Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
3.4 LOW
CVE-2026-42195 — Unvalidated gitlab URL parameter redirects OAuth authorize step to attacker-controlled ho…

draw.io is a configurable diagramming and whiteboarding application. Prior to version 29.7.9, the draw.io client accepts a ?gitlab= URL parameter that overrides the GitLab server URL used during OAut…

drawio | Remote | Authentication
May 08, 2026 May 12, 2026
May 08, 2026
May 12, 2026
9.1 CRITICAL
CVE-2026-42193 — Plunk: SNS webhook forgery

Plunk is an open-source email platform built on top of AWS SES. Prior to version 0.9.0, the /webhooks/sns endpoint accepts Amazon SNS notification payloads from unauthenticated requests without verif…

plunk | Remote | Authentication
May 08, 2026 May 12, 2026
May 08, 2026
May 12, 2026
5.4 MEDIUM
CVE-2026-42192 — Plunk: Stored XSS in campaign view

Plunk is an open-source email platform built on top of AWS SES. Prior to version 0.9.0, a stored cross-site scripting (XSS) vulnerability exists in the campaign management feature, where the email bo…

plunk | Remote | Cross-Site Scripting
May 08, 2026 May 12, 2026
May 08, 2026
May 12, 2026
0.0 NONE
CVE-2026-41517 — Emlog: Remote Code Execution via Malicious Plugin Upload

Emlog is an open source website building system. Prior to version 2.6.11, insecure plugin upload functionality allows attackers to upload and execute arbitrary PHP code, leading to complete server co…

emlog | Remote | Misconfiguration
May 08, 2026 May 12, 2026
May 08, 2026
May 12, 2026
8.9 HIGH
CVE-2026-41486 — Ray: Remote Code Execution via Parquet Arrow Extension Type Deserialization

Ray is an AI compute engine. From version 2.54.0 to before version 2.55.0, Ray Data registers custom Arrow extension types (ray.data.arrow_tensor, ray.data.arrow_tensor_v2, ray.data.arrow_variable_sh…

ray | Remote | Supply Chain
May 08, 2026 May 18, 2026
May 08, 2026
May 18, 2026
Showing 20 of 6725 Results