Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.1 CRITICAL
CVE-2026-41258 — OpenMRS: Stored Velocity SSTI to RCE via ConceptReferenceRange

OpenMRS is an open source electronic medical record system platform. From 2.7.0 to before 2.7.9 and 2.8.6, the ConceptReferenceRangeUtility.evaluateCriteria() method in OpenMRS Core evaluates databas…

Remote | Injection
May 15, 2026 May 18, 2026
May 15, 2026
May 18, 2026
6.9 MEDIUM
CVE-2026-41181 — Traefik: Errors middleware forwards Authorization and Cookie headers to separate error pa…

Traefik is an HTTP reverse proxy and load balancer. Prior to 2.11.44, 3.6.15, and 3.7.0-rc.3, there is an information disclosure vulnerability in Traefik's errors (custom error pages) middleware. Whe…

traefik | Remote | Information Disclosure
May 15, 2026 May 19, 2026
May 15, 2026
May 19, 2026
5.4 MEDIUM
CVE-2026-23695 — Cockpit CMS 2.14.0 Stored XSS via Set Field Display Template

Cockpit CMS through version 2.14.0, patched in commit 72a83fc, contains a stored cross-site scripting vulnerability in the Set field type's Display template option, where the template string is proce…

cockpit | Remote | Cross-Site Scripting
May 15, 2026 May 18, 2026
May 15, 2026
May 18, 2026
8.4 HIGH
CVE-2026-46508 — Turborepo: VSCode Extension command injection

Turborepo is a high-performance build system for JavaScript and TypeScript codebases. Prior to 2.9.14000, the Turborepo LSP VS Code extension could execute shell commands derived from workspace-contr…

May 15, 2026 May 19, 2026
May 15, 2026
May 19, 2026
3.5 LOW
CVE-2026-45803 — gh: GitHub Actions log output in `gh run view` allows terminal escape sequence injection

`gh` is GitHub’s official command line tool. From 1.6.0 to before 2.92.0, a security vulnerability has been identified in GitHub CLI that could allow terminal escape sequence injection when users vie…

cli | Remote | Information Disclosure
May 15, 2026 May 21, 2026
May 15, 2026
May 21, 2026
6.5 MEDIUM
CVE-2026-45773 — Turborepo: Login callback CSRF/session fixation

Turborepo is a high-performance build system for JavaScript and TypeScript codebases. Prior to 2.9.14, Turborepo's self-hosted login and SSO browser flows did not validate a CSRF state value on the l…

turborepo turborepo_language_server_protocol | Remote | Cross-Site Request Forgery
May 15, 2026 May 19, 2026
May 15, 2026
May 19, 2026
9.8 CRITICAL
CVE-2026-45772 — Turborepo: Unexpected local code execution during Yarn Berry detection

Turborepo is a high-performance build system for JavaScript and TypeScript codebases. From 1.1.0 to before 2.9.14, Turborepo can be vulnerable to arbitrary code execution when run in untrusted reposi…

May 15, 2026 May 19, 2026
May 15, 2026
May 19, 2026
8.1 HIGH
CVE-2026-35194 — Apache Flink: Remote code execution via SQL injection in code generation

Code injection in SQL code generation in Apache Flink 1.15.0 through 1.20.x and 2.0.0 through 2.x allows authenticated users with query submission privileges to execute arbitrary code on TaskManagers…

flink | Remote | Injection
May 15, 2026 May 18, 2026
May 15, 2026
May 18, 2026
10.0 CRITICAL
CVE-2026-2031 — Google Cloud Application Integration: Exposed internal APIs allow Information Disclosure …

An Improper Access Control vulnerability in several internal API endpoints for Google Cloud Application Integration prior to 2026-01-23 allows a remote, unauthenticated attacker to disclose sensitive…

Remote | Authorization
May 15, 2026 May 18, 2026
May 15, 2026
May 18, 2026
6.5 MEDIUM
CVE-2026-8669 — Imager versions through 1.030 for Perl allow a heap out of bounds (OOB) write on crafted …

