Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.5 HIGH
CVE-2026-9538 — Archive::Tar versions before 3.10 for Perl allow memory exhaustion via attacker controlle…

Archive::Tar versions before 3.10 for Perl allow memory exhaustion via attacker controlled entry size field in tar header. _read_tar() reads each entry's payload with $handle->read($$data, $block), …

\ | Remote | Memory Corruption
May 26, 2026 May 28, 2026
May 26, 2026
May 28, 2026
7.5 HIGH
CVE-2026-9521 — fraillt bitsery std_smart_ptr.h loadFromSharedState improper validation of specified type…

A security vulnerability has been detected in fraillt bitsery up to 5.2.4. Affected is the function loadFromSharedState in the library include/bitsery/ext/std_smart_ptr.h. Such manipulation leads to …

bitsery | Remote | Misconfiguration
May 26, 2026 May 26, 2026
May 26, 2026
May 26, 2026
5.0 MEDIUM
CVE-2026-9520 — blitz-js blitz Sign-in LoginForm.tsx cross site scripting

A weakness has been identified in blitz-js blitz up to 3.0.2 on GitHub. This impacts an unknown function of the file packages/generator/templates/app/src/app/auth/components/LoginForm.tsx of the comp…

blitz | Remote | Cross-Site Scripting
May 26, 2026 May 26, 2026
May 26, 2026
May 26, 2026
5.0 MEDIUM
CVE-2026-9519 — stonith404 pingvin-share Sign-in Auto-Redirect signIn.tsx getServerSideProps cross site s…

A security flaw has been discovered in stonith404 pingvin-share up to 1.13.0. This affects the function getServerSideProps of the file frontend/src/pages/auth/signIn.tsx of the component Sign-in Auto…

pingvin-share | Remote | Cross-Site Scripting
May 26, 2026 May 26, 2026
May 26, 2026
May 26, 2026
5.0 MEDIUM
CVE-2026-9518 — hemant6488 CodeIgniter-StudentManagementSystem Students Controller view_students.php addS…

A vulnerability was identified in hemant6488 CodeIgniter-StudentManagementSystem. The impacted element is the function addStudent of the file view_students.php of the component Students Controller. T…

codeigniter-studentmanagementsystem | Remote | Cross-Site Scripting
May 26, 2026 May 26, 2026
May 26, 2026
May 26, 2026
6.5 MEDIUM
CVE-2026-4795 — Zyxel GS1200 Series Missing Authorization Vulnerability (Configuration Disclosure)

A missing authorization vulnerability in Zyxel GS1200-5v3 firmware versions through 1.00(ACPS.2)C0, GS1200-8v3 firmware versions through 1.00(ACPT.2)C0,  GS1200-5HPv3 firmware versions through 1.00(A…

| Authorization
May 26, 2026 May 26, 2026
May 26, 2026
May 26, 2026
7.5 HIGH
CVE-2026-42497 — Archive::Tar versions before 3.08 for Perl extract hardlinks to attacker controlled paths…

Archive::Tar versions before 3.08 for Perl extract hardlinks to attacker controlled paths outside the extraction directory. _make_special_file() passes the tar header's linkname to link() without va…

\ | Remote | Path Traversal
May 26, 2026 May 28, 2026
May 26, 2026
May 28, 2026
9.1 CRITICAL
CVE-2026-42496 — Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targ…

Archive::Tar versions before 3.08 for Perl extract symlinks with attacker controlled targets outside the extraction directory. _make_special_file() passes the tar header's linkname to symlink() with…

\ | Remote | Path Traversal
May 26, 2026 May 28, 2026
May 26, 2026
May 28, 2026
1.8 LOW
CVE-2025-71310 — Backdrop CMS YouTube GDPR Cookies Module XSS

The GDPR cookies module for Backdrop CMS (before 1.x-1.3.5) doesn't sufficiently protect visitors from Cross Site Scripting (XSS) if a malicious value has been provided for the optional 'Info conte…

Remote | Cross-Site Scripting
May 26, 2026 May 26, 2026
May 26, 2026
May 26, 2026
Showing 20 of 8069 Results