Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.5 HIGH
CVE-2026-6659 — Crypt::PasswdMD5 versions through 1.42 for Perl generates insecure random values for salts

Crypt::PasswdMD5 versions through 1.42 for Perl generates insecure random values for salts. The built-in rand function is predictable, and unsuitable for cryptography.

Remote | Cryptography
May 08, 2026 May 26, 2026
May 08, 2026
May 26, 2026
9.8 CRITICAL
CVE-2026-42072 — Nornicdb: Improper Network Binding in NornicDB Bolt Server allows unauthorized remote acc…

Nornicdb is a distributed low-latency, Graph+Vector, Temporal MVCC with all sub-ms HNSW search, graph traversal, and writes. Prior to version 1.0.42-hotfix, the --address CLI flag (and NORNICDB_ADDRE…

Remote | Misconfiguration
May 08, 2026 May 13, 2026
May 08, 2026
May 13, 2026
6.1 MEDIUM
CVE-2026-42030 — MapServer: Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) …

MapServer is a system for developing web-based GIS applications. From version 6.0 to before version 8.6.2, a reflected XSS vulnerability in MapServer's WMS server allows an unauthenticated attacker t…

mapserver | Remote | Cross-Site Scripting
May 08, 2026 May 14, 2026
May 08, 2026
May 14, 2026
5.3 MEDIUM
CVE-2026-42028 — novaGallery: Unauthenticated Path Traversal in Album and Cached Image Routes Allows Readi…

novaGallery is a php image gallery. Prior to version 2.1.1, a path traversal vulnerability has been identified in novaGallery. This allows unauthenticated users to read image files outside the intend…

Remote | Path Traversal
May 08, 2026 May 12, 2026
May 08, 2026
May 12, 2026
9.8 CRITICAL
CVE-2026-41889 — pgx: SQL Injection via placeholder confusion with dollar quoted string literals

pgx is a PostgreSQL driver and toolkit for Go. Prior to version 5.9.2, SQL injection can occur when the non-default simple protocol is used, a dollar quoted string literal is used in the SQL query, t…

pgx pgx | Remote | Injection
May 08, 2026 May 21, 2026
May 08, 2026
May 21, 2026
4.9 MEDIUM
CVE-2026-41887 — Flarum: Path traversal in LESS parser via theme color settings (incomplete fix for CVE-20…

Flarum is open-source forum software. Prior to versions 1.8.16 and 2.0.0-rc.1, Flarum's patch for CVE-2023-27577 restricted the @import and data-uri() LESS features in the custom_less setting, but th…

flarum | Remote | Injection
May 08, 2026 May 12, 2026
May 08, 2026
May 12, 2026
9.8 CRITICAL
CVE-2026-38360 — Fohrloop Dash-Uploader Directory Traversal RCE

Directory Traversal vulnerability in fohrloop dash-uploader v.0.1.0 through v.0.7.0a2 allows a remote attacker to execute arbitrary code via the dash_uploader/httprequesthandler.py, aseHttpRequestHan…

Remote | Path Traversal
May 08, 2026 May 12, 2026
May 08, 2026
May 12, 2026
Showing 20 of 6747 Results