Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.5 HIGH
CVE-2026-40029 — parseusbs < 1.9 Command Injection via Crafted LNK Filename

parseusbs before 1.9 contains an OS command injection vulnerability in parseUSBs.py where LNK file paths are passed unsanitized into an os.popen() shell command, allowing arbitrary command execution …

parseusbs | Injection
Apr 08, 2026 Apr 13, 2026
Apr 08, 2026
Apr 13, 2026
5.4 MEDIUM
CVE-2026-40028 — Hayabusa < 3.8.0 XSS via JSON Log Import

Hayabusa versions prior to 3.8.0 contain a cross-site scripting (XSS) vulnerability in its HTML report output that allows an attacker to execute arbitrary JavaScript when a user scans JSON-exported l…

hayabusa | Remote | Cross-Site Scripting
Apr 08, 2026 Apr 17, 2026
Apr 08, 2026
Apr 17, 2026
8.4 HIGH
CVE-2026-40027 — ALEAPP NQ Vault Artifact Parser Path Traversal

ALEAPP (Android Logs Events And Protobuf Parser) through 3.4.0 contains a path traversal vulnerability in the NQ_Vault.py artifact parser that uses attacker-controlled file_name_from values from a da…

| Path Traversal
Apr 08, 2026 Apr 13, 2026
Apr 08, 2026
Apr 13, 2026
7.1 HIGH
CVE-2026-40026 — Sleuth Kit ISO9660 SUSP Extension Reference Out-of-Bounds Read

The Sleuth Kit through 4.14.0 contains an out-of-bounds read vulnerability in the ISO9660 filesystem parser where the parse_susp() function trusts len_id, len_des, and len_src fields from the disk im…

the_sleuth_kit | Memory Corruption
Apr 08, 2026 Apr 17, 2026
Apr 08, 2026
Apr 17, 2026
6.1 MEDIUM
CVE-2026-40025 — Sleuth Kit APFS Keybag Parser Out-of-Bounds Read

The Sleuth Kit through 4.14.0 contains an out-of-bounds read vulnerability in the APFS filesystem keybag parser where the wrapped_key_parser class follows attacker-controlled length fields without bo…

the_sleuth_kit | Memory Corruption
Apr 08, 2026 Apr 15, 2026
Apr 08, 2026
Apr 15, 2026
8.4 HIGH
CVE-2026-40024 — Sleuth Kit tsk_recover Path Traversal

The Sleuth Kit through 4.14.0 contains a path traversal vulnerability in tsk_recover that allows an attacker to write files to arbitrary locations outside the intended recovery directory via crafted …

the_sleuth_kit | Path Traversal
Apr 08, 2026 Apr 15, 2026
Apr 08, 2026
Apr 15, 2026
5.7 MEDIUM
CVE-2026-39901 — monetr: Protected Transactions Deletable via PUT

monetr is a budgeting application focused on planning for recurring expenses. Prior to 1.12.3, a transaction integrity flaw allows an authenticated tenant user to soft-delete synced non-manual transa…

Remote | Authorization
Apr 08, 2026 Apr 16, 2026
Apr 08, 2026
Apr 16, 2026
7.5 HIGH
CVE-2026-5805 — code-projects Easy Blog Site contact_us.php sql injection

A weakness has been identified in code-projects Easy Blog Site up to 1.0. The impacted element is an unknown function of the file /users/contact_us.php. Executing a manipulation of the argument Name …

Remote | Injection
Apr 08, 2026 Apr 08, 2026
Apr 08, 2026
Apr 08, 2026
6.5 MEDIUM
CVE-2026-5803 — bigsk1 openai-realtime-ui API Proxy Endpoint server.js server-side request forgery

A security flaw has been discovered in bigsk1 openai-realtime-ui up to 188ccde27fdf3d8fab8da81f3893468f53b2797c. The affected element is an unknown function of the file server.js of the component API…

Remote | Server-Side Request Forgery
Apr 08, 2026 Apr 08, 2026
Apr 08, 2026
Apr 08, 2026
6.4 MEDIUM
CVE-2026-5451 — Extensions for Leaflet Map <= 4.14 - Authenticated (Contributor+) Stored Cross-Site Scrip…

The Extensions for Leaflet Map plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'elevation-track' shortcode in all versions up to, and including, 4.14. This is due to insuffi…

extensions_for_leaflet_map | Remote | Cross-Site Scripting
Apr 08, 2026 Apr 08, 2026
Apr 08, 2026
Apr 08, 2026
8.1 HIGH
CVE-2026-5436 — MW WP Form <= 5.1.1 - Unauthenticated Arbitrary File Move via regenerate_upload_file_keys

