Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.9 CRITICAL
CVE-2026-44723 — Vowpal Wabbit: Shell injection via crafted PR title in python_checks.yml allows arbitrary…

Vowpal Wabbit is a machine learning system. The workflow .github/workflows/python_checks.yml embeds ${{ github.event.pull_request.title }} directly inside double-quoted bash strings in four separate …

vowpal_wabbit | Remote | Injection
May 26, 2026 May 28, 2026
May 26, 2026
May 28, 2026
7.6 HIGH
CVE-2026-44680 — MikroORM: SQL injection via runtime-controlled identifiers and JSON-path keys

MikroORM is a TypeScript ORM for Node.js based on Data Mapper, Unit of Work and Identity Map patterns. Prior to @mikro-orm/knex 6.6.14 and @mikro-orm/sql 7.0.14, MikroORM's identifier-quoting helper …

mikroorm | Remote | Injection
May 26, 2026 May 26, 2026
May 26, 2026
May 26, 2026
4.3 MEDIUM
CVE-2026-44502 — Bugsink: SSRF bypass in `validate_webhook_url`

Bugsink is a self-hosted error tracking tool. Prior to 2.1.3, Bugsink’s webhook URL validation could be (partially) bypassed because of a mismatch in URL parsing. The original validation logic parsed…

bugsink | Remote | Misconfiguration
May 26, 2026 May 26, 2026
May 26, 2026
May 26, 2026
5.3 MEDIUM
CVE-2026-44314 — Traccar: Missing edit authorization on device image upload allows read-only users to writ…

Traccar is an open source GPS tracking system. Prior to 6.13.0, DeviceResource.uploadImage authorizes the target device only through Condition.Permission(User.class, getUserId(), Device.class) and th…

traccar | Remote | Authorization
May 26, 2026 May 27, 2026
May 26, 2026
May 27, 2026
8.7 HIGH
CVE-2026-43982 — Algernon: Path traversal file write via savein()

Algernon is a small self-contained pure-Go web server. Prior to 1.17.6, uploadedFileSaveIn() in lua/upload/upload.go uses filepath.Join() with the caller-supplied directory but performs no boundary c…

algernon | Remote | Path Traversal
May 26, 2026 May 26, 2026
May 26, 2026
May 26, 2026
8.2 HIGH
CVE-2026-43981 — Algernon: Race Condition in handle() shared LState

Algernon is a small self-contained pure-Go web server. Prior to 1.17.6, in engine/luahandler.go, the sync.RWMutex protecting LoadCommonFunctions is released before L.Push() and L.PCall() execute. Sin…

algernon | Remote | Race Condition
May 26, 2026 May 26, 2026
May 26, 2026
May 26, 2026
7.5 HIGH
CVE-2026-40384 — Joomla! Core - [20260510] - Path traversal in com_media webservice endpoint

An improper validation of the search parameter of the com_media files API endpoint leads to a path traversal vulnerability.

joomla\! | Remote | Path Traversal
May 26, 2026 May 28, 2026
May 26, 2026
May 28, 2026
9.8 CRITICAL
CVE-2026-40383 — Joomla! Core - [20260509] - LFI in HTMLView layout parameter

An improper validation of user-supplied input leads to a local file inclusion vulnerability.

joomla\! | Remote | Path Traversal
May 26, 2026 May 27, 2026
May 26, 2026
May 27, 2026
9.8 CRITICAL
CVE-2026-35223 — Joomla! Core - [20260508] - Improper access check in com_config webservice endpoints

An improper access check allows unauthorized access to com_config webservice endpoints.

joomla\! | Remote | Authorization
May 26, 2026 May 28, 2026
May 26, 2026
May 28, 2026
9.8 CRITICAL
CVE-2026-35222 — Joomla! Core - [20260507] - Authenticated blind SQLi in com_tags

Improperly validated order clauses lead to a SQL injection vulnerability in com_tags.

