Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.5 HIGH
CVE-2026-6332 — Clear Text Storage of Sensitive Information on EcoStruxure™ Machine Expert HVAC

CWE-312: Cleartext Storage of Sensitive Information vulnerability exists that could cause the disclosure of a sensitive information which could result in revealing protected source code and loss of …

ecostruxure_machine_expert_hvac | Remote | Information Disclosure
May 14, 2026 May 27, 2026
May 14, 2026
May 27, 2026
9.1 CRITICAL
CVE-2026-46470 — GStreamer gst-plugins-good Integer Division by Zero Denial of Service

An issue was discovered in GStreamer gst-plugins-good before 1.28.2. When parsing MP4 audio tracks, the isomp4 plugin's qtdemux_audio_caps function does not sufficiently validate atom data before per…

good_plug-ins gst-plugins-good | Remote | Denial of Service
May 14, 2026 May 19, 2026
May 14, 2026
May 19, 2026
5.5 MEDIUM
CVE-2026-46469 — GStreamer gst-plugins-good Integer Division by Zero Denial of Service

An issue was discovered in GStreamer gst-plugins-good before 1.28.2. When parsing MP4 audio tracks, the isomp4 plugin's qtdemux_parse_trak function does not sufficiently validate atom data before per…

good_plug-ins gst-plugins-good | Denial of Service
May 14, 2026 May 19, 2026
May 14, 2026
May 19, 2026
4.9 MEDIUM
CVE-2026-44544 — gittuf: Policy can be rolled back to prior valid version

gittuf is a platform-agnostic Git security system. Prior to 0.14.0, an attacker with push access to gittuf's Reference State Log (RSL) can roll back the current policy to any previous policy trusted …

Remote | Authorization
May 14, 2026 May 14, 2026
May 14, 2026
May 14, 2026
9.1 CRITICAL
CVE-2026-44542 — FileBrowser Quantum: Unauthenticated Path Traversal in Public Share Delete Allows Arbitra…

FileBrowser Quantum is a free, self-hosted, web-based file manager. Prior to 1.3.1-stable and 1.3.9-beta, attacker-controlled path input is joined with a trusted base path prior to sanitization, allo…

filebrowser_quantum | Remote | Path Traversal
May 14, 2026 May 15, 2026
May 14, 2026
May 15, 2026
5.7 MEDIUM
CVE-2026-44520 — Docling-Graph: SSRF via Missing Internal IP Validation in URLInputHandler

Docling-Graph turns documents into validated Pydantic objects, then builds a directed knowledge graph with explicit semantic relationships. Prior to 1.5.1, the URLInputHandler class in docling_graph/…

Remote | Server-Side Request Forgery
May 14, 2026 May 14, 2026
May 14, 2026
May 14, 2026
4.3 MEDIUM
CVE-2026-44283 — etcd: Read access via PrevKv in etcd transactions may bypass RBAC authorization checks

etcd is a distributed key-value store for the data of a distributed system. Prior to 3.4.44, 3.5.30, and 3.6.11, a vulnerability in etcd allows read access via PrevKv, or lease attachment in Put requ…

etcd | Remote | Authorization
May 14, 2026 May 15, 2026
May 14, 2026
May 15, 2026
8.1 HIGH
CVE-2026-42897 — Microsoft Exchange Server Cross-Site Scripting Vulnerability - [Actively Exploited]

Improper neutralization of input during web page generation ('cross-site scripting') in Microsoft Exchange Server allows an unauthorized attacker to perform spoofing over a network.

May 14, 2026 May 15, 2026
May 14, 2026
May 15, 2026
6.9 MEDIUM
CVE-2026-42598 — Pode: Directory Traversal is possible on Static Routes

Pode is a Cross-Platform PowerShell web framework for creating REST APIs, Web Sites, and TCP/SMTP servers. From 2.4.0, to before 2.13.0, when requesting content from a Static Route, it was possible t…

Remote | Path Traversal
May 14, 2026 May 14, 2026
May 14, 2026
May 14, 2026
6.5 MEDIUM
CVE-2026-42572 — Hatchet: Cross-tenant information disclosure in `listTasksByDAGIds`

