Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.3 MEDIUM
CVE-2026-38740 — Foscam VD1 Cleartext SDP Transmission Vulnerability

Foscam VD1 Video Doorbell before V5.3.13_1072 is vulnerable to Cleartext Transmission of Sensitive Information. The device transmits sensitive Session Description Protocol (SDP), including ICE creden…

Remote | Information Disclosure
May 14, 2026 May 15, 2026
May 14, 2026
May 15, 2026
9.2 CRITICAL
CVE-2026-27886 — Strapi may leak sensitive data via relational filtering due to lack of query sanitization

Strapi is an open source headless content management system. Strapi versions starting in 4.0.0 and prior to 5.37.0 did not sufficiently sanitize query parameters when filtering content via relational…

strapi | Remote | Injection
May 14, 2026 May 16, 2026
May 14, 2026
May 16, 2026
4.3 MEDIUM
CVE-2026-27680 — CSS Injection vulnerability in SAP NetWeaver Application Server ABAP

Due to improper input handling under certain conditions, SAP NetWeaver Application Server ABAP allows an attacker to inject custom Cascading Style Sheets (CSS) data into a web page served by the appl…

netweaver_application_server_abap | Remote | Cross-Site Scripting
May 14, 2026 Jun 03, 2026
May 14, 2026
Jun 03, 2026
8.2 HIGH
CVE-2026-23998 — Fleet has a Windows MDM management endpoint authentication bypass

Fleet is open source device management software. Prior to version 4.81.0, a vulnerability in Fleet’s Windows MDM management endpoint could allow requests to be processed without proper client certifi…

fleet | Remote | Authentication
May 14, 2026 May 15, 2026
May 14, 2026
May 15, 2026
5.4 MEDIUM
CVE-2026-22707 — Strapi Upload Plugin MIME Validation Bypass via Content API

Strapi is an open source headless content management system. In Strapi versions prior to 5.33.3, the Upload plugin's Content API endpoints did not enforce the administrator-configured MIME type restr…

strapi | Remote | Misconfiguration
May 14, 2026 May 16, 2026
May 14, 2026
May 16, 2026
6.5 MEDIUM
CVE-2026-22706 — Strapi: Password Reset Does Not Revoke Existing Refresh Sessions

Strapi is an open source headless content management system. In Strapi versions prior to 5.33.3, changing or resetting a user's password did not invalidate the user's existing refresh-token sessions …

strapi | Remote | Authentication
May 14, 2026 May 16, 2026
May 14, 2026
May 16, 2026
9.3 CRITICAL
CVE-2026-22599 — Strapi Vulnerable to SQL Injection in Content Type Builder

Strapi is an open source headless content management system. In versions on the 4.x branch prior to 4.26.1 and on the 5.x branch prior to 5.33.2, a database-query injection vulnerability existed in t…

strapi | Remote | Injection
May 14, 2026 May 16, 2026
May 14, 2026
May 16, 2026
6.9 MEDIUM
CVE-2025-64526 — Strapi has a rate limit bypass on users-permissions plugin via attacker-controlled email …

Strapi is an open source headless content management system. In Strapi versions prior to 5.45.0, the rate-limit middleware in the users-permissions plugin derived its rate-limit key in part from `ctx…

strapi | Remote | Authentication
May 14, 2026 May 16, 2026
May 14, 2026
May 16, 2026
7.5 HIGH
CVE-2026-6332 — Clear Text Storage of Sensitive Information on EcoStruxure™ Machine Expert HVAC

CWE-312: Cleartext Storage of Sensitive Information vulnerability exists that could cause the disclosure of a sensitive information which could result in revealing protected source code and loss of …

ecostruxure_machine_expert_hvac | Remote | Information Disclosure
May 14, 2026 May 27, 2026
May 14, 2026
May 27, 2026
9.1 CRITICAL
CVE-2026-46470 — GStreamer gst-plugins-good Integer Division by Zero Denial of Service

An issue was discovered in GStreamer gst-plugins-good before 1.28.2. When parsing MP4 audio tracks, the isomp4 plugin's qtdemux_audio_caps function does not sufficiently validate atom data before per…

good_plug-ins gst-plugins-good | Remote | Denial of Service
May 14, 2026 May 19, 2026
May 14, 2026
May 19, 2026
5.5 MEDIUM
CVE-2026-46469 — GStreamer gst-plugins-good Integer Division by Zero Denial of Service

