Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
6.5 MEDIUM
CVE-2026-40910 — frp: Authentication bypass in frp HTTP vhost routing when routeByHTTPUser is used for acc…

frp is a fast reverse proxy. From 0.43.0 to 0.68.0, frp contains an authentication bypass in the HTTP vhost routing path when routeByHTTPUser is used as part of access control. In proxy-style request…

Remote | Authentication
Apr 21, 2026 Apr 22, 2026
Apr 21, 2026
Apr 22, 2026
9.9 CRITICAL
CVE-2026-40906 — Electric: SQL Injection via ORDER BY Parameter in Shape API

Electric is a Postgres sync engine. From 1.1.12 to before 1.5.0, the order_by parameter in the ElectricSQL /v1/shape API is vulnerable to error-based SQL injection, allowing any authenticated user to…

Remote | Injection
Apr 21, 2026 Apr 22, 2026
Apr 21, 2026
Apr 22, 2026
8.1 HIGH
CVE-2026-40905 — LinkAce: Password Reset Poisoning via X-Forwarded-Host Header Injection Leading to Accoun…

LinkAce is a self-hosted archive to collect website links. Prior to 2.5.4, a password reset poisoning vulnerability was identified in the application due to improper trust of user-controlled HTTP hea…

linkace | Remote | Server-Side Request Forgery
Apr 21, 2026 Apr 22, 2026
Apr 21, 2026
Apr 22, 2026
6.9 MEDIUM
CVE-2026-40895 — follow-redirects: Custom Authentication Headers Leaked to Cross-Domain Redirect Targets

follow-redirects is an open source, drop-in replacement for Node's `http` and `https` modules that automatically follows redirects. Prior to 1.16.0, when an HTTP request follows a cross-domain redire…

follow-redirects | Remote | Information Disclosure
Apr 21, 2026 Apr 22, 2026
Apr 21, 2026
Apr 22, 2026
8.1 HIGH
CVE-2026-40892 — PJSIP: Stack buffer overflow in pjsip_auth_create_digest2()

PJSIP is a free and open source multimedia communication library written in C. In 2.16 and earlier, a stack buffer overflow exists in pjsip_auth_create_digest2() in PJSIP when using pre-computed dige…

pjsip | Remote | Memory Corruption
Apr 21, 2026 Apr 22, 2026
Apr 21, 2026
Apr 22, 2026
6.4 MEDIUM

Vulnerability in the Oracle Security Service product of Oracle Fusion Middleware (component: C Oracle SSL API). Supported versions that are affected are 12.2.1.4.0 and 12.1.3.0.0. Difficult to expl…

security_service | Remote
Apr 21, 2026 Apr 22, 2026
Apr 21, 2026
Apr 22, 2026
7.5 HIGH

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.6. Difficult to exploit vulnerability allows high privile…

Apr 21, 2026 Apr 22, 2026
Apr 21, 2026
Apr 22, 2026
2.3 LOW

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.6. Easily exploitable vulnerability allows high privilege…

Apr 21, 2026 Apr 22, 2026
Apr 21, 2026
Apr 22, 2026
3.2 LOW

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.6. Easily exploitable vulnerability allows high privilege…

Apr 21, 2026 Apr 22, 2026
Apr 21, 2026
Apr 22, 2026
5.0 MEDIUM

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.6. Difficult to exploit vulnerability allows high privile…

Apr 21, 2026 Apr 22, 2026
Apr 21, 2026
Apr 22, 2026
6.0 MEDIUM

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.6. Easily exploitable vulnerability allows high privilege…

Apr 21, 2026 Apr 22, 2026
Apr 21, 2026
Apr 22, 2026
7.5 HIGH

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.6. Difficult to exploit vulnerability allows high privile…

Apr 21, 2026 Apr 22, 2026
Apr 21, 2026
Apr 22, 2026
7.5 HIGH

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.6. Easily exploitable vulnerability allows unauthenticate…

vm_virtualbox | Remote
Apr 21, 2026 Apr 22, 2026
Apr 21, 2026
Apr 22, 2026
5.2 MEDIUM

Vulnerability in the Oracle Hyperion Infrastructure Technology product of Oracle Hyperion (component: Lifecycle Management). The supported version that is affected is 11.2.24.0.000. Easily exploita…

Apr 21, 2026 Apr 22, 2026
Apr 21, 2026
Apr 22, 2026
7.8 HIGH

Vulnerability in the Oracle Application Development Framework (ADF) product of Oracle Fusion Middleware (component: ADF Faces). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. E…

Apr 21, 2026 Apr 22, 2026
Apr 21, 2026
Apr 22, 2026
7.5 HIGH

Vulnerability in the Oracle VM VirtualBox product of Oracle Virtualization (component: Core). The supported version that is affected is 7.2.6. Difficult to exploit vulnerability allows high privile…

Apr 21, 2026 Apr 22, 2026
Apr 21, 2026
Apr 22, 2026
5.7 MEDIUM

Vulnerability in the PeopleSoft Enterprise CS Student Records product of Oracle PeopleSoft (component: Research Tracking). The supported version that is affected is 9.2. Easily exploitable vulnerab…

Apr 21, 2026 Apr 22, 2026
Apr 21, 2026
Apr 22, 2026
4.9 MEDIUM

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vuln…

mysql_server | Remote
Apr 21, 2026 Apr 22, 2026
Apr 21, 2026
Apr 22, 2026
4.9 MEDIUM

Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: DML). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerabil…

mysql_server | Remote
Apr 21, 2026 Apr 22, 2026
Apr 21, 2026
Apr 22, 2026
4.9 MEDIUM

Vulnerability in the MySQL Server product of Oracle MySQL (component: InnoDB). Supported versions that are affected are 8.0.0-8.0.45, 8.4.0-8.4.8 and 9.0.0-9.6.0. Easily exploitable vulnerability a…

mysql_server | Remote
Apr 21, 2026 Apr 22, 2026
Apr 21, 2026
Apr 22, 2026
Showing 20 of 6460 Results