Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.8 CRITICAL
CVE-2026-48687 — FastNetMon Juniper Router Integration OS Command Injection

FastNetMon Community Edition through 1.2.9 contains an OS command injection vulnerability in the Juniper router integration plugin. The _log() function in src/juniper_plugin/fastnetmon_juniper.php (l…

fastnetmon | Remote | Injection
May 26, 2026 May 27, 2026
May 26, 2026
May 27, 2026
9.8 CRITICAL
CVE-2026-48686 — FastNetMon Community Edition Buffer Overflow Vulnerability

FastNetMon Community Edition through 1.2.9 contains a stack-based buffer overflow in the BGP NLRI (Network Layer Reachability Information) decoder. The function decode_bgp_subnet_encoding_ipv4_raw() …

fastnetmon | Remote | Memory Corruption
May 26, 2026 May 27, 2026
May 26, 2026
May 27, 2026
6.5 MEDIUM
CVE-2026-48685 — FastNetMon BGP Path Attribute Out-of-Bounds Memory Access Vulnerability

FastNetMon Community Edition through 1.2.9 has out-of-bounds memory access because it incorrectly parses BGP path attributes with the extended length flag set. In src/bgp_protocol.hpp, the parse_raw_…

fastnetmon | Remote | Memory Corruption
May 26, 2026 May 27, 2026
May 26, 2026
May 27, 2026
6.5 MEDIUM
CVE-2026-48684 — FastNetMon Community Edition Out-of-Bounds Read Vulnerability

FastNetMon Community Edition through 1.2.9 contains an out-of-bounds read in the NetFlow v9 options template parser. In process_netflow_v9_options_template() (src/netflow_plugin/netflow_v9_collector.…

fastnetmon | Remote | Memory Corruption
May 26, 2026 May 27, 2026
May 26, 2026
May 27, 2026
6.5 MEDIUM
CVE-2026-48683 — FastNetMon Community Edition Out-of-Bounds Read Vulnerability

FastNetMon Community Edition through 1.2.9 contains an out-of-bounds read vulnerability in the NetFlow v9 data flowset processor. In src/netflow_plugin/netflow_v9_collector.cpp, the Data template bra…

Remote | Information Disclosure
May 26, 2026 May 26, 2026
May 26, 2026
May 26, 2026
6.5 MEDIUM
CVE-2026-46620 — e107: CSRF in comment.php moderation endpoints via token-optional validation in session_h…

e107 is a content management system (CMS). Prior to 2.3.5, e107 CMS does not properly enforce CSRF token validation on comment moderation actions. The problem comes down to how session_handler::check…

e107 | Remote | Cross-Site Request Forgery
May 26, 2026 May 27, 2026
May 26, 2026
May 27, 2026
4.3 MEDIUM
CVE-2026-43936 — e107: Server-Side Request Forgery (SSRF) in the remote file fetcher

e107 is a content management system (CMS). Prior to 2.3.4, you can access the local environment by specifying the URL of the local environment from "Image/File URL:" of "From a remote location" in "M…

e107 | Remote | Path Traversal
May 26, 2026 May 26, 2026
May 26, 2026
May 26, 2026
8.1 HIGH
CVE-2026-43935 — e107: Host Header Injection in e107 password reset enables phishing

e107 is a content management system (CMS). Prior to 2.3.4, a Host Header Injection vulnerability in the password reset page allows attackers to manipulate the Host header to generate password reset l…

e107 | Remote | Misconfiguration
May 26, 2026 May 26, 2026
May 26, 2026
May 26, 2026
6.5 MEDIUM
CVE-2026-43934 — e107: Broken Access Control in e107 comment edit allows cross-user comment modification

e107 is a content management system (CMS). Prior to 2.3.4, a Broken Access Control vulnerability exists in the application, allowing an unauthorized authenticated user to edit comments posted by othe…

e107 | Remote | Authorization
May 26, 2026 May 26, 2026
May 26, 2026
May 26, 2026
6.5 MEDIUM
CVE-2026-40564 — Apache Flink Kubernetes Operator: Server-Side Request Forgery and local file access in Ku…

Files or Directories Accessible to External Parties, Server-Side Request Forgery (SSRF) vulnerability in Apache Flink Kubernetes Operator. The FlinkSessionJob jarURI is currently not validated so th…

flink_kubernetes_operator | Remote | Server-Side Request Forgery
May 26, 2026 Jun 02, 2026
May 26, 2026
Jun 02, 2026
4.3 MEDIUM
CVE-2026-38587 — ONLYOFFICE DocSpace IDOR Vulnerability