An issue was discovered in GStreamer gst-plugins-good before 1.28.2. When parsing MP4 audio tracks, the isomp4 plugin's qtdemux_parse_trak function does not sufficiently validate atom data before per…

good_plug-ins gst-plugins-good | Denial of Service
May 14, 2026 May 19, 2026
May 14, 2026
May 19, 2026
4.9 MEDIUM
CVE-2026-44544 — gittuf: Policy can be rolled back to prior valid version

gittuf is a platform-agnostic Git security system. Prior to 0.14.0, an attacker with push access to gittuf's Reference State Log (RSL) can roll back the current policy to any previous policy trusted …

Remote | Authorization
May 14, 2026 May 14, 2026
May 14, 2026
May 14, 2026
9.1 CRITICAL
CVE-2026-44542 — FileBrowser Quantum: Unauthenticated Path Traversal in Public Share Delete Allows Arbitra…

FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to 1.3.1-stable and 1.3.9-beta, attacker-controlled path input is joined with a trusted base path prior to sanitization, allo…

filebrowser_quantum | Remote | Path Traversal
May 14, 2026 May 15, 2026
May 14, 2026
May 15, 2026
5.7 MEDIUM
CVE-2026-44520 — Docling-Graph: SSRF via Missing Internal IP Validation in URLInputHandler

Docling-Graph turns documents into validated Pydantic objects, then builds a directed knowledge graph with explicit semantic relationships. Prior to 1.5.1, the URLInputHandler class in docling_graph/…

Remote | Server-Side Request Forgery
May 14, 2026 May 14, 2026
May 14, 2026
May 14, 2026
4.3 MEDIUM
CVE-2026-44283 — etcd: Read access via PrevKv in etcd transactions may bypass RBAC authorization checks

etcd is a distributed key-value store for the data of a distributed system. Prior to 3.4.44, 3.5.30, and 3.6.11, a vulnerability in etcd allows read access via PrevKv, or lease attachment in Put requ…

etcd | Remote | Authorization
May 14, 2026 May 15, 2026
May 14, 2026
May 15, 2026
8.1 HIGH
CVE-2026-42897 — Microsoft Exchange Server Cross-Site Scripting Vulnerability - [Actively Exploited]

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

May 14, 2026 May 15, 2026
May 14, 2026
May 15, 2026
6.9 MEDIUM
CVE-2026-42598 — Pode: Directory Traversal is possible on Static Routes

Pode is a Cross-Platform PowerShell web framework for creating REST APIs, Web Sites, and TCP/SMTP servers. From 2.4.0, to before 2.13.0, when requesting content from a Static Route, it was possible t…

Remote | Path Traversal
May 14, 2026 May 14, 2026
May 14, 2026
May 14, 2026
6.5 MEDIUM
CVE-2026-42572 — Hatchet: Cross-tenant information disclosure in `listTasksByDAGIds`

Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. Prior to 0.83.39, a missing authorization directive on the GET /api/v1/stable/dags/tasks endpoint …

hatchet | Remote | Authorization
May 14, 2026 May 27, 2026
May 14, 2026
May 27, 2026
7.5 HIGH
CVE-2026-42334 — Mongoose: Improper Sanitization of $nor in sanitizeFilter May Allow NoSQL Injection

Mongoose is a MongoDB object modeling tool designed to work in an asynchronous environment. Prior to 6.13.9, 7.8.9, 8.22.1, and 9.1.6, a vulnerability allows bypassing Mongoose’s sanitizeFilter query…

mongoose | Remote | Injection
May 14, 2026 May 15, 2026
May 14, 2026
May 15, 2026
6.5 MEDIUM
CVE-2026-41888 — Distribution: Tag deletion bypasses `storage.delete.enabled` configuration

Distribution is a toolkit to pack, ship, store, and deliver container content. Prior to 3.1.1, tag deletion via the DELETE /v2/<name>/manifests/<tag> endpoint bypasses the storage.delete.enabled: fal…

distribution | Remote | Misconfiguration
May 14, 2026 May 15, 2026
May 14, 2026
May 15, 2026
Showing 20 of 7216 Results