Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.0 MEDIUM
CVE-2026-41195 — mosparo: Rule package source URL stored SSRF enables internal HTTP probing

mosparo is the modern solution to protect your online forms from spam. Prior to 1.4.13, the automatic rule package source URL feature allows a project member with the editor role to store an attacker…

mosparo | Remote | Server-Side Request Forgery
May 12, 2026 May 18, 2026
May 12, