Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.2 CRITICAL
CVE-2026-40946 — Oxia: OIDC token audience validation bypass via SkipClientIDCheck

Oxia is a metadata store and coordination system. Prior to 0.16.2, the OIDC authentication provider unconditionally sets SkipClientIDCheck: true in the go-oidc verifier configuration, disabling the s…

Remote | Authentication
Apr 21, 2026 Apr 22, 2026
Apr 21, 2026
Apr 22, 2026
8.7 HIGH
CVE-2026-40945 — Oxia: Bearer token exposed in debug log messages on authentication failure

Oxia is a metadata store and coordination system. Prior to 0.16.2, when OIDC authentication fails, the full bearer token is logged at DEBUG level in plaintext. If debug logging is enabled in producti…

Remote | Information Disclosure
Apr 21, 2026 Apr 22, 2026
Apr 21, 2026
Apr 22, 2026
6.9 MEDIUM
CVE-2026-40944 — Oxia: TLS CA certificate chain validation fails with multi-certificate PEM bundles

Oxia is a metadata store and coordination system. Prior to 0.16.2, the trustedCertPool() function in the TLS configuration only parses the first PEM block from CA certificate files. When a CA bundle …

Remote | Misconfiguration
Apr 21, 2026 Apr 22, 2026
Apr 21, 2026
Apr 22, 2026
8.7 HIGH
CVE-2026-40943 — Oxia: Server crash via race condition in session heartbeat handling

Oxia is a metadata store and coordination system. Prior to 0.16.2, a race condition between session heartbeat processing and session closure can cause the server to panic with send on closed channel.…

Remote | Race Condition
Apr 21, 2026 Apr 22, 2026
Apr 21, 2026
Apr 22, 2026
6.3 MEDIUM
CVE-2026-40942 — DSF: Inverted Time Comparison in OIDC JWKS and Token Cache

The Data Sharing Framework (DSF) implements a distributed process engine based on the BPMN 2.0 and FHIR R4 standards. Prior to 2.1.0, The OIDC JWKS and Metadata Document caches used an inverted time …

Remote | Misconfiguration
Apr 21, 2026 Apr 22, 2026
Apr 21, 2026
Apr 22, 2026
6.8 MEDIUM
CVE-2026-40939 — DSF: Missing Session Timeout for OIDC Sessions

The Data Sharing Framework (DSF) implements a distributed process engine based on the BPMN 2.0 and FHIR R4 standards. Prior to 2.1.0, OIDC-authenticated sessions had no configured maximum inactivity …

| Authentication
Apr 21, 2026 Apr 22, 2026
Apr 21, 2026
Apr 22, 2026
9.9 CRITICAL
CVE-2026-40933 — Flowise: Authenticated RCE Via MCP Adapters

Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.0, due to unsafe serialization of stdio commands in the MCP adapter, an authenticated attacker ca…

flowise | Remote | Injection
Apr 21, 2026 Apr 22, 2026
Apr 21, 2026
Apr 22, 2026
8.4 HIGH
CVE-2026-40931 — Complete Bypass of CVE-2026-24884 Patch via Git-Delivered Symlink Poisoning in compressing

Compressing is a compressing and uncompressing lib for node. Prior to 2.1.1 and 1.10.5, the patch for CVE-2026-24884 relies on a purely logical string validation within the isPathWithinParent utility…

compressing | Path Traversal
Apr 21, 2026 Apr 22, 2026
Apr 21, 2026
Apr 22, 2026
8.4 HIGH
CVE-2026-40706 — NTFS-3G Heap Buffer Overflow Vulnerability

In NTFS-3G 2022.10.3 before 2026.2.25, a heap buffer overflow exists in ntfs_build_permissions_posix() in acls.c that allows an attacker to corrupt heap memory in the SUID-root ntfs-3g binary by craf…

ntfs-3g | Memory Corruption
Apr 21, 2026 Apr 22, 2026
Apr 21, 2026
Apr 22, 2026
6.4 MEDIUM
CVE-2026-1354 — Zero Motorcycles Firmware Key Exchange without Entity Authentication

Zero Motorcycles firmware versions 44 and prior enable an attacker to forcibly pair a device with the motorcycle via Bluetooth. Once paired, an attacker can utilize over-the-air firmware updating f…

| Authentication
Apr 21, 2026 Apr 22, 2026
Apr 21, 2026
Apr 22, 2026
8.3 HIGH
CVE-2026-6823 — HKUDS OpenHarness Insecure Default Remote Channel Allowlist

