Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.1 HIGH
CVE-2026-43913 — Vaultwarden: Unconfirmed Owner Can Purge Entire Organization Vault

Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.35.5, Vaultwarden allows an unconfirmed organization owner to purge the entire organization vault. The organization invite flo…

vaultwarden | Remote | Authorization
May 11, 2026 May 13, 2026
May 11, 2026
May 13, 2026
8.7 HIGH
CVE-2026-43912 — Vaultwarden: Cross-Org Group Binding Enables Unauthorized Read And Write Access Into Anot…

Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.35.5, Vaultwarden does not enforce that a groups_users.users_organizations_uuid entry belongs to the same organization as grou…

vaultwarden | Remote | Authorization
May 11, 2026 May 15, 2026
May 11, 2026
May 15, 2026
8.1 HIGH
CVE-2026-43911 — Vaultwarden: Refresh tokens not invalidated on security stamp rotation

Vaultwarden is a Bitwarden-compatible server written in Rust. Prior to 1.35.5, refresh tokens are not invalidated when the user's security_stamp is rotated by some security-sensitive operations (pass…

vaultwarden | Remote | Authentication
May 11, 2026 May 18, 2026
May 11, 2026
May 18, 2026
6.8 MEDIUM
CVE-2026-43901 — Wireshark MCP: Arbitrary file write via export_objects when WIRESHARK_MCP_ALLOWED_DIRS is…

Wireshark MCP is an MCP Server that turns tshark into a structured analysis interface, then layers in optional Wireshark suite utilities. In 1.1.5 and earlier, wireshark-mcp exposes a wireshark_expor…

wireshark_mcp | Remote | Path Traversal
May 11, 2026 May 13, 2026
May 11, 2026
May 13, 2026
9.3 CRITICAL
CVE-2026-43900 — DeepChat: Persistent DOM XSS via HTML Entity Encoding in `<antArtifact>` SVG Rendering (B…

DeepChat is an open-source artificial intelligence agent platform that unifies models, tools, and agents. Prior to v1.0.4-beta.1, a Cross-Site Scripting (XSS) vulnerability exists due to a discrepanc…

deepchat | Remote | Cross-Site Scripting
May 11, 2026 May 12, 2026
May 11, 2026
May 12, 2026
9.6 CRITICAL
CVE-2026-43899 — DeepChat: Incomplete Fix for CVE-2025-55733 leads to Remote Code Execution via Markdown L…

DeepChat is an open-source artificial intelligence agent platform that unifies models, tools, and agents. Prior to v1.0.4-beta.1, An incomplete mitigation for CVE-2025-55733 leaves DeepChat vulnerabl…

deepchat | Remote | Misconfiguration
May 11, 2026 May 12, 2026
May 11, 2026
May 12, 2026
6.1 MEDIUM
CVE-2026-42554 — Fiber: XSS in AutoFormat Content Negotiation

Fiber is a web framework for Go. Prior to 2.52.12 and 3.1.0, Cross-Site Scripting vulnerability in Go Fiber allows a remote attacker to inject arbitrary HTML/JavaScript by supplying Accept: text/html…

fiber | Remote | Cross-Site Scripting
May 11, 2026 May 18, 2026
May 11, 2026
May 18, 2026
8.6 HIGH
CVE-2026-34963 — barebox EFI PE Loader Memory Safety Vulnerabilities

barebox version prior to 2026.04.0 contains multiple memory-safety vulnerabilities in the EFI PE loader in efi/loader/pe.c where integer overflow in virtual image size computation using 32-bit arithm…

barebox | Memory Corruption
May 11, 2026 May 13, 2026
May 11, 2026
May 13, 2026
6.9 MEDIUM
CVE-2026-34962 — barebox ext4 Directory Parsing Infinite Loop Denial of Service

barebox version prior to 2026.04.0 contains a denial-of-service vulnerability in ext4 directory parsing in fs/ext4/ext4_common.c where the ext4fs_iterate_dir() function fails to validate that directo…

barebox | Denial of Service
May 11, 2026 May 13, 2026
May 11, 2026
May 13, 2026
Showing 20 of 7429 Results