4 HIGH
CVE-2026-49238 — SFTP Server VM Escape in Canonical Multipass

An issue was discovered in Canonical Multipass before version 1.16.3. The host-side SFTP server component (sshfs_server), which executes with root privileges on the host, contains a path containment …

multipass | Path Traversal
May 28, 2026 Jun 01, 2026
May 28, 2026
Jun 01, 2026
7.8 HIGH
CVE-2026-49237 — Local Privilege Escalation in Canonical Multipass

An issue was discovered in Canonical Multipass for macOS before version 1.16.3 due to an incomplete fix for CVE-2025-5199. While the patch in version 1.16.0 updated the ownership of the multipassd da…

macos multipass | Misconfiguration
May 28, 2026 Jun 01, 2026
May 28, 2026
Jun 01, 2026
5.1 MEDIUM
CVE-2026-42250 — Off-by-One Leading to Out-of-Bounds Write in bzip2

bzip2 contains an off‑by‑one error in the bzip2recover utility. When processing a specially crafted file, the application performs an out‑of‑bounds write to a global buffer, resulting in memory corru…

trusted_profile_analyzer | Memory Corruption
May 28, 2026 Jun 05, 2026
May 28, 2026
Jun 05, 2026
7.3 HIGH
CVE-2026-37579 — SMSGate sms-core Remote Code Execution

An issue in SMSGate sms-core<=2.1.13.6 allows a remote attacker to execute arbitrary code via the Cmpp7FDeliverRequestMessageCodec.java component

Remote | Memory Corruption
May 28, 2026 Jun 01, 2026
May 28, 2026
Jun 01, 2026
8.0 HIGH
CVE-2026-37266 — Apache Struts Remote Code Execution

An issue in Responsive File Manager Responsive FileManager Version 9.14.0 allows a remote attacker to execute arbitrary code via the force_download.php component

Remote | Injection
May 28, 2026 May 29, 2026
May 28, 2026
May 29, 2026
7.3 HIGH
CVE-2026-9658 — Plack::Middleware::Security::Common versions before 0.13.1 for Perl did not block header …

Plack::Middleware::Security::Common versions before 0.13.1 for Perl did not block header injections in request paths. The header injection rule was ineffective at blocking header injections in the r…

Remote | Injection
May 28, 2026 Jun 01, 2026
May 28, 2026
Jun 01, 2026
4.3 MEDIUM
CVE-2026-40914 — Apache Artemis Stomp Protocol, Apache ActiveMQ Artemis Stomp Protocol: Address routing-ty…

A vulnerability exists in Apache Artemis whereby an application using the STOMP protocol with security credentials that grant either the consume or send permission on an address can augment the routi…

activemq_artemis artemis | Remote | Authorization
May 28, 2026 May 29, 2026
May 28, 2026
May 29, 2026
9.9 CRITICAL
CVE-2026-9813 — FlowIntel external reference URL probe allows server-side request forgery

FlowIntel up to version 3.3.0 contains a server-side request forgery (SSRF) vulnerability in the external reference URL probe functionality in app/case/task.py. An attacker who can submit an external…

flowintel | Remote | Server-Side Request Forgery
May 28, 2026 Jun 04, 2026
May 28, 2026
Jun 04, 2026
6.0 MEDIUM
CVE-2026-4377 — Use of Weak Credentials in D-Link DWR-X1820 router

Dlink DWR-X1820 router uses weak default password generated from its IMEI number and does not require users to change it. An attacker who knows how passwords are generated can easily crack the defaul…

| Authentication
May 28, 2026 May 28, 2026
May 28, 2026
May 28, 2026
Showing 20 of 7213 Results