Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.5 MEDIUM
CVE-2026-47326 — Memory leak in Ubuntu Linux AppArmor large notification response allocation

Ubuntu Linux 6.8, 6.17 and 7.0 contain SAUCE patches with a memory leak in the handling of big responses to AppArmor notifications. The bug can be triggered by an unprivileged local user. The memory …

ubuntu_linux | Memory Corruption
May 28, 2026 May 29, 2026
May 28, 2026
May 29, 2026
6.9 MEDIUM
CVE-2026-47136 — RustFS: Unauthenticated RustFS console license endpoint exposes license metadata

RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, the RustFS console endpoint GET /rustfs/console/license returns parsed license metadata without requiring authentic…

rustfs | Remote | Information Disclosure
May 28, 2026 May 29, 2026
May 28, 2026
May 29, 2026
6.0 MEDIUM
CVE-2026-46685 — RustFS: Reflective CORS with credentials on S3 listener; unauthenticated license metadata…

RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, when RUSTFS_CORS_ALLOWED_ORIGINS is unset, the RustFS S3 listener's ConditionalCorsLayer reflects any request Origi…

rustfs | Remote | Misconfiguration
May 28, 2026 May 29, 2026
May 28, 2026
May 29, 2026
5.0 MEDIUM
CVE-2026-46526 — Local Deep Research: SSRF bypass in `safe_get`

Local Deep Research is an AI-powered research assistant for deep, iterative research. Prior to 1.6.10, the URL checking logic in local-deep-research has a logical flaw that could be bypassed by attac…

local_deep_research | Remote | Server-Side Request Forgery
May 28, 2026 Jun 01, 2026
May 28, 2026
Jun 01, 2026
8.2 HIGH
CVE-2026-46509 — deepobj: Improperly Controlled Modification of Object Prototype Attributes ('Prototype Po…

deepobj provides get, set, delete deep objects in javascript. Prior to 1.0.3, prototype pollution is possible when property paths contain __proto__/constructor/prototype. The property path must not b…

Remote | Misconfiguration
May 28, 2026 Jun 01, 2026
May 28, 2026
Jun 01, 2026
7.5 HIGH
CVE-2026-45332 — Automad Broken Access Control: unauthenticated exposure of administrator bcrypt password …

Automad is a flat-file content management system and template engine. From 2.0.0-alpha.1 to 2.0.0-beta.27, a Broken Access Control vulnerability allows an unauthenticated attacker to retrieve the bcr…

automad | Remote | Authentication
May 28, 2026 Jun 01, 2026
May 28, 2026
Jun 01, 2026
8.8 HIGH
CVE-2026-45044 — RustFS: Authentication bypass in /profile/cpu and /profile/memory allows unauthenticated …

RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, the admin router explicitly whitelists /profile/cpu and /profile/memory from the authentication layer, allowing any…

rustfs | Remote | Denial of Service
May 28, 2026 May 29, 2026
May 28, 2026
May 29, 2026
7.1 HIGH
CVE-2026-45042 — RustFS: UploadPartCopy Does Not Enforce Destination Bucket Policy on Copy Source

RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, improper authorization in the UploadPartCopy operation allows copying objects across buckets without enforcing dest…

rustfs | Remote | Authorization
May 28, 2026 May 29, 2026
May 28, 2026
May 29, 2026
8.7 HIGH
CVE-2026-45041 — RustFS: Hard-coded RSA private key in license verifier permits arbitrary license forgery

RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, crates/appauth/src/token.rs ships a 2048-bit RSA private key as a string constant named TEST_PRIVATE_KEY and uses i…

rustfs | Remote | Cryptography
May 28, 2026 May 29, 2026
May 28, 2026
May 29, 2026
5.3 MEDIUM
CVE-2026-45040 — RustFS: Sensitive Information Leakage (SessionToken and SecretAccessKey) in RustFS Logs […

RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, RustFS suffers from sensitive information leakage in log outputs. When the server is run with RUST_LOG=debug sensit…

rustfs | Remote | Information Disclosure
May 28, 2026 Jun 02, 2026
May 28, 2026
Jun 02, 2026
9.8 CRITICAL
CVE-2026-45039 — RustFS: Internode RPC HMAC secret falls back to public default credential, enabling peer …