Imager versions through 1.030 for Perl allow a heap out of bounds (OOB) write on crafted multi-frame GIF files. Imager::File::GIF's i_readgif_multi_low allocates a single per-row buffer GifRow sized…

imager | Remote | Memory Corruption
May 15, 2026 May 18, 2026
May 15, 2026
May 18, 2026
7.0 HIGH
CVE-2026-46483 — Vim: Command injection in tar#Vimuntar via missing shellescape {special} flag

Vim is an open source, command line text editor. Prior to 9.2.0479, a command injection vulnerability exists in tar#Vimuntar() in runtime/autoload/tar.vim when decompressing .tgz archives on Unix-lik…

vim | Injection
May 15, 2026 May 19, 2026
May 15, 2026
May 19, 2026
7.5 HIGH
CVE-2026-45736 — ws: Uninitialized memory disclosure

ws is an open source WebSocket client and server for Node.js. Prior to 8.20.1, the websocket.close() implementation is vulnerable to uninitialized memory disclosure when a TypedArray is passed as the…

ws | Remote | Memory Corruption
May 15, 2026 May 19, 2026
May 15, 2026
May 19, 2026
7.3 HIGH
CVE-2026-39054 — Pamirs Oinone Command Injection Vulnerability

Oinone Pamirs 7.0.0 contains a command injection vulnerability in CommandHelper.executeCommands. The method starts a shell process and writes attacker-controlled command strings directly to the proce…

Remote | Injection
May 15, 2026 May 18, 2026
May 15, 2026
May 18, 2026
6.5 MEDIUM
CVE-2026-39053 — Pamirs Oinone XXE File Disclosure/SSRF Vulnerability

Oinone Pamirs 7.0.0 contains an XML External Entity (XXE) issue in its XStream-based XML parsing logic. When attacker-controlled XML is passed to framework parsing entry points such as PamirsXmlUtils…

Remote | XML External Entity
May 15, 2026 May 18, 2026
May 15, 2026
May 18, 2026
6.5 MEDIUM
CVE-2026-39052 — Pamirs Oinone ScriptRunner Code Execution Vulnerability

Oinone Pamirs 7.0.0 contains a code execution vulnerability via ScriptRunner. The method ScriptRunner.run(String expression, String type, Map<String, Object> context) evaluates attacker-controlled sc…

Remote | Injection
May 15, 2026 May 18, 2026
May 15, 2026
May 18, 2026
7.5 HIGH
CVE-2026-38728 — Nodemailer SMTP Denial of Service Vulnerability

An issue in Nodemailer smtp_server before v.3.18.3 allows a remote attacker to cause a denial of service via the SMTPStream._write, lib/smtp-stream.js components

Remote | Denial of Service
May 15, 2026 May 18, 2026
May 15, 2026
May 18, 2026
8.2 HIGH
CVE-2026-34253 — Vorbis-tools Ogg123 Buffer Underflow Vulnerability

A buffer underflow vulnerability has been identified in the ogg123 utility from the vorbis-tools 1.4.3 package in function remotethread in remote.c. This vulnerability occurs in the remote control fu…

Remote | Memory Corruption
May 15, 2026 May 18, 2026
May 15, 2026
May 18, 2026
6.5 MEDIUM
CVE-2025-67437 — MedicarePlus Password Reset Privilege Escalation

Medical Management System a81df1ce700a9662cb136b27af47f4cbde64156b is vulnerable to Insecure Permissions, which allows arbitrary user password reset.

Remote | Authentication
May 15, 2026 May 18, 2026
May 15, 2026
May 18, 2026
4.1 MEDIUM
CVE-2025-14972 — Insufficient DPA countermeasure reseeding

* Countermeasures for DPA within SYMCRYPTO engine on SixG301xxx devices are not sufficiently random and will eventually repeat. * KSU keys using SYMCRYPTO will be impacted by this vulnerability.

May 15, 2026 May 18, 2026
May 15, 2026
May 18, 2026
7.1 HIGH
CVE-2026-46333 — ptrace: slightly saner 'get_dumpable()' logic

In the Linux kernel, the following vulnerability has been resolved: ptrace: slightly saner 'get_dumpable()' logic The 'dumpability' of a task is fundamentally about the memory image of the task - t…

linux_kernel | Authorization
May 15, 2026 May 22, 2026
May 15, 2026
May 22, 2026
Showing 20 of 7120 Results