Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.5 MEDIUM
CVE-2026-42183 — Argo Workflows: SSO RBAC Delegation Nil Pointer Dereference DoS (gatekeeper.go)

Argo Workflows is an open source container-native workflow engine for orchestrating parallel jobs on Kubernetes. From version 4.0.0 to before version 4.0.5, a nil pointer dereference in server/auth/g…

argo_workflows | Remote | Denial of Service
May 09, 2026 May 14, 2026
May 09, 2026
May 14, 2026
5.3 MEDIUM
CVE-2026-42174 — Kirby: User avatar creation, replacement and deletion are not gated by user update permis…

Kirby is an open-source content management system. Prior to versions 4.9.0 and 5.4.0, user avatar creation, replacement and deletion are not gated by user update permissions. This issue has been patc…

kirby | Remote | Authorization
May 09, 2026 May 18, 2026
May 09, 2026
May 18, 2026
7.1 HIGH
CVE-2026-42137 — Kirby: `pages.access/list` and `files.access/list` permissions are not consistently check…

Kirby is an open-source content management system. Prior to versions 4.9.0 and 5.4.0, `pages.access/list` and `files.access/list` permissions are not consistently checked in the Panel and REST API. T…

kirby | Remote | Authorization
May 09, 2026 May 18, 2026
May 09, 2026
May 18, 2026
7.1 HIGH
CVE-2026-42069 — Kirby: Read access to site, user and role information is not gated by permissions

Kirby is an open-source content management system. Prior to versions 4.9.0 and 5.4.0, read access to site, user and role information is not gated by permissions. This issue has been patched in versio…

kirby | Remote | Authorization
May 09, 2026 May 18, 2026
May 09, 2026
May 18, 2026
5.3 MEDIUM
CVE-2026-42051 — Kirby: System API endpoint leaks license data and installed version to authenticated users

Kirby is an open-source content management system. Prior to versions 4.9.0 and 5.4.0, the system API endpoint leaks license data and installed version to authenticated users. This issue has been patc…

kirby | Remote | Information Disclosure
May 09, 2026 May 18, 2026
May 09, 2026
May 18, 2026
7.5 HIGH
CVE-2026-41311 — LiquidJS is vulnerable to Denial of Service via circular block reference in layout

LiquidJS is a Shopify / GitHub Pages compatible template engine in pure JavaScript. Prior to version 10.25.7, a circular block reference in {% layout %} / {% block %} causes an infinite recursive loo…

liquidjs | Remote | Denial of Service
May 09, 2026 May 14, 2026
May 09, 2026
May 14, 2026
8.7 HIGH
CVE-2026-41163 — bubblewrap vulnerable to privilege escalation in setuid mode via ptrace

bubblewrap is a low-level unprivileged sandboxing tool. From version 0.11.0 to before version 0.11.2, if bubblewrap is installed in setuid mode then the user can use ptrace to attach to bubblewrap an…

bubblewrap | Remote | Misconfiguration
May 09, 2026 May 13, 2026
May 09, 2026
May 13, 2026
7.0 HIGH
CVE-2026-8207 — Gibbon SQL Injection Vulnerability

Gibbon versions before v30.0.01 are affected by an authenticated SQL Injection vulnerability by abusing the Tracking/graphing https://github.com/GibbonEdu/core/blob/c431e25fdc874adece5d2dc7e408e9aa2…

gibbon | Remote | Injection
May 09, 2026 May 12, 2026
May 09, 2026
May 12, 2026
5.3 MEDIUM
CVE-2026-7652 — LatePoint <= 5.5.0 - Unauthenticated Account Takeover via Weak Password Recovery Mechanism

The LatePoint plugin for WordPress is vulnerable to Account Takeover via Weak Password Recovery Mechanism in the unauthenticated guest booking flow in versions up to, and including, 5.5.0 This is due…

Remote | Authentication
May 09, 2026 May 11, 2026
May 09, 2026
May 11, 2026
Showing 20 of 6689 Results