The MW WP Form plugin for WordPress is vulnerable to Arbitrary File Move/Read in all versions up to and including 5.1.1. This is due to insufficient validation of the $name parameter (upload field ke…

mw_wp_form | Remote | Path Traversal
Apr 08, 2026 Apr 08, 2026
Apr 08, 2026
Apr 08, 2026
9.8 CRITICAL
CVE-2026-39892 — cryptography has a buffer overflow if non-contiguous buffers were passed to APIs

cryptography is a package designed to expose cryptographic primitives and recipes to Python developers. From 45.0.0 to before 46.0.7, if a non-contiguous buffer was passed to APIs which accepted Pyth…

cryptography | Remote | Memory Corruption
Apr 08, 2026 Apr 15, 2026
Apr 08, 2026
Apr 15, 2026
8.8 HIGH
CVE-2026-39891 — PraisonAI has a Template Injection in Agent Tool Definitions

PraisonAI is a multi-agent teams system. Prior to 4.5.115, the create_agent_centric_tools() function returns tools (like acp_create_file) that process file content using template rendering. When user…

praisonai praisonaiagents | Remote | Injection
Apr 08, 2026 Apr 09, 2026
Apr 08, 2026
Apr 09, 2026
9.8 CRITICAL
CVE-2026-39890 — PraisonAI Affected by Remote Code Execution via YAML Deserialization in Agent Definition …

PraisonAI is a multi-agent teams system. Prior to 4.5.115, the AgentService.loadAgentFromFile method uses the js-yaml library to parse YAML files without disabling dangerous tags (such as !!js/functi…

praisonai praisonaiagents | Remote | Injection
Apr 08, 2026 Apr 15, 2026
Apr 08, 2026
Apr 15, 2026
7.5 HIGH
CVE-2026-39889 — PraisonAI has Unauthenticated SSE Event Stream Exposes All Agent Activity in A2U Server

PraisonAI is a multi-agent teams system. Prior to 4.5.115, the A2U (Agent-to-User) event stream server in PraisonAI exposes all agent activity without authentication. The create_a2u_routes() function…

praisonai praisonaiagents | Remote | Authentication
Apr 08, 2026 Apr 15, 2026
Apr 08, 2026
Apr 15, 2026
9.9 CRITICAL
CVE-2026-39888 — PraisonAIAgents has a sandbox escape via exception frame traversal in `execute_code` (sub…

PraisonAI is a multi-agent teams system. Prior to 1.5.115, execute_code() in praisonaiagents.tools.python_tools defaults to sandbox_mode="sandbox", which runs user code in a subprocess wrapped with a…

praisonai praisonaiagents | Remote | Injection
Apr 08, 2026 Apr 15, 2026
Apr 08, 2026
Apr 15, 2026
7.5 HIGH
CVE-2026-39885 — FrontMCP Affected by SSRF via $ref Dereferencing in Untrusted OpenAPI Specifications

FrontMCP is a TypeScript-first framework for the Model Context Protocol (MCP). Prior to 2.3.0, the mcp-from-openapi library uses @apidevtools/json-schema-ref-parser to dereference $ref pointers in Op…

\@frontmcp\/adapters \@frontmcp\/sdk frontmcp mcp-from-openapi | Remote | Server-Side Request Forgery
Apr 08, 2026 Apr 15, 2026
Apr 08, 2026
Apr 15, 2026
7.3 HIGH
CVE-2026-39883 — OpenTelemetry-Go has an incomplete fix for CVE-2026-24051: BSD kenv command not using abs…

OpenTelemetry-Go is the Go implementation of OpenTelemetry. From 1.15.0 to 1.42.0, the fix for CVE-2026-24051 changed the Darwin ioreg command to use an absolute path but left the BSD kenv command us…

opentelemetry opentelemetry-go | Misconfiguration
Apr 08, 2026 Apr 10, 2026
Apr 08, 2026
Apr 10, 2026
5.3 MEDIUM
CVE-2026-39882 — OpenTelemetry-Go OTLP HTTP exporters read unbounded HTTP response bodies

OpenTelemetry-Go is the Go implementation of OpenTelemetry. Prior to 1.43.0, the otlp HTTP exporters (traces/metrics/logs) read the full HTTP response body into an in-memory bytes.Buffer without a si…

opentelemetry opentelemetry-go | Denial of Service
Apr 08, 2026 Apr 09, 2026
Apr 08, 2026
Apr 09, 2026
5.0 MEDIUM
CVE-2026-39881 — Vim Ex command injection in Vims NetBeans integration

Vim is an open source, command line text editor. Prior to 9.2.0316, a command injection vulnerability in Vim's netbeans interface allows a malicious netbeans server to execute arbitrary Ex commands w…

vim | Injection
Apr 08, 2026 Apr 08, 2026
Apr 08, 2026
Apr 08, 2026
Showing 20 of 6333 Results