Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.9 CRITICAL
CVE-2026-40470 — Hackage package and doc upload stored XSS vulnerability

A critical XSS vulnerability affected hackage-server and hackage.haskell.org. HTML and JavaScript files provided in source packages or via the documentation upload facility were served as-is on the …

Remote | Cross-Site Scripting
Apr 23, 2026 Apr 23, 2026
Apr 23, 2026
Apr 23, 2026
9.8 CRITICAL
CVE-2026-39087 — Ntfy Arbitrary Code Execution Vulnerability

An issue in Ntfy ntfy.sh before v.2.21 allows a remote attacker to execute arbitrary code via the parseActions function

Remote | Injection
Apr 23, 2026 Apr 23, 2026
Apr 23, 2026
Apr 23, 2026
7.8 HIGH
CVE-2026-34003 — Xorg: xwayland: x.org x server: information exposure and denial of service via out-of-bou…

A flaw was found in the X.Org X server's XKB key types request validation. A local attacker could send a specially crafted request to the X server, leading to an out-of-bounds memory access vulnerabi…

| Memory Corruption
Apr 23, 2026 Apr 23, 2026
Apr 23, 2026
Apr 23, 2026
7.8 HIGH
CVE-2026-34001 — Xorg: xwayland: x.org x server: use-after-free vulnerability leads to server crash and po…

A flaw was found in the X.Org X server. This use-after-free vulnerability occurs in the XSYNC fence triggering logic, specifically within the miSyncTriggerFence() function. An attacker with access to…

| Memory Corruption
Apr 23, 2026 Apr 23, 2026
Apr 23, 2026
Apr 23, 2026
7.8 HIGH
CVE-2026-33999 — Xorg: xwayland: x.org x server: denial of service via integer underflow in xkb compatibil…

A flaw was found in the X.Org X server. This integer underflow vulnerability, specifically in the XKB compatibility map handling, allows an attacker with local or remote X11 server access to trigger …

| Memory Corruption
Apr 23, 2026 Apr 23, 2026
Apr 23, 2026
Apr 23, 2026
9.8 CRITICAL
CVE-2026-23751 — Kofax Capture 6.0.0.0 Unauthenticated File Read/Write & SMB Coercion via .NET Remoting

Kofax Capture, now referred to as Tungsten Capture, version 6.0.0.0 (other versions may be affected) exposes a deprecated .NET Remoting HTTP channel on port 2424 via the Ascent Capture Service that i…

Remote | Information Disclosure
Apr 23, 2026 Apr 23, 2026
Apr 23, 2026
Apr 23, 2026
9.8 CRITICAL
CVE-2025-62373 — Pipecat vulnerable to Remote Code Execution by Pickle Deserialization via LivekitFrameSer…

Pipecat is an open-source Python framework for building real-time voice and multimodal conversational agents. Versions 0.0.41 through 0.0.93 have a vulnerability in `LivekitFrameSerializer` – an opti…

Remote | Injection
Apr 23, 2026 Apr 23, 2026
Apr 23, 2026
Apr 23, 2026
0.0 NA
CVE-2025-50229 — Jizhicms SQL Injection Vulnerability

Jizhicms v2.5.4 is vulnerable to SQL injection in the product editing module.

| Injection
Apr 23, 2026 Apr 23, 2026
Apr 23, 2026
Apr 23, 2026
8.5 HIGH
CVE-2026-41461 — SocialEngine <= 7.8.0 Blind SSRF via /core/link/preview

SocialEngine versions 7.8.0 and prior contain a blind server-side request forgery vulnerability in the /core/link/preview endpoint where user-supplied input passed via the uri request parameter is no…

socialengine | Remote | Server-Side Request Forgery
Apr 23, 2026 Apr 23, 2026
Apr 23, 2026
Apr 23, 2026
9.8 CRITICAL
CVE-2026-41460 — SocialEngine <= 7.8.0 SQL Injection via activity/index/get-memberall

SocialEngine versions 7.8.0 and prior contain a SQL injection vulnerability in the /activity/index/get-memberall endpoint where user-supplied input passed via the text parameter is not sanitized befo…

socialengine | Remote | Injection
Apr 23, 2026 Apr 23, 2026
Apr 23, 2026
Apr 23, 2026
8.7 HIGH
CVE-2026-35225 — Improper timeout handling in CODESYS EtherNetIP

An unauthenticated remote attacker is able to exhaust all available TCP connections in the CODESYS EtherNet/IP adapter stack, preventing legitimate clients from establishing new connections.

codesys_ethernetip | Remote | Denial of Service
Apr 23, 2026 Apr 23, 2026
Apr 23, 2026
Apr 23, 2026
7.3 HIGH
CVE-2025-70994 — Yadea T5 Electric Bicycles Keyless Entry Signal Forgery Vulnerability

Yadea T5 Electric Bicycles (models manufactured in/after 2024) have a weak authentication mechanism in their keyless entry system. The system utilizes the EV1527 fixed-code RF protocol without implem…

| Authentication
Apr 23, 2026 Apr 23, 2026
Apr 23, 2026
Apr 23, 2026
9.9 CRITICAL
CVE-2026-39440 — WordPress FunnelFormsPro plugin <= 3.8.1 - Remote Code Execution (RCE) vulnerability

Improper Control of Generation of Code ('Code Injection') vulnerability in Funnelforms LLC FunnelFormsPro allows Remote Code Inclusion.This issue affects FunnelFormsPro: from n/a through 3.8.1.

Remote | Injection
Apr 23, 2026 Apr 23, 2026
Apr 23, 2026
Apr 23, 2026
4.7 MEDIUM
CVE-2025-66286 — Webkitgtk: authorization bypass through webpage::send-request signal handler

An API design flaw in WebKitGTK and WPE WebKit allows untrusted web content to unexpectedly perform IP connections, DNS lookups, and HTTP requests. Applications expect to use the WebPage::send-reques…

Remote | Server-Side Request Forgery
Apr 23, 2026 Apr 23, 2026
Apr 23, 2026
Apr 23, 2026
5.7 MEDIUM
CVE-2025-13763 — Libopensc: opensc: multiple uses of uninitialized variable

Multiple uses of uninitialized variables were found in libopensc that may lead to information disclosure or application crash. An attack requires a crafted USB device or smart card that would present…

opensc | Information Disclosure
Apr 23, 2026 Apr 23, 2026
Apr 23, 2026
Apr 23, 2026
0.0 NA
CVE-2026-31532 — can: raw: fix ro->uniq use-after-free in raw_rcv()

In the Linux kernel, the following vulnerability has been resolved: can: raw: fix ro->uniq use-after-free in raw_rcv() raw_release() unregisters raw CAN receive filters via can_rx_unregister(), but…

linux_kernel | Memory Corruption
Apr 23, 2026 Apr 23, 2026
Apr 23, 2026
Apr 23, 2026
0.0 NA
CVE-2026-31531 — ipv4: nexthop: allocate skb dynamically in rtm_get_nexthop()

In the Linux kernel, the following vulnerability has been resolved: ipv4: nexthop: allocate skb dynamically in rtm_get_nexthop() When querying a nexthop object via RTM_GETNEXTHOP, the kernel curren…

linux_kernel | Denial of Service
Apr 23, 2026 Apr 23, 2026
Apr 23, 2026
Apr 23, 2026
6.5 MEDIUM
CVE-2026-28040 — WordPress Taxi Booking Manager for WooCommerce plugin <= 2.0.0 - Cross Site Scripting (XS…

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Magepeople inc. Taxi Booking Manager for WooCommerce allows Stored XSS.This issue affects Taxi Bo…

Remote | Cross-Site Scripting
Apr 23, 2026 Apr 23, 2026
Apr 23, 2026
Apr 23, 2026
6.5 MEDIUM
CVE-2025-62110 — WordPress Rescue Shortcodes plugin <= 3.3 - Cross Site Scripting (XSS) vulnerability

Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Rescue Themes Rescue Shortcodes allows Stored XSS.This issue affects Rescue Shortcodes: from n/a …

rescue_shortcodes | Remote | Cross-Site Scripting
Apr 23, 2026 Apr 23, 2026
Apr 23, 2026
Apr 23, 2026
4.3 MEDIUM
CVE-2025-62104 — WordPress ACF Galerie 4 plugin <= 1.4.2 - Broken Access Control vulnerability

Missing Authorization vulnerability in Navneil Naicker ACF Galerie 4 allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects ACF Galerie 4: from n/a through 1.4.2.

Remote | Authorization
Apr 23, 2026 Apr 23, 2026
Apr 23, 2026
Apr 23, 2026
Showing 20 of 6337 Results