Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.2 HIGH
CVE-2026-41471 — Easy PayPal Events & Tickets 1.3 Information Disclosure via QR Code Endpoint

Easy PayPal Events & Tickets plugin for WordPress versions 1.3 and earlier contain an information disclosure vulnerability in the QR code scanning endpoint that allows unauthenticated attackers to en…

Remote | Information Disclosure
May 04, 2026 May 04, 2026
May 04, 2026
May 04, 2026
8.7 HIGH
CVE-2026-32834 — Easy PayPal Events & Tickets 1.3 Authentication Bypass via QR Code Scanning

Easy PayPal Events & Tickets plugin for WordPress version 1.3 and earlier contain a hardcoded authentication bypass vulnerability in the QR code scanning functionality that allows unauthenticated rem…

Remote | Authentication
May 04, 2026 May 04, 2026
May 04, 2026
May 04, 2026
0.0 NA
CVE-2026-42140 — Server-Side Request Forgery (SSRF) in PlantUML Macro via 'server' parameter

PlantUML Macro is a macro for rendering UML diagrams from simple textual schemes. Prior to version 2.4.1, the PlantUML Macro is vulnerable to Server-Side Request Forgery (SSRF). The macro allows user…

| Server-Side Request Forgery
May 04, 2026 May 04, 2026
May 04, 2026
May 04, 2026
0.0 NA
CVE-2026-42138 — Dify Vulnerable to Stored XSS via SVG-file upload

Dify is an open-source LLM app development platform. Prior to version 1.13.1, using the method POST /api/files/upload, any unauthenticated user can upload an SVG file with XSS. The method POST /v1/fi…

| Cross-Site Scripting
May 04, 2026 May 04, 2026
May 04, 2026
May 04, 2026
7.1 HIGH
CVE-2026-43616 — Detect-It-Easy < 3.21 Path Traversal Arbitrary File Write

Detect-It-Easy prior to 3.21 contains a path traversal vulnerability that allows attackers to write arbitrary files to the filesystem by crafting malicious archive entries with relative traversal seq…

| Path Traversal
May 04, 2026 May 04, 2026
May 04, 2026
May 04, 2026
0.0 NA
CVE-2026-42092 — Global Settings Publication Exposes Sensitive Configuration to Any Authenticated User in …

titra is an open source time tracking project. In version 0.99.52, the globalsettings Meteor publication returns all global settings without any admin or role check. Any authenticated user can subscr…

| Information Disclosure
May 04, 2026 May 04, 2026
May 04, 2026
May 04, 2026
0.0 NA
CVE-2026-42091 — goshs has Cross-Origin Arbitrary File Write via Missing CSRF on PUT and Wildcard CORS

goshs is a SimpleHTTPServer written in Go. Prior to version 2.0.2, the PUT upload handler (httpserver/updown.go) lacks the CSRF token validation that was added to the POST upload handler during the C…

| Cross-Site Request Forgery
May 04, 2026 May 04, 2026
May 04, 2026
May 04, 2026
0.0 NA
CVE-2026-42088 — OpenC3 COSMOS: Administrative Actions via the Script Runner Tool

OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. Prior to version 7.0.0-rc3, the Script Runner widget allows users to execute Py…

| Authorization
May 04, 2026 May 04, 2026
May 04, 2026
May 04, 2026
9.8 CRITICAL
CVE-2026-42796 — Arelle < 2.39.10 Unauthenticated RCE via /rest/configure

Arelle before 2.39.10 contains an unauthenticated remote code execution vulnerability in the /rest/configure REST endpoint that accepts a plugins query parameter and forwards it to the plugin manager…

Remote | Authentication
May 04, 2026 May 04, 2026
May 04, 2026
May 04, 2026
0.0 NA
CVE-2026-42087 — OpenC3 COSMOS: SQL Injection in QuestDB Time-Series Data Base

OpenC3 COSMOS provides the functionality needed to send commands to and receive data from one or more embedded systems. From version 6.7.0 to before version 7.0.0-rc3, a SQL injection vulnerability e…

| Injection
May 04, 2026 May 04, 2026
May 04, 2026
May 04, 2026
9.9 CRITICAL
CVE-2026-42812 — Apache Polaris: No protection on `write.metadata.path`

