Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.8 HIGH
CVE-2026-35582 — Emissary has an OS Command Injection via Unvalidated IN_FILE_ENDING / OUT_FILE_ENDING in …

Emissary is a P2P based data-driven workflow engine. In versions 8.42.0 and below, Executrix.getCommand() is vulnerable to OS command injection because it interpolates temporary file paths into a /b…

| Injection
Apr 18, 2026 Apr 18, 2026
Apr 18, 2026
Apr 18, 2026
6.1 MEDIUM
CVE-2026-1838 — Hostel <= 1.1.6 - Reflected Cross-Site Scripting via 'shortcode_id' Parameter

The Hostel plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'shortcode_id' parameter in all versions up to, and including, 1.1.6 due to insufficient input sanitization and…

Remote | Cross-Site Scripting
Apr 18, 2026 Apr 18, 2026
Apr 18, 2026
Apr 18, 2026
6.4 MEDIUM
CVE-2026-1559 — Youzify <= 1.3.6 - Authenticated (Subscriber+) Stored Cross-Site Scripting via 'checkin_p…

The Youzify plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'checkin_place_id' parameter in all versions up to, and including, 1.3.6 due to insufficient input sanitization a…

Remote | Cross-Site Scripting
Apr 18, 2026 Apr 18, 2026
Apr 18, 2026
Apr 18, 2026
9.0 CRITICAL
CVE-2026-40572 — NovumOS has Arbitrary Memory Mapping via Syscall 15 (MemoryMapRange)

NovumOS is a custom 32-bit operating system written in Zig and x86 Assembly. In versions prior to 0.24, Syscall 15 (MemoryMapRange) allows Ring 3 user-mode processes to map arbitrary virtual address …

| Memory Corruption
Apr 18, 2026 Apr 18, 2026
Apr 18, 2026
Apr 18, 2026
8.8 HIGH
CVE-2026-40350 — Movary User Management (/settings/users) has Authorization Bypass that Allows Low-Privile…

Movary is a self hosted web app to track and rate a user's watched movies. Prior to version 0.71.1, an ordinary authenticated user can access the user-management endpoints `/settings/users` and use t…

movary | Remote | Authentication
Apr 18, 2026 Apr 18, 2026
Apr 18, 2026
Apr 18, 2026
9.3 CRITICAL
CVE-2026-40317 — NovumOS has Privilege Escalation in the Syscall Interface

NovumOS is a custom 32-bit operating system written in Zig and x86 Assembly. In versions prior to 0.24, Syscall 12 (JumpToUser) accepts an arbitrary entry point address from user-space registers with…

| Authentication
Apr 18, 2026 Apr 18, 2026
Apr 18, 2026
Apr 18, 2026
7.5 HIGH
CVE-2026-35465 — SecureDrop Client has path injection in read_gzip_header_filename()

SecureDrop Client is a desktop app for journalists to securely communicate with sources and handle submissions on the SecureDrop Workstation. In versions 0.17.4 and below, a compromised SecureDrop Se…

Remote | Path Traversal
Apr 18, 2026 Apr 18, 2026
Apr 18, 2026
Apr 18, 2026
4.8 MEDIUM
CVE-2026-40593 — ChurchCRM: Stored XSS in UserEditor.php via Login Name Field

ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the User Editor (UserEditor.php) renders stored usernames directly into an HTML input value attribute without applyin…

churchcrm | Remote | Cross-Site Scripting
Apr 18, 2026 Apr 18, 2026
Apr 18, 2026
Apr 18, 2026
9.1 CRITICAL
CVE-2026-40582 — ChurchCRM: Authentication Bypass in `/api/public/user/login` Allows Bypass of 2FA and Acc…

ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the /api/public/user/login endpoint validates only the username and password before returning the user's API key, byp…

churchcrm | Remote | Authentication
Apr 18, 2026 Apr 18, 2026
Apr 18, 2026
Apr 18, 2026
8.1 HIGH
CVE-2026-40581 — ChurchCRM: Cross-Site Request Forgery (CSRF) in SelectDelete.php Leading to Permanent Dat…

ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the family record deletion endpoint (SelectDelete.php) performs permanent, irreversible deletion of family records an…

churchcrm | Remote | Cross-Site Request Forgery
Apr 18, 2026 Apr 18, 2026
Apr 18, 2026
Apr 18, 2026
5.3 MEDIUM
CVE-2026-40485 — ChurchCRM: Username Enumeration via Differential Response in Public Login API

ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the public API login endpoint (/api/public/user/login) returns distinguishable HTTP response codes based on whether a…

churchcrm | Remote | Information Disclosure
Apr 18, 2026 Apr 18, 2026
Apr 18, 2026
Apr 18, 2026
9.1 CRITICAL
CVE-2026-40484 — ChurchCRM: Authenticated Remote Code Execution via Unrestricted PHP File Write in Databas…

ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the database backup restore functionality extracts uploaded archive contents and copies files from the Images/ direct…

churchcrm | Remote | Path Traversal
Apr 18, 2026 Apr 18, 2026
Apr 18, 2026
Apr 18, 2026
5.4 MEDIUM
CVE-2026-40483 — ChurchCRM: Stored XSS in PledgeEditor.php via Donation Comment Field

ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the Pledge Editor renders donation comment values directly into HTML input value attributes without escaping via html…

churchcrm | Remote | Cross-Site Scripting
Apr 18, 2026 Apr 18, 2026
Apr 18, 2026
Apr 18, 2026
7.1 HIGH
CVE-2026-40482 — ChurchCRM has Authenticated SQL Injection in `/api/families/byCheckNumber/{scanString}`

ChurchCRM is an open-source church management system. Versions prior to 7.2.0 have SQL injection in FinancialService::getMemberByScanString() via unsanitized $routeAndAccount concatenated into raw SQ…

churchcrm | Remote | Injection
Apr 18, 2026 Apr 18, 2026
Apr 18, 2026
Apr 18, 2026
7.1 HIGH
CVE-2026-40480 — ChurchCRM has Missing Object-Level Authorization / IDOR in `/api/person/{personId}`

ChurchCRM is an open-source church management system. In versions prior to 7.2.0, the GET /api/person/{personId} endpoint loads and returns person records without performing object-level authorizatio…

churchcrm | Remote | Authorization
Apr 18, 2026 Apr 18, 2026
Apr 18, 2026
Apr 18, 2026
8.8 HIGH
CVE-2026-40349 — Authenticated Movary User Can Self-Escalate to Administrator via PUT /settings/users/{use…

Movary is a self hosted web app to track and rate a user's watched movies. Prior to version 0.71.1, an ordinary authenticated user can escalate their own account to administrator by sending `isAdmin=…

movary | Remote | Authorization
Apr 18, 2026 Apr 18, 2026
Apr 18, 2026
Apr 18, 2026
7.7 HIGH
CVE-2026-40348 — Movary has Authenticated SSRF via Jellyfin Server URL Verification that Allows Internal N…

Movary is a self hosted web app to track and rate a user's watched movies. Prior to version 0.71.1, an ordinary authenticated user can trigger server-side requests to arbitrary internal targets throu…

movary | Remote | Server-Side Request Forgery
Apr 18, 2026 Apr 18, 2026
Apr 18, 2026
Apr 18, 2026
5.3 MEDIUM
CVE-2026-40347 — Python-Multipart affected by Denial of Service via large multipart preamble or epilogue d…

Python-Multipart is a streaming multipart parser for Python. Versions prior to 0.0.26 have a denial of service vulnerability when parsing crafted `multipart/form-data` requests with large preamble or…

python-multipart | Remote | Denial of Service
Apr 18, 2026 Apr 18, 2026
Apr 18, 2026
Apr 18, 2026
6.4 MEDIUM
CVE-2026-40346 — NocoBase has SSRF in Workflow HTTP Request and Custom Request Plugins

NocoBase is an AI-powered no-code/low-code platform for building business applications and enterprise solutions. Prior to version 2.0.37, NocoBase's workflow HTTP request plugin and custom request ac…

nocobase | Remote | Server-Side Request Forgery
Apr 18, 2026 Apr 18, 2026
Apr 18, 2026
Apr 18, 2026
3.5 LOW
CVE-2026-40341 — libgphoto2 has an OOB Read in ptp_unpack_EOS_FocusInfoEx

libgphoto2 is a camera access and control library. In versions up to and including 2.5.33, an out of bound read in ptp_unpack_EOS_FocusInfoEx could be used to crash libgphoto2 when processing input f…

| Memory Corruption
Apr 18, 2026 Apr 18, 2026
Apr 18, 2026
Apr 18, 2026
Showing 20 of 6473 Results