RustFS is a distributed object storage system built in Rust. Prior to 1.0.0-beta.2, the internode RPC layer authenticates every request with an HMAC-SHA256 signature using a shared secret. The functi…

rustfs | Remote | Authentication
May 28, 2026 May 29, 2026
May 28, 2026
May 29, 2026
8.1 HIGH
CVE-2026-44394 — OpenStack Keystone Infinite Token Lifetime Vulnerability

An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone federated token rescoping mechanism does not propagate the original token's expiry to the newly issued token. When a federate…

keystone | Remote | Authentication
May 28, 2026 Jun 02, 2026
May 28, 2026
Jun 02, 2026
5.0 MEDIUM
CVE-2026-43979 — Local Deep Research: HTML Injection via Unescaped User Input in PDF Export (`pdf_service.…

Local Deep Research is an AI-powered research assistant for deep, iterative research. Prior to 1.6.0, PDFService._markdown_to_html() constructs an HTML document by interpolating user-controlled value…

local_deep_research | Remote | Cross-Site Scripting
May 28, 2026 Jun 01, 2026
May 28, 2026
Jun 01, 2026
8.8 HIGH
CVE-2026-43000 — OpenStack Keystone Trust Delegation Privilege Escalation Vulnerability

An issue was discovered in OpenStack Keystone before 29.0.2. When combined with an application credential impersonation vulnerability, an attacker with the member role on a project can escalate to ad…

keystone | Remote | Authorization
May 28, 2026 Jun 02, 2026
May 28, 2026
Jun 02, 2026
8.8 HIGH
CVE-2026-42999 — OpenStack Keystone JSON Injection Vulnerability

An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone RBAC policy enforcer in enforce_call unconditionally merges the raw JSON request body into the policy enforcement dictionary …

keystone | Remote | Authorization
May 28, 2026 Jun 02, 2026
May 28, 2026
Jun 02, 2026
8.8 HIGH
CVE-2026-42998 — OpenStack Keystone Credential Authentication Impersonation

An issue was discovered in OpenStack Keystone before 29.0.2. The Keystone application credential authentication plugin does not verify that the user supplied in the authentication request matches the…

keystone | Remote | Authentication
May 28, 2026 Jun 02, 2026
May 28, 2026
Jun 02, 2026
7.3 HIGH
CVE-2026-30761 — SourceBans Material Admin File Upload RCE

An arbitrary file upload vulnerability in the pages/admin.uploadmapimg.php component of SourceBans Material Admin v1.1.6 allows attackers to execute arbitrary code via uploading a crafted image file.

Remote | Misconfiguration
May 28, 2026 May 29, 2026
May 28, 2026
May 29, 2026
7.3 HIGH
CVE-2026-30760 — SourceBans Material Admin Unauthenticated Arbitrary Data Manipulation Vulnerability

An issue in SourceBans Material Admin before v.1.1.6 (3ecd95e) allows attackers to manipulate arbitrary user data in the web app via a crafted XAJAX call.

Remote | Injection
May 28, 2026 May 29, 2026
May 28, 2026
May 29, 2026
5.0 MEDIUM
CVE-2026-46561 — pyLoad: SSRF via HTTP Redirect Bypass in parse_urls API

pyLoad is a free and open-source download manager written in Python. Prior to 0.5.0b3.dev100, the PREREQFUNCTION-based private IP check was not applied to HTTPRequest (used by the parse_urls API). An…

pyload | Remote | Server-Side Request Forgery
May 28, 2026 May 29, 2026
May 28, 2026
May 29, 2026
9.1 CRITICAL
CVE-2026-45787 — electerm's encrypt method not safe enough

electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to 3.9.5, deterministic AES-192-CBC with a fixed zero IV, constant KDF salt, and no MAC leads to confid…

electerm | Remote | Cryptography
May 28, 2026 Jun 03, 2026
May 28, 2026
Jun 03, 2026
Showing 20 of 7161 Results