Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.5 HIGH
CVE-2026-8098 — code-projects Feedback System checklogin.php sql injection

A security vulnerability has been detected in code-projects Feedback System 1.0. Impacted is an unknown function of the file /admin/checklogin.php. Such manipulation of the argument email leads to sq…

Remote | Injection
May 07, 2026 May 11, 2026
May 07, 2026
May 11, 2026
6.5 MEDIUM
CVE-2026-8097 — CodeAstro Online Classroom askquery.php sql injection

A security flaw has been discovered in CodeAstro Online Classroom 1.0. This vulnerability affects unknown code of the file /askquery.php. The manipulation of the argument squeryx results in sql injec…

Remote | Injection
May 07, 2026 May 11, 2026
May 07, 2026
May 11, 2026
8.5 HIGH
CVE-2026-42449 — n8n-MCP: IPv4-mapped IPv6 addresses bypass SSRF protection in validateUrlSync(), enabling…

n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. In versions 2.47.4 through 2.47.13, the SDK embedder path (N8NDocumentationMCPServer…

n8n-mcp | Remote | Server-Side Request Forgery
May 07, 2026 May 14, 2026
May 07, 2026
May 14, 2026
8.6 HIGH
CVE-2026-42047 — Inngest TypeScript SDK exposes environment variables via serve() handler on unhandled HTT…

Inngest is a platform for running event-driven and scheduled background functions with queueing, retries, and step orchestration. Versions 3.22.0 through 3.53.1 contain a vulnerability that allows un…

inngest | Remote | Information Disclosure
May 07, 2026 May 13, 2026
May 07, 2026
May 13, 2026
4.7 MEDIUM
CVE-2026-41692 — i18nextify is vulnerable to DOM XSS via javascript:/data: URL schemes in translated href/…

i18nextify is a JavaScript library that adds website internationalization via a script tag, without source code changes. Versions prior to 4.0.8 substitute {{key}} interpolation tokens inside src and…

i18nextify | Remote | Cross-Site Scripting
May 07, 2026 May 29, 2026
May 07, 2026
May 29, 2026
9.1 CRITICAL
CVE-2026-41691 — i18next-http-backend has Path Traversal & URL Injection via Unsanitised lng/ns

Copilot said: i18nextify is a JavaScript library that adds i18nextify is a JavaScript library that adds website internationalization via a script tag, without source code changes. Versions prior to 3…

i18next-http-backend | Remote | Path Traversal
May 07, 2026 May 29, 2026
May 07, 2026
May 29, 2026
Showing 20 of 7126 Results