Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.1 HIGH
CVE-2026-45707 — n8n-MCP: Multi-tenant MCP requests fall back to process-level n8n credentials when tenant…

n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior to 2.51.2, when ENABLE_MULTI_TENANT=true, the HTTP transport documents that th…

n8n-mcp | Remote | Authorization
May 29, 2026 Jun 01, 2026
May 29, 2026
Jun 01, 2026
5.3 MEDIUM
CVE-2026-45620 — AVideo CVE-2026-43881 incomplete fix - `objects/mention.json.php:17` is an unauthenticate…

WWBN AVideo is an open source video platform. In 29.0 and earlier, objects/mention.json.php has no User::loginCheck() or admin gate. It only has an entry guard: preg_match('/^@/', $_REQUEST['term']) …

avideo | Remote | Authentication
May 29, 2026 Jun 01, 2026
May 29, 2026
Jun 01, 2026
6.5 MEDIUM
CVE-2026-45619 — AVideo CVE-2026-43884 incomplete fix - `isSSRFSafeURL()` call sites still discard the `$r…

WWBN AVideo is an open source video platform. In 29.0 and earlier, EpgParser.php, plugin/AI/receiveAsync.json.php, and other locations do not use the $resolvedIP out-param of isSSRFSafeURL() for DNS …

avideo | Remote | Server-Side Request Forgery
May 29, 2026 Jun 01, 2026
May 29, 2026
Jun 01, 2026
8.2 HIGH
CVE-2026-45615 — mouse07410/asn1c: 1-byte Heap Out-of-Bounds Read in `INTEGER_decode_oer` via Malformed OE…

mouse07410/asn1c is an ASN.1 compiler. In 1.4 and earlier, a memory safety vulnerability was identified in the OER decoding skeleton files generated by asn1c (specifically INTEGER_oer.c). When parsin…

Remote | Memory Corruption
May 29, 2026 Jun 01, 2026
May 29, 2026
Jun 01, 2026
6.5 MEDIUM
CVE-2026-45610 — WWBN AVideo plugin/LoginControl/set.json.php: 2FA toggle endpoint has no CSRF protection,…

WWBN AVideo is an open source video platform. In 29.0 and earlier, there is a cross-site request forgery vulnerability on the 2FA toggle. plugin/LoginControl/set.json.php accepts POST type=set2FA val…

avideo | Remote | Cross-Site Request Forgery
May 29, 2026 Jun 01, 2026
May 29, 2026
Jun 01, 2026
6.5 MEDIUM
CVE-2026-45582 — n8n-MCP: Workflow telemetry sanitizer could retain partial values from URL-shaped node pa…

n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior to 2.51.3, the workflow telemetry sanitizer could retain partial fragments of …

n8n-mcp | Remote | Information Disclosure
May 29, 2026 Jun 01, 2026
May 29, 2026
Jun 01, 2026
5.4 MEDIUM
CVE-2026-45580 — WWBN AVideo Live: stored XSS via unescaped stream key in modeYoutubeLive.php class attrib…

WWBN AVideo is an open source video platform. In 29.0 and earlier, there is a stored cross-site scripting vulnerability. The Live plugin's "YouTube-style" view renders the live transmission's stream …

avideo | Remote | Cross-Site Scripting
May 29, 2026 Jun 01, 2026
May 29, 2026
Jun 01, 2026
8.8 HIGH
CVE-2026-45578 — WWBN AVideo Live: OS command injection in on_publish.php execAsync via unescaped m3u8 URL

WWBN AVideo is an open source video platform. In 29.0 and earlier, there is a classic shell-metacharacter injection. The YPTSocket notification branch in plugin/Live/on_publish.php builds an execAsyn…

avideo | Remote | Injection
May 29, 2026 Jun 01, 2026
May 29, 2026
Jun 01, 2026
7.8 HIGH
CVE-2026-45555 — Roslyn CodeLens MCP Server: Untrusted Roslyn Analyzer Execution via get_diagnostics Leads…

Roslyn CodeLens MCP Server is a Roslyn-based MCP server providing semantic code intelligence for .NET codebases. From 0.0.9 to 1.17.0, the get_diagnostics MCP tool loads and executes all DiagnosticAn…

| Supply Chain
May 29, 2026 Jun 01, 2026
May 29, 2026
Jun 01, 2026
8.3 HIGH
CVE-2026-44698 — Home Assistant: Cross-origin iframe access token exfiltration via WebView JS bridge callb…

Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2026.4.1 for iOS and 2026.4.4 for Android, he Home Assistant Companion apps for Android and …

home-assistant | Remote | Cross-Site Scripting
May 29, 2026 May 29, 2026
May 29, 2026
May 29, 2026
8.8 HIGH
CVE-2026-44239 — FreePBX: Authenticated Local File Inclusion in Dashboard Module

FreePBX is an open source IP PBX. Prior to 16.0.22 and 17.0.5, the Dashboard module's getcontent AJAX handler includes PHP files based on user-supplied input without path sanitization. The $_REQUEST[…

freepbx | Remote | Path Traversal
May 29, 2026 Jun 01, 2026
May 29, 2026
Jun 01, 2026
8.8 HIGH
CVE-2026-44238 — FreePBX: Authenticated SQL Injection via ORDER BY in CDR Reports

FreePBX is an open source IP PBX. Prior to 16.0.50 and 17.0.11, the CDR Reports module page allows SQL injection through the order and sort POST parameters. Authentication with a FreePBX Administrati…

freepbx cdr | Remote | Injection
May 29, 2026 Jun 01, 2026
May 29, 2026
Jun 01, 2026
8.1 HIGH
CVE-2026-44237 — FreePBX: Authenticated Access can lead to Subsequent OAuth2 Authentication Bypass in API …

FreePBX is an open source IP PBX. Prior to 17.0.8, the FreePBX api module's OAuth2 implementation does not sufficiently validate client credentials during token issuance. Knowledge of a valid client_…

freepbx api | Remote | Authentication
May 29, 2026 Jun 01, 2026
May 29, 2026
Jun 01, 2026
7.8 HIGH
CVE-2026-40528 — OpenSC < 0.27.0 Buffer Overrun in do_key_value() via profile.c

OpenSC before 0.27.0, fixed in commit 0358817, contains a stack and heap buffer overrun vulnerability in the do_key_value() function in src/pkcs15init/profile.c that allows attackers to corrupt memor…

opensc | Memory Corruption
May 29, 2026 Jun 03, 2026
May 29, 2026
Jun 03, 2026
6.8 MEDIUM
CVE-2026-40510 — OpenSC < 0.27.0-rc1 Stack Buffer Overflow via piv_process_history() in card-piv.c

OpenSC before 0.27.0-rc1, fixed in commit 3f24f0b, contains a stack buffer overflow vulnerability in piv_process_history() in src/libopensc/card-piv.c that allows physically present attackers to trig…

opensc | Memory Corruption
May 29, 2026 Jun 03, 2026
May 29, 2026
Jun 03, 2026
5.3 MEDIUM
CVE-2026-10075 — Interinfo|DreamMaker - Path Traversal

DreamMaker developed by Interinfo has a Path Traversal vulnerability, allowing unauthenticated remote attackers to read file names under arbitrary path by exploiting an Absolute Path Traversal vulner…

Remote | Path Traversal
May 29, 2026 May 29, 2026
May 29, 2026
May 29, 2026
4.9 MEDIUM
CVE-2026-10074 — Interinfo|DreamMaker - Arbitrary File Read

DreamMaker developed by Interinfo has an Arbitrary File Read vulnerability, allowing privileged local attackers to exploit Relative Path Traversal to download arbitrary system files.

Remote | Path Traversal
May 29, 2026 May 29, 2026
May 29, 2026
May 29, 2026
7.5 HIGH
CVE-2026-10073 — Interinfo|DreamMaker - Arbitrary File Read

DreamMaker developed by Interinfo has an Arbitrary File Read vulnerability, allowing unauthenticated local attackers to exploit Relative Path Traversal to download arbitrary system files.

Remote | Path Traversal
May 29, 2026 May 29, 2026
May 29, 2026
May 29, 2026
7.2 HIGH
CVE-2026-10072 — Interinfo|DreamMaker - Arbitrary File Upload

DreamMaker developed by Interinfo has an Arbitrary File Upload vulnerability, allowing privileged remote attackers to upload and execute web shell backdoors, thereby enabling arbitrary code execution…

Remote | Misconfiguration
May 29, 2026 May 29, 2026
May 29, 2026
May 29, 2026
9.8 CRITICAL
CVE-2026-10061 — TRENDnet TEW-432BRP formWPS command injection

A vulnerability was found in TRENDnet TEW-432BRP 3.10B20. Affected is the function formWPS of the file /goform/formWPS. The manipulation of the argument peerPin results in command injection. The atta…

May 29, 2026 Jun 03, 2026
May 29, 2026
Jun 03, 2026
Showing 20 of 7188 Results