An Insecure Direct Object Reference (IDOR) vulnerability was discovered in ONLYOFFICE DocSpace before 3.2.1. The flaw exists in multiple REST API endpoints. This allows authenticated users with low-l…

Remote | Authorization
May 26, 2026 May 26, 2026
May 26, 2026
May 26, 2026
7.8 HIGH
CVE-2026-25112 — Genetec RabbitMQ Privilege Escalation Vulnerability

A high-severity vulnerability in the deployment of Genetec RabbitMQ that allows a privilege escalation attack.

| Authorization
May 26, 2026 May 26, 2026
May 26, 2026
May 26, 2026
7.5 HIGH
CVE-2026-9552 — Das Parking Management System 停车场管理系统 Search API Endpoint sql injection

A security flaw has been discovered in Das Parking Management System 停车场管理系统 6.2.0. This vulnerability affects unknown code of the component Search API Endpoint. The manipulation of the argument Valu…

parking_management_system_ | Remote | Injection
May 26, 2026 May 26, 2026
May 26, 2026
May 26, 2026
7.5 HIGH
CVE-2026-9551 — Das Parking Management System 停车场管理系统 API Endpoint ExportParkingRecords xp_cmdshell sql i…

A vulnerability was identified in Das Parking Management System 停车场管理系统 6.2.0. This affects the function xp_cmdshell of the file ParkingRecord/ExportParkingRecords of the component API Endpoint. The …

parking_management_system_ | Remote | Injection
May 26, 2026 May 26, 2026
May 26, 2026
May 26, 2026
7.5 HIGH
CVE-2026-9550 — Acrel Electrical EEMS Enterprise Power Operation and Maintenance Cloud Platform upfile pa…

A vulnerability was determined in Acrel Electrical EEMS Enterprise Power Operation and Maintenance Cloud Platform 1.3.0. Affected by this issue is some unknown functionality of the file /SubstationWE…

May 26, 2026 May 26, 2026
May 26, 2026
May 26, 2026
9.8 CRITICAL
CVE-2026-4480 — Samba: samba: remote code execution in printing subsystem via unescaped job description

A flaw was found in the Samba printing subsystem. Samba passes the client-controlled job description string to the command configured with the "print command" setting via the "%J" substitution charac…

May 26, 2026 Jun 04, 2026
May 26, 2026
Jun 04, 2026
8.8 HIGH
CVE-2026-46368 — luci-app-https-dns-proxy Authenticated Command Injection via setInitAction

luci-app-https-dns-proxy through 2025.12.29-5 — an optional LuCI web UI add-on for the https-dns-proxy package, distributed through the OpenWrt community packages feed and not installed by default — …

Remote | Injection
May 26, 2026 May 26, 2026
May 26, 2026
May 26, 2026
9.8 CRITICAL
CVE-2026-45247 — Mirasvit Full Page Cache Warmer Deserialization of Untrusted Data Vulnerability - [Active…

Mirasvit Full Page Cache Warmer for Magento 2 before version 1.11.12 contains a PHP object injection vulnerability that allows unauthenticated attackers to achieve remote code execution by supplying …

full_page_cache_warmer | CISA KEV Remote | Injection
May 26, 2026 Jun 03, 2026
May 26, 2026
Jun 03, 2026
7.6 HIGH
CVE-2026-45082 — Karakeep has a SSRF Protection Bypass via Redirect Handling

Karakeep is a elf-hostable bookmark-everything app. A Server-Side Request Forgery (SSRF) protection bypass vulnerability was identified in versions prior to 0.32.0 affecting redirect-following proces…

karakeep | Remote | Server-Side Request Forgery
May 26, 2026 May 26, 2026
May 26, 2026
May 26, 2026
8.6 HIGH
CVE-2026-42785 — OpenKM 6.3.12 Remote Code Execution via Administrative Scripting

OpenKM 6.3.12 contains a remote code execution vulnerability that allows authenticated administrators to execute arbitrary Java/BeanShell code through the /admin/Scripting endpoint. Attackers can sub…

openkm | Remote | Injection
May 26, 2026 May 26, 2026
May 26, 2026
May 26, 2026
Showing 20 of 6704 Results