Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.5 HIGH
CVE-2026-7461 — OS Command Injection in Amazon ECS Agent via FSx Windows File Server Volume Credentials

Improper neutralization of inputs used in an OS command in the FSx Windows File Server volume mounting component in Amazon ECS Agent on Windows before version 1.103.0 might allow a remote authenticat…

Remote | Injection
Apr 30, 2026 Apr 30, 2026
Apr 30, 2026
Apr 30, 2026
8.1 HIGH
CVE-2026-40904 — Chartbrew: Incorrect Access Control in dataset and dataRequest routes via team-scoped per…

Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. In version 4.9.0, Chartbrew exposes multiple dataset and dataRequest end…

Remote | Authorization
Apr 30, 2026 Apr 30, 2026
Apr 30, 2026
Apr 30, 2026
6.5 MEDIUM
CVE-2026-40603 — Chartbrew: Incorrect Access Control in /api/project/dashboard/:brewName via same-team ove…

Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. In version 4.9.0, Chartbrew exposes a legacy dashboard route that return…

Remote | Authorization
Apr 30, 2026 Apr 30, 2026
Apr 30, 2026
Apr 30, 2026
7.5 HIGH
CVE-2026-40601 — Chartbrew: Missing Authorization in /api/chart/:chart_id/query via team-level refresh tog…

Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. In version 4.9.0, Chartbrew exposes POST /api/chart/:chart_id/query with…

Remote | Authorization
Apr 30, 2026 Apr 30, 2026
Apr 30, 2026
Apr 30, 2026
8.1 HIGH
CVE-2026-40600 — Chartbrew: Incorrect Access Control in project share policy routes via unbound policy_id

Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. In version 4.9.0, Chartbrew allows authenticated users with access to on…

Remote | Authorization
Apr 30, 2026 Apr 30, 2026
Apr 30, 2026
Apr 30, 2026
7.5 HIGH
CVE-2026-40595 — Chartbrew: Incorrect Access Control in public chart and export routes via missing onRepor…

Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. In version 4.9.0, Chartbrew exposes public chart retrieval and export ro…

Remote | Authorization
Apr 30, 2026 Apr 30, 2026
Apr 30, 2026
Apr 30, 2026
6.5 MEDIUM
CVE-2026-35514 — Unauthenticated Account Registration via /user/invited Bypasses All Signup Restrictions i…

Chartbrew is an open-source web application that can connect directly to databases and APIs and use the data to create charts. In version 4.9.0, the endpoint POST /user/invited does not validate any …

Remote | Authentication
Apr 30, 2026 Apr 30, 2026
Apr 30, 2026
Apr 30, 2026
8.9 HIGH
CVE-2026-32148 — Lockfile checksums not verified in Hex allows dependency integrity bypass

Insufficient Verification of Data Authenticity vulnerability in hexpm hex (Hex.RemoteConverger module) allows dependency integrity bypass via unverified lockfile checksums. Hex stores checksums for …

Remote | Supply Chain
Apr 30, 2026 Apr 30, 2026
Apr 30, 2026
Apr 30, 2026
6.5 MEDIUM
CVE-2026-3833 — Gnutls: gnutls: policy bypass due to case-sensitive nameconstraints comparison

A flaw was found in gnutls. This vulnerability occurs because gnutls performs case-sensitive comparisons of `nameConstraints` labels, specifically for `dNSName` (DNS) or `rfc822Name` (email) constrai…

Remote | Misconfiguration
Apr 30, 2026 Apr 30, 2026
Apr 30, 2026
Apr 30, 2026
3.7 LOW
CVE-2026-3832 — Gnutls: gnutls: security bypass allows acceptance of revoked server certificates via craf…

A flaw was found in gnutls. A remote attacker could exploit this vulnerability by presenting a specially crafted Online Certificate Status Protocol (OCSP) response during a TLS handshake. Due to a lo…

Remote | Cryptography
Apr 30, 2026 Apr 30, 2026
Apr 30, 2026
Apr 30, 2026
5.4 MEDIUM
CVE-2026-36766 — Shopizer Cross-Site Scripting (XSS) Vulnerability

