Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.8 CRITICAL
CVE-2026-7304 — CVE-2026-7304

SGLangs multimodal generation runtime is vulnerable to unauthenticated remote code execution when the --enable-custom-logit-processor option is enabled, as Python objects loaded via dill.loads() will…

sglang | Remote | Authentication
May 18, 2026 May 19, 2026
May 18, 2026
May 19, 2026
9.1 CRITICAL
CVE-2026-7302 — CVE-2026-7302

SGLangs multimodal generation runtime is vulnerable to an unauthenticated path traversal vulnerability, allowing an attacker to write arbitrary files anywhere the server process has write access, by …

sglang | Remote | Path Traversal
May 18, 2026 May 19, 2026
May 18, 2026
May 19, 2026
9.8 CRITICAL
CVE-2026-7301 — CVE-2026-7301

SGLangs multimodal generation runtime scheduler's ROUTER socket binds to 0.0.0.0 by default and contains a sink that calls pickle.loads() on incoming messages, enabling RCE when exposed to the intern…

sglang | Remote | Information Disclosure
May 18, 2026 May 19, 2026
May 18, 2026
May 19, 2026
7.1 HIGH
CVE-2026-0983 — Denial of service vulnerability in M-Files Server

Denial-of-service condition in M-Files Server versions before 26.5.16015.0, before 26.2 LTS, and before 25.8 LTS SR3 allows an authenticated user to cause the MFserver process to crash

m-files_server | Remote | Denial of Service
May 18, 2026 May 18, 2026
May 18, 2026
May 18, 2026
5.3 MEDIUM
CVE-2026-8802 — opensourcepos Open Source Point of Sale Items.php getPicThumb path traversal

A vulnerability was detected in opensourcepos Open Source Point of Sale up to 3.4.2. This issue affects the function getPicThumb of the file app/Controllers/Items.php. The manipulation of the argumen…

open_source_point_of_sale | Remote | Path Traversal
May 18, 2026 May 18, 2026
May 18, 2026
May 18, 2026
9.3 CRITICAL
CVE-2026-4320 — Authorization Bypass in ICMS Content Management by Creartia Internet Consulting

Authorization Bypass vulnerability in Creartia's ICMS software could allow an attacker to gain unauthorized access to protected features by manipulating the HTTP redirect headers of the login process…

Remote | Authorization
May 18, 2026 May 18, 2026
May 18, 2026
May 18, 2026
6.8 MEDIUM
CVE-2026-41119 — Dell Live Optics Certificate Validation Vulnerability

Dell Live Optics Windows and Personal Edition collectors contain an improper certificate validation vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability leadi…

Remote | Misconfiguration
May 18, 2026 May 18, 2026
May 18, 2026
May 18, 2026
8.8 HIGH
CVE-2026-7498 — Stored XSS in Basamak Informatics' DernekWeb

Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Basamak Information Technology Consulting and Organization Trade Ltd. Co. DernekWeb allows Stored…

Remote | Cross-Site Scripting
May 18, 2026 May 18, 2026
May 18, 2026
May 18, 2026
7.7 HIGH
CVE-2026-6902 — Code Injection in Perforce P4 (Helix Core)

A Remote Code Execution vulnerability in P4 (Helix Core) Server's Command-Line Client, prior to the 2025.2 Patch 2, has been fixed to address potential security risks.

Remote | Injection
May 18, 2026 May 20, 2026
May 18, 2026
May 20, 2026
7.6 HIGH
CVE-2026-6347 — Mattermost Calls plugin exposes TURN server credentials in plaintext in support packets

Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to sanitize sensitive configuration fields in the Mattermost Calls plugin which allows an attacker with access to a su…

mattermost_server | Remote | Information Disclosure
May 18, 2026 May 18, 2026
May 18, 2026
May 18, 2026
8.7 HIGH
CVE-2026-6346 — Sensitive credentials exposed in plaintext in Mattermost support packets

Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to sanitize sensitive configuration fields before including them in support packet generation, which allows a Mattermo…

mattermost_server legal_hold | Remote | Information Disclosure
May 18, 2026 May 18, 2026
May 18, 2026
May 18, 2026
6.5 MEDIUM
CVE-2026-6345 — Prevent password disclosure and force reset during Slack import

Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail prevent disclosure of created user password which allows a malicious attacker to impersonate a user via the use of som…

mattermost_server legal_hold | Remote | Information Disclosure
May 18, 2026 May 18, 2026
May 18, 2026
May 18, 2026
4.3 MEDIUM
CVE-2026-6343 — Mattermost Playbooks Plugin fails to enforce view permissions in list endpoints, allowing…

Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13, 11.4.x <= 11.4.3 fail to check public/private permissions which allows members without these permissions to access public playbooks via /get…

mattermost_server legal_hold | Remote | Authorization
May 18, 2026 May 18, 2026
May 18, 2026
May 18, 2026
4.3 MEDIUM
CVE-2026-6339 — Missing request origin validation on burn-on-read reveal endpoint

Mattermost versions 11.5.x <= 11.5.1, 11.4.x <= 11.4.3 fail to validate the X-Requested-With header on the burn-on-read reveal endpoint which allows an authenticated channel member to force the revea…

mattermost_server legal_hold | Remote | Cross-Site Request Forgery
May 18, 2026 May 18, 2026
May 18, 2026
May 18, 2026
5.0 MEDIUM
CVE-2026-6333 — SSRF via Host Header Spoofing in Custom Slash Commands

Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to validate the Host header when constructing response URLs for custom slash commands which allows an authenticated attacker to redirect…

mattermost_server legal_hold | Remote | Server-Side Request Forgery
May 18, 2026 May 19, 2026
May 18, 2026
May 19, 2026
6.5 MEDIUM
CVE-2026-5163 — Missing authorization check in AI message rewrite endpoint allows access to private threa…

Mattermost versions 11.5.x <= 11.5.1 fail to verify channel membership when processing AI-assisted message rewrites which allows an authenticated attacker to read the content of threads in private ch…

mattermost_server legal_hold | Remote | Authorization
May 18, 2026 May 18, 2026
May 18, 2026
May 18, 2026
3.5 LOW
CVE-2026-4643 — Calling window.close() from server-side content causes crash in the Mattermost Desktop App

Mattermost Desktop App versions <=6.1 6.0.1 5.4.13.0 fail to prevent server-rendered content from closing an underlying application view in the Mattermost Desktop App which allows a malicious server …

mattermost_server mattermost_desktop legal_hold | Remote | Denial of Service
May 18, 2026 Jun 05, 2026
May 18, 2026
Jun 05, 2026
4.3 MEDIUM
CVE-2026-4286 — Playbooks Plugin fails to validate team transfers, allowing unauthorized removal of membe…

Mattermost versions 11.5.x <= 11.5.1, 10.11.x <= 10.11.13 fail to check if {{team_id}} was being changed when updating playbooks, allowing users with only {{Manage Playbook Configurations}} permissio…

mattermost_server legal_hold | Remote | Authorization
May 18, 2026 May 18, 2026
May 18, 2026
May 18, 2026
6.5 MEDIUM
CVE-2026-3471 — Opening a window with {{javascript:alert()}} as URL causes crash in the Mattermost Deskto…

Mattermost Desktop App versions <=6.1 6.0.1 5.4.13.0 fail to prevent an invalid URL from loading in a pop-up window in the Mattermost Desktop App which allows a malicious server owner to repeated cra…

mattermost_server mattermost_desktop legal_hold | Remote | Denial of Service
May 18, 2026 Jun 05, 2026
May 18, 2026
Jun 05, 2026
6.5 MEDIUM
CVE-2026-3117 — Instance and webhook GitLab plugin commands were able to be run by non-admin users

Mattermost Plugins versions <=11.5 11.1.5 10.13.11 11.3.4.0 fail to properly check for permissions when processing commands in the Gitlab plugin which allows normal users to uninstall instances or se…

mattermost_server legal_hold | Remote | Authorization
May 18, 2026 May 29, 2026
May 18, 2026
May 29, 2026
Showing 20 of 7161 Results