Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.5 HIGH
CVE-2026-42544 — Granian: Unauthenticated DoS via WebSocket subprotocol header panic

Granian is a Rust HTTP server for Python applications. From 1.2.0 to 2.7.4, Granian aborts a worker process when an unauthenticated client sends a WebSocket upgrade request whose Sec-WebSocket-Protoc…

Remote | Denial of Service
May 12, 2026 May 18, 2026
May 12, 2026
May 18, 2026
8.2 HIGH
CVE-2026-42268 — ModSecurity: Unsigned integer underflow in @verifySSN / @verifyCPF / @verifySVNR operators

ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. From 3.0.0 to before 3.0.15, there is an unhandled exception (std::out_of_range) caused …

modsecurity | Remote | Denial of Service
May 12, 2026 May 14, 2026
May 12, 2026
May 14, 2026
9.9 CRITICAL
CVE-2026-42196 — django-s3file: Relative path traversal

django-s3file is a lightweight file upload input for Django and Amazon S3. Prior to 7.0.2, S3FileMiddleware is vulnerable to relative path traversal attacks, where an attacker can use a modified requ…

django-s3file | Remote | Path Traversal
May 12, 2026 May 13, 2026
May 12, 2026
May 13, 2026
5.0 MEDIUM
CVE-2026-41195 — mosparo: Rule package source URL stored SSRF enables internal HTTP probing

mosparo is the modern solution to protect your online forms from spam. Prior to 1.4.13, the automatic rule package source URL feature allows a project member with the editor role to store an attacker…

mosparo | Remote | Server-Side Request Forgery
May 12, 2026 May 18, 2026
May 12, 2026
May 18, 2026
7.5 HIGH
CVE-2026-40902 — PhpSpreadsheet: CPU Denial of Service via Unbounded Row Number in XLSX Row Dimensions

PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. Prior to 1.30.4, 2.1.16, 2.4.5, 3.10.5, and 5.7.0, the XLSX reader's ColumnAndRowAttributes::readRowAttributes() method…

phpspreadsheet | Remote | Denial of Service
May 12, 2026 May 14, 2026
May 12, 2026
May 14, 2026
7.5 HIGH
CVE-2026-40863 — PhpSpreadsheet: CPU Denial of Service via Unbounded Row Index in SpreadsheetML XML Reader

PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. Prior to 1.30.4, 2.1.16, 2.4.5, 3.10.5, and 5.7.0, the SpreadsheetML XML reader (Reader\Xml) does not validate the ss:I…

phpspreadsheet | Remote | Denial of Service
May 12, 2026 May 13, 2026
May 12, 2026
May 13, 2026
7.0 HIGH
CVE-2026-35555 — Subnet Solutions PowerSYSTEM Center Incorrect Authorization

PowerSYSTEM Center feature for device project groups allows an authenticated user with limited permissions to perform an unauthorized deletion of project groups.

| Authorization
May 12, 2026 May 13, 2026
May 12, 2026
May 13, 2026
6.9 MEDIUM
CVE-2026-33570 — Subnet Solutions PowerSYSTEM Center Incorrect Authorization

PowerSYSTEM Center REST API endpoint for devices allows a low privilege authenticated user to access information normally limited by operational permissions.

| Authorization
May 12, 2026 May 13, 2026
May 12, 2026
May 13, 2026
8.4 HIGH
CVE-2026-26289 — Subnet Solutions PowerSYSTEM Center Incorrect Authorization

PowerSYSTEM Center REST API endpoint for device account export allows an authenticated user with limited permissions to expose sensitive information normally restricted to administrative permissions …

| Authorization
May 12, 2026 May 13, 2026
May 12, 2026
May 13, 2026
Showing 20 of 7069 Results