Hatchet is a platform for orchestrating background tasks, AI agents, and durable workflows at scale. Prior to 0.83.39, a missing authorization directive on the GET /api/v1/stable/dags/tasks endpoint …

hatchet | Remote | Authorization
May 14, 2026 May 27, 2026
May 14, 2026
May 27, 2026
7.5 HIGH
CVE-2026-42334 — Mongoose: Improper Sanitization of $nor in sanitizeFilter May Allow NoSQL Injection

Mongoose is a MongoDB object modeling tool designed to work in an asynchronous environment. Prior to 6.13.9, 7.8.9, 8.22.1, and 9.1.6, a vulnerability allows bypassing Mongoose’s sanitizeFilter query…

mongoose | Remote | Injection
May 14, 2026 May 15, 2026
May 14, 2026
May 15, 2026
6.5 MEDIUM
CVE-2026-41888 — Distribution: Tag deletion bypasses `storage.delete.enabled` configuration

Distribution is a toolkit to pack, ship, store, and deliver container content. Prior to 3.1.1, tag deletion via the DELETE /v2/<name>/manifests/<tag> endpoint bypasses the storage.delete.enabled: fal…

distribution | Remote | Misconfiguration
May 14, 2026 May 15, 2026
May 14, 2026
May 15, 2026
9.6 CRITICAL
CVE-2026-41615 — Microsoft Authenticator Information Disclosure Vulnerability

Exposure of sensitive information to an unauthorized actor in Microsoft Authenticator allows an unauthorized attacker to disclose information over a network.

May 14, 2026 May 15, 2026
May 14, 2026
May 15, 2026
8.8 HIGH
CVE-2025-15024 — RCE in Yordam Informatics' Library Automation System

Improper Control of Generation of Code ('Code Injection') vulnerability in Yordam Information Technology Consulting, Training and Electronic Systems Industry and Trade Inc. Library Automation System …

Remote | Injection
May 14, 2026 May 14, 2026
May 14, 2026
May 14, 2026
8.8 HIGH
CVE-2025-15023 — Improper Access Control in Yordam Informatics' Library Automation System

Incorrect Authorization vulnerability in Yordam Information Technology Consulting, Training and Electronic Systems Industry and Trade Inc. Library Automation System allows Exploiting Incorrectly Conf…

Remote | Authorization
May 14, 2026 May 14, 2026
May 14, 2026
May 14, 2026
3.8 LOW
CVE-2026-6923 — Nuvoton - CWE-1300: Improper Protection of Physical Side Channels

A side-channel attack, which requires a physical presence to the TPM, can lead to extraction of an Elliptic Curve Diffie-Hellman (ECDH) key.

| Cryptography
May 14, 2026 May 14, 2026
May 14, 2026
May 14, 2026
4.3 MEDIUM
CVE-2026-45448 — ntopng - CWE-601: URL Redirection to Untrusted Site ('Open Redirect')

CWE-601 URL redirection to untrusted site ('open redirect')

ntopng | Remote | Misconfiguration
May 14, 2026 May 14, 2026
May 14, 2026
May 14, 2026
8.8 HIGH
CVE-2026-44827 — Diffusers: None.py Trust Remote Code Bypass

Diffusers is the a library for pretrained diffusion models. Prior to 0.38.0, diffusers 0.37.0 allows remote code execution without the trust_remote_code=True safeguard when loading pipelines from Hu…

diffusers | Remote | Supply Chain
May 14, 2026 May 19, 2026
May 14, 2026
May 19, 2026
7.6 HIGH
CVE-2026-44516 — Valtimo: Sensitive data exposure through HTTP request/response logging in LoggingRestClie…

Valtimo is an open-source business process automation platform. From 12.4.0 to 12.33.0 and 13.26.0, the LoggingRestClientCustomizer in the web module automatically intercepts all outgoing HTTP calls …

Remote | Information Disclosure
May 14, 2026 May 14, 2026
May 14, 2026
May 14, 2026
2.3 LOW
CVE-2026-44515 — Nextcloud News: Authenticated blind SSRF via feed URL

Nextcloud News is an RSS/Atom feed reader. Prior to 28.3.0-beta.1, Nextcloud News allows authenticated users to add feeds by providing a feed URL (via the web interface or the API). In affected versi…

news | Remote | Server-Side Request Forgery
May 14, 2026 May 14, 2026
May 14, 2026
May 14, 2026
Showing 20 of 7094 Results