HKUDS OpenHarness prior to PR #147 remediation contains an insecure default configuration vulnerability where remote channels inherit allow_from = ["*"] permitting arbitrary remote senders to pass ad…

Remote | Misconfiguration
Apr 21, 2026 Apr 22, 2026
Apr 21, 2026
Apr 22, 2026
5.3 MEDIUM
CVE-2026-6797 — Sanluan PublicCMS DocToHtmlUtils.java ZipSecureFile.setMinflateRatio resource consumption

A vulnerability was identified in Sanluan PublicCMS up to 6.202506.d. Affected by this vulnerability is the function ZipSecureFile.setMinflateRatio of the file common/src/main/java/com/publiccms/comm…

publiccms | Remote | Denial of Service
Apr 21, 2026 Apr 22, 2026
Apr 21, 2026
Apr 22, 2026
5.3 MEDIUM
CVE-2026-6796 — Sanluan PublicCMS Failed Login LoginAdminController.java log_login cleartext storage in f…

A vulnerability was determined in Sanluan PublicCMS up to 6.202506.d. Affected is the function log_login of the file core/src/main/java/com/publiccms/controller/admin/LoginAdminController.java of the…

publiccms | Remote | Information Disclosure
Apr 21, 2026 Apr 22, 2026
Apr 21, 2026
Apr 22, 2026
7.5 HIGH
CVE-2026-40938 — Tekton Pipelines: Git Resolver Unsanitized Revision Parameter Enables git Argument Inject…

Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. From 1.0.0 to before 1.11.0, the git resolver's revision parameter is passed directly as a positional argume…

tekton_pipelines | Remote | Injection
Apr 21, 2026 Apr 22, 2026
Apr 21, 2026
Apr 22, 2026
5.4 MEDIUM
CVE-2026-40927 — Docmost: XSS in Comments with JavaScript URI

Docmost is open-source collaborative wiki and documentation software. Prior to 0.80.0, when leaving a comment on a page, it is possible to include a JavaScript URI as the link. When a user clicks on …

docmost | Remote | Cross-Site Scripting
Apr 21, 2026 Apr 22, 2026
Apr 21, 2026
Apr 22, 2026
8.3 HIGH
CVE-2026-40925 — WWBN AVideo has CSRF in configurationUpdate.json.php Enables Full Site Configuration Take…

WWBN AVideo is an open source video platform. In versions 29.0 and prior, `objects/configurationUpdate.json.php` (also routed via `/updateConfig`) persists dozens of global site settings from `$_POST…

avideo | Remote | Cross-Site Request Forgery
Apr 21, 2026 Apr 22, 2026
Apr 21, 2026
Apr 22, 2026
6.5 MEDIUM
CVE-2026-40924 — Tekton Pipelines: HTTP Resolver Unbounded Response Body Read Enables Denial of Service vi…

Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Prior to 1.11.1, the HTTP resolver's FetchHttpResource function calls io.ReadAll(resp.Body) with no response…

tekton_pipelines | Remote | Denial of Service
Apr 21, 2026 Apr 22, 2026
Apr 21, 2026
Apr 22, 2026
5.4 MEDIUM
CVE-2026-40923 — Tekton Pipelines: VolumeMount path restriction bypass via missing filepath.Clean in /tekt…

Tekton Pipelines project provides k8s-style resources for declaring CI/CD-style pipelines. Prior to 1.11.1, a validation bypass in the VolumeMount path restriction allows mounting volumes under restr…

tekton_pipelines | Remote | Path Traversal
Apr 21, 2026 Apr 22, 2026
Apr 21, 2026
Apr 22, 2026
10.0 CRITICAL
CVE-2026-40911 — WWBN AVideo YPTSocket WebSocket Broadcast Relay Leads to Unauthenticated Cross-User JavaS…

WWBN AVideo is an open source video platform. In versions 29.0 and prior, the YPTSocket plugin's WebSocket server relays attacker-supplied JSON message bodies to every connected client without saniti…

avideo | Remote | Cross-Site Scripting
Apr 21, 2026 Apr 22, 2026
Apr 21, 2026
Apr 22, 2026
6.5 MEDIUM
CVE-2026-40910 — frp: Authentication bypass in frp HTTP vhost routing when routeByHTTPUser is used for acc…

frp is a fast reverse proxy. From 0.43.0 to 0.68.0, frp contains an authentication bypass in the HTTP vhost routing path when routeByHTTPUser is used as part of access control. In proxy-style request…

Remote | Authentication
Apr 21, 2026 Apr 22, 2026
Apr 21, 2026
Apr 22, 2026
Showing 20 of 6478 Results