Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.8 MEDIUM
CVE-2026-45246 — Summarize < 0.15.1 Insecure File Permissions Information Disclosure

Summarize prior to 0.15.1 contains an insecure file permission vulnerability in the refresh-free configuration rewrite path that allows local users to read sensitive credentials by exploiting default…

summarize | Misconfiguration
May 18, 2026 May 19, 2026
May 18, 2026
May 19, 2026
7.4 HIGH
CVE-2026-45245 — Summarize < 0.15.1 Unauthorized Daemon Request via Untrusted Events

Summarize prior to 0.15.1 contains a vulnerability in the hover summary feature that allows malicious pages to dispatch synthetic mouseover events over attacker-controlled links, causing the extensio…

summarize | Remote | Server-Side Request Forgery
May 18, 2026 May 19, 2026
May 18, 2026
May 19, 2026
5.4 MEDIUM
CVE-2026-45244 — Summarize < 0.15.1 Unapproved Browser Automation Execution

Summarize prior to 0.15.1 contains a missing authorization vulnerability that allows attackers to execute browser automation actions without per-call user approval when the extension automation featu…

summarize | Remote | Authorization
May 18, 2026 May 19, 2026
May 18, 2026
May 19, 2026
4.6 MEDIUM
CVE-2026-21789 — HCL Connections is vulnerable to broken access control

HCL Connections contains a broken access control vulnerability that may allow unauthorized user to update data in certain scenarios.

Remote | Authorization
May 18, 2026 May 18, 2026
May 18, 2026
May 18, 2026
6.1 MEDIUM
CVE-2025-65954 — SimpleSAMLphp-casserver has an Open Redirect vulnerability via logout

SimpleSAMLphp-casserver is a CAS 1.0 and 2.0 compliant CAS server in the form of a SimpleSAMLphp module. In versions below 6.3.1 and 7.0.0, the logout endpoint accepts a url query parameter to redire…

May 18, 2026 May 27, 2026
May 18, 2026
May 27, 2026
10.0 HIGH
CVE-2026-8836 — lwIP snmpv3 USM snmp_msg.c snmp_parse_inbound_frame stack-based overflow

A vulnerability was found in lwIP up to 2.2.1. Affected is the function snmp_parse_inbound_frame of the file src/apps/snmp/snmp_msg.c of the component snmpv3 USM Handler. Performing a manipulation of…

lwip | Remote | Memory Corruption
May 18, 2026 May 18, 2026
May 18, 2026
May 18, 2026
6.1 MEDIUM
CVE-2026-45243 — Summarize < 0.15.1 Browser Extension Missing Authorization via Content Script

Summarize prior to 0.15.1 contains a missing authorization vulnerability in the content script window.postMessage bridge that allows malicious pages to perform unauthorized operations on automation a…

summarize | Remote | Authorization
May 18, 2026 May 19, 2026
May 18, 2026
May 19, 2026
7.1 HIGH
CVE-2026-45242 — Summarize < 0.15.1 Path Traversal via slidesDir Parameter

Summarize prior to 0.15.1 contains a path traversal vulnerability in the /v1/summarize daemon endpoint that allows authenticated callers to write files to arbitrary directories by supplying an absolu…

summarize | Remote | Path Traversal
May 18, 2026 May 19, 2026
May 18, 2026
May 19, 2026
6.1 MEDIUM
CVE-2026-45231 — DumbAssets 1.0.11 Stored Cross-Site Scripting via Asset Fields

DumbAssets through 1.0.11 contains a stored cross-site scripting vulnerability in asset fields including name, description, modelNumber, serialNumber, and tags that are stored without server-side san…

Remote | Cross-Site Scripting
May 18, 2026 May 18, 2026
May 18, 2026
May 18, 2026
Showing 20 of 7609 Results