Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.4 MEDIUM
CVE-2026-45023 — AutoGP: Credit system bypassed via direct block execution in POST /api/blocks/{block_id}/…

AutoGPT is a workflow automation platform for creating, deploying, and managing continuous artificial intelligence agents. Prior to 0.6.59, POST /api/blocks/{block_id}/execute endpoint executes block…

autogpt_platform | Remote | Authentication
May 28, 2026 May 29, 2026
May 28, 2026
May 29, 2026
8.1 HIGH
CVE-2026-44973 — Billy: Path traversal vulnerabilities

Billy is an interface filesystem abstraction for Go. Prior to 5.9.0, multiple path traversal issues exist across different components of go-billy. Insufficient path sanitization and boundary enforcem…

Remote | Path Traversal
May 28, 2026 May 29, 2026
May 28, 2026
May 29, 2026
5.5 MEDIUM
CVE-2026-44885 — Portainer: Path traversal in backup archive extraction allows arbitrary file write

Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. From 2.33.0 to before …

portainer | Remote | Path Traversal
May 28, 2026 Jun 01, 2026
May 28, 2026
Jun 01, 2026
6.5 MEDIUM
CVE-2026-44884 — Portainer: Missing authorization on custom template file endpoint exposes template content

Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. From 2.33.0 to before …

portainer | Remote | Authorization
May 28, 2026 Jun 01, 2026
May 28, 2026
Jun 01, 2026
7.7 HIGH
CVE-2026-44883 — Portainer: JWT accepted in URL query leaks tokens to logs and referers

Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. From 2.33.0 to before …

portainer | Remote | Authentication
May 28, 2026 Jun 02, 2026
May 28, 2026
Jun 02, 2026
8.1 HIGH
CVE-2026-44882 — Portainer: Kubernetes middleware continues after token validation failure, bypassing endp…

Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. From 2.33.0 to before …

portainer | Remote | Authorization
May 28, 2026 Jun 01, 2026
May 28, 2026
Jun 01, 2026
9.9 CRITICAL
CVE-2026-44881 — Portainer: Arbitrary File Read via Git Symlink Injection in Stack Auto-Update

Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. From 2.33.0 to before …

portainer | Remote | Path Traversal
May 28, 2026 Jun 01, 2026
May 28, 2026
Jun 01, 2026
8.5 HIGH
CVE-2026-44850 — Portainer: Bind-mount restriction bypass via HostConfig.Mounts

Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. From 2.33.0 to before …

portainer | Remote | Misconfiguration
May 28, 2026 Jun 01, 2026
May 28, 2026
Jun 01, 2026
9.4 CRITICAL
CVE-2026-44849 — Portainer: Endpoint security bypass via Swarm service create/update

Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. From 2.33.0 to before …

portainer | Remote | Authorization
May 28, 2026 Jun 01, 2026
May 28, 2026
Jun 01, 2026
9.4 CRITICAL
CVE-2026-44848 — Portainer: Missing authorization on Docker plugin endpoints allows host RCE

Portainer Community Edition is a lightweight service delivery platform for containerized applications that can be used to manage Docker, Swarm, Kubernetes and ACI environments. From 2.33.0 to before …

portainer | Remote | Authorization
May 28, 2026 Jun 01, 2026
May 28, 2026
Jun 01, 2026
8.7 HIGH
CVE-2026-39929 — Lakeside SysTrack Agent LsiAgent.exe Out-of-Bounds Read via UDP

Lakeside SysTrack Agent versions prior to 11.2.1.28, 11.3.0.38, 11.4.0.24, 11.5.0.15 contain an out-of-bounds read vulnerability in the Command ID 30 UDP packet handler that allows remote attackers t…

Remote | Denial of Service
May 28, 2026 Jun 01, 2026
May 28, 2026
Jun 01, 2026
8.2 HIGH
CVE-2026-10044 — ai-goofish-monitor Unauthenticated Arbitrary File Read via GET /api/prompts/

Usagi-org ai-goofish-monitor contains an unauthenticated arbitrary file read vulnerability in the GET /api/prompts/{filename} endpoint on Windows deployments that allows unauthenticated remote attack…

Remote | Path Traversal
May 28, 2026 Jun 01, 2026
May 28, 2026
Jun 01, 2026
6.1 MEDIUM
CVE-2026-9646 — ScadaBR Unauthenticated Reflected Cross-Site Scripting

A reflected cross-site scripting issue exists in URL handling.

scadabr | Remote | Cross-Site Scripting
May 28, 2026 Jun 01, 2026
May 28, 2026
Jun 01, 2026
9.9 CRITICAL
CVE-2026-9645 — ScadaBR Authenticated Remote Code Execution

Exposed methods allow authenticated users to create and execute arbitrary JavaScript code on the server. The scripts execute with full access, enabling complete system compromise as commands are exec…

scadabr | Remote | Authorization
May 28, 2026 Jun 01, 2026
May 28, 2026
Jun 01, 2026
7.2 HIGH
CVE-2026-49095 — Improper Input Validation in Kibana Fleet Leading to Privilege Escalation

Improper Input Validation (CWE-20) in the Kibana Fleet agent policy management feature can lead to privilege escalation. An authenticated user with Fleet management privileges can manipulate agent po…

kibana | Remote | Authorization
May 28, 2026 Jun 01, 2026
May 28, 2026
Jun 01, 2026
6.5 MEDIUM
CVE-2026-49094 — Uncontrolled Resource Consumption in Kibana Leading to Denial of Service

Uncontrolled Resource Consumption (CWE-400) in Kibana can lead to denial of service via Excessive Allocation (CAPEC-130). An authenticated user with viewer-level access can submit a request containin…

kibana | Remote | Denial of Service
May 28, 2026 Jun 01, 2026
May 28, 2026
Jun 01, 2026
7.7 HIGH
CVE-2026-49093 — Server-Side Request Forgery (SSRF) in Kibana Leading to Unauthorized Network Access

Server-Side Request Forgery (CWE-918) in Kibana can allow an authenticated user with connector management privileges to bypass the operator-configured connector allowlist, causing the Kibana server t…

kibana | Remote | Server-Side Request Forgery
May 28, 2026 Jun 01, 2026
May 28, 2026
Jun 01, 2026
5.3 MEDIUM

Vulnerability in Oracle REST Data Services (component: Core). Supported versions that are affected are 24.2.0-26.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network ac…

May 28, 2026 Jun 03, 2026
May 28, 2026
Jun 03, 2026
5.3 MEDIUM

Vulnerability in Oracle REST Data Services (component: Core). Supported versions that are affected are 24.2.0-26.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network ac…

May 28, 2026 Jun 03, 2026
May 28, 2026
Jun 03, 2026
5.3 MEDIUM

Vulnerability in Oracle REST Data Services (component: General). Supported versions that are affected are 24.2.0-26.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network…

May 28, 2026 Jun 04, 2026
May 28, 2026
Jun 04, 2026
Showing 20 of 7162 Results