Multiple authenticated cross-site scripting (XSS) vulnerabilities in the XssHttpServletRequestWrapper class of shopizer v3.2.5 allows attackers to execute arbitrary web scripts or HTML via injecting …

Remote | Cross-Site Scripting
Apr 30, 2026 Apr 30, 2026
Apr 30, 2026
Apr 30, 2026
0.0 NA
CVE-2026-36765 — SpringBlade XXE Code Execution Vulnerability

An XML external entity (XXE) vulnerability in the /designer/loadReport endpoint of SpringBlade v4.8.0 allows authenticated attackers to execute arbitrary code via injecting a crafted payload.

| XML External Entity
Apr 30, 2026 Apr 30, 2026
Apr 30, 2026
Apr 30, 2026
6.1 MEDIUM
CVE-2026-36763 — SpringBlade Stored Cross-Site Scripting (XSS)

A stored cross-site scripting (XSS) vulnerability in the /api/blade-desk/notice/submit endpoint of SpringBlade v4.8.0 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted…

Remote | Cross-Site Scripting
Apr 30, 2026 Apr 30, 2026
Apr 30, 2026
Apr 30, 2026
0.0 NA
CVE-2026-36762 — JeeSite File Upload Path Traversal Vulnerability

An issue in the fileEntityId parameter in the /a/file/upload endpoint of JeeSite v5.15.1 allows authenticated attackers with file upload permissions to execute a path traversal and write arbitrary fi…

| Path Traversal
Apr 30, 2026 Apr 30, 2026
Apr 30, 2026
Apr 30, 2026
6.1 MEDIUM
CVE-2026-36761 — JeeSite Stored XSS Vulnerability

A stored cross-site scripting (XSS) vulnerability in the /msg/msgInner/save endpoint of JeeSite v5.15.1 allows attackers to execute arbitrary web scripts or HTML via injecting a crafted input into th…

Remote | Cross-Site Scripting
Apr 30, 2026 Apr 30, 2026
Apr 30, 2026
Apr 30, 2026
7.5 HIGH
CVE-2026-33845 — Gnutls: gnutls: denial of service via dtls zero-length fragment

A flaw in GnuTLS DTLS handshake parsing allows malformed fragments with zero length and non-zero offset, leading to an integer underflow during reassembly and resulting in an out-of-bounds read. This…

Remote | Memory Corruption
Apr 30, 2026 Apr 30, 2026
Apr 30, 2026
Apr 30, 2026
10.0 CRITICAL
CVE-2026-36767 — Shopizer Path Traversal File Write Vulnerability

A path traversal vulnerability in the /content/images/add endpoint of shopizer v3.2.5 allows attackers write arbitrary files to any writeable path via a crafted POST request.

Remote | Path Traversal
Apr 30, 2026 Apr 30, 2026
Apr 30, 2026
Apr 30, 2026
5.0 MEDIUM
CVE-2026-36764 — SpringBlade SSRF Vulnerability

A Server-Side Request Forgery (SSRF) in the /ureport/datasource/testConnection endpoint of SpringBlade v4.8.0 allows authenticated attackers to scan internal resources via a crafted GET request.

Remote | Server-Side Request Forgery
Apr 30, 2026 Apr 30, 2026
Apr 30, 2026
Apr 30, 2026
9.6 CRITICAL
CVE-2026-36760 — JeeSite File Upload Path Traversal Write Arbitrary Files

An issue in the fileMd5 parameter in the /a/file/upload endpoint of JeeSite v5.15.1 allows authenticated attackers with file upload permissions to execute a path traversal and write arbitrary files w…

Remote | Path Traversal
Apr 30, 2026 Apr 30, 2026
Apr 30, 2026
Apr 30, 2026
4.3 MEDIUM
CVE-2026-36757 — Halo SSRF

A Server-Side Request Forgery (SSRF) in the /plugins/{name}/upgrade-from-uri endpoint of halo v2.22.14 allows authenticated attackers to scan internal resources via a crafted GET request.

Remote | Server-Side Request Forgery
Apr 30, 2026 Apr 30, 2026
Apr 30, 2026
Apr 30, 2026
Showing 20 of 5853 Results