In Apache Iceberg, the table's metadata files are control files: they tell readers which data files belong to the table and which table version to read. `write.metadata.path` is an optional table …

Remote | Misconfiguration
May 04, 2026 May 04, 2026
May 04, 2026
May 04, 2026
9.9 CRITICAL
CVE-2026-42811 — Apache Polaris: could broaden vended GCS credentials through unescaped identifier content…

In plain terms, Apache Polaris is supposed to issue short-lived GCS credentials that only work for one table's files, but a crafted namespace or table name can cause those credentials to work across …

Remote | Authorization
May 04, 2026 May 04, 2026
May 04, 2026
May 04, 2026
9.9 CRITICAL
CVE-2026-42810 — Apache Polaris: could broaden vended S3 credentials through wildcard-bearing namespace or…

Apache Polaris accepts literal `*` characters in namespace and table names. When it later builds temporary S3 access policies for delegated table access, those same characters appear to be reused une…

Remote | Authorization
May 04, 2026 May 04, 2026
May 04, 2026
May 04, 2026
9.9 CRITICAL
CVE-2026-42809 — Apache Polaris: staged table creation could vend storage credentials for unvalidated loca…

Apache Polaris can issue broad temporary ("vended") storage credentials during staged table creation before the effective table location has been validated or durably reserved. Those temporary crede…

Remote | Misconfiguration
May 04, 2026 May 04, 2026
May 04, 2026
May 04, 2026
0.0 NA
CVE-2026-42440 — Apache OpenNLP: OOM DoS via Unbounded Array Allocation in AbstractModelReader

OOM Denial of Service via Unbounded Array Allocation in Apache OpenNLP AbstractModelReader  Versions Affected:  before 2.5.9 before 3.0.0-M3  Description: The AbstractModelReader methods getOut…

| Denial of Service
May 04, 2026 May 04, 2026
May 04, 2026
May 04, 2026
9.8 CRITICAL
CVE-2026-42376 — D-Link DIR-456U A1 Hardcoded Telnet Backdoor Credentials

D-Link DIR-456U Hardware Revision A1 (End-of-Life, EOL) contains a hardcoded telnet backdoor. The device starts a telnet daemon at boot via /etc/init0.d/S80telnetd.sh with the username "Alphanetworks…

Remote | Authentication
May 04, 2026 May 04, 2026
May 04, 2026
May 04, 2026
9.8 CRITICAL
CVE-2026-42375 — D-Link DIR-600L A1 Hardcoded Telnet Backdoor Credentials

D-Link DIR-600L Hardware Revision A1 (End-of-Life) contains a hardcoded telnet backdoor. The device starts a telnet daemon at boot via /bin/telnetd.sh with the username "Alphanetworks" and the static…

Remote | Authentication
May 04, 2026 May 04, 2026
May 04, 2026
May 04, 2026
9.8 CRITICAL
CVE-2026-42374 — D-Link DIR-600L B1 Hardcoded Telnet Backdoor Credentials

D-Link DIR-600L Hardware Revision B1 (End-of-Life) contains a hardcoded telnet backdoor. The device starts a telnet daemon at boot via /bin/telnetd.sh with the username "Alphanetworks" and the static…

Remote | Authentication
May 04, 2026 May 04, 2026
May 04, 2026
May 04, 2026
9.8 CRITICAL
CVE-2026-42373 — D-Link DIR-605L B2 Hardcoded Telnet Backdoor Credentials

D-Link DIR-605L Hardware Revision B2 (End-of-Life, EOL) contains a hardcoded telnet backdoor. The device starts a telnet daemon at boot via /bin/telnetd.sh with the username "Alphanetworks" and the s…

Remote | Authentication
May 04, 2026 May 04, 2026
May 04, 2026
May 04, 2026
8.8 HIGH
CVE-2026-42372 — D-Link DIR-605L A1 Hardcoded Telnet Backdoor Credentials

D-Link DIR-605L Hardware Revision A1 (End-of-Life, EOL) contains a hardcoded telnet backdoor. The device starts a telnet daemon at boot via /bin/telnetd.sh with the username "Alphanetworks" and the s…

| Authentication
May 04, 2026 May 04, 2026
May 04, 2026
May 04, 2026
Showing 20 of 5570 Results