joomla\! | Remote | Injection
May 26, 2026 May 27, 2026
May 26, 2026
May 27, 2026
9.8 CRITICAL
CVE-2026-35221 — Joomla! Core - [20260506] - Authenticated blind SQLi in com_finder

Improperly built filter clauses lead to a SQL injection vulnerability in the search query for com_finder.

joomla\! | Remote | Injection
May 26, 2026 May 27, 2026
May 26, 2026
May 27, 2026
4.6 MEDIUM
CVE-2026-35220 — Joomla! Core - [20260505] - CSRF in user activation endpoint

Lack of CSRF token validation lead to a CSRF attack vector in the admin activation endpoint of com_users.

joomla\! | Remote | Cross-Site Request Forgery
May 26, 2026 May 27, 2026
May 26, 2026
May 27, 2026
6.9 MEDIUM
CVE-2026-30895 — Joomla! Core - [20260504] - XSS in readmore links

Lack of output escaping leads to a XSS vector in the readmore links for com_content.

joomla\! | Remote | Cross-Site Scripting
May 26, 2026 May 27, 2026
May 26, 2026
May 27, 2026
6.9 MEDIUM
CVE-2026-30894 — Joomla! Core - [20260503] - XSS in com_contenthistory

Lack of output escaping leads to a XSS vector in the content history component.

joomla\! | Remote | Cross-Site Scripting
May 26, 2026 May 27, 2026
May 26, 2026
May 27, 2026
9.2 CRITICAL
CVE-2026-2264 — Server-Side Request Forgery and Credential Exfiltration in Google Cloud Apigee via SetInt…

A vulnerability in the Google Cloud Apigee SetIntegrationRequest policy allowed remote attackers to perform Server-Side Request Forgery (SSRF) and exfiltrate service account access tokens. For succe…

Remote | Server-Side Request Forgery
May 26, 2026 May 26, 2026
May 26, 2026
May 26, 2026
6.9 MEDIUM
CVE-2026-25901 — Joomla! Core - [20260502] - XSS in com_associations

Lack of output escaping leads to a XSS vector in the multilingual associations component.

joomla\! | Remote | Cross-Site Scripting
May 26, 2026 May 27, 2026
May 26, 2026
May 27, 2026
6.9 MEDIUM
CVE-2026-25900 — Joomla! Core - [20260501] - XSS in feed modules

Lack of output escaping leads to a XSS vector in the feed modules.

joomla\! | Remote | Cross-Site Scripting
May 26, 2026 May 27, 2026
May 26, 2026
May 27, 2026
9.8 CRITICAL
CVE-2026-24212 — NVIDIA Isaac Launchable for Linux Cleartext Information Disclosure and Execution

NVIDIA Isaac Launchable for Linux contains a vulnerability where sensitive information is transmitted in clear text. A successful exploit of this vulnerability might lead to code execution, escalatio…

linux_kernel isaac_launchable | Remote | Information Disclosure
May 26, 2026 May 27, 2026
May 26, 2026
May 27, 2026
7.8 HIGH
CVE-2026-24162 — NVIDIA Transformers4Rec Linux Improper Deserialization Vulnerability

NVIDIA Transformers4Rec for Linux contains a vulnerability where an attacker could cause improper deserialization of untrusted data. A successful exploit of this vulnerability might lead to code exec…

May 26, 2026 Jun 04, 2026
May 26, 2026
Jun 04, 2026
7.5 HIGH
CVE-2025-36221 — Vulnerabilities exists in IBM Cloud Pak for Data System (CPDS 1.0) - Cyclops.

IBM Cloud Pak for Data System - Cyclops 11.3.0.2 through Interim Fix 002 IBM Cloud Pak for Data System uses default passwords default passwords from the manufacturing process for use during the inst…

May 26, 2026 Jun 02, 2026
May 26, 2026
Jun 02, 2026
Showing 20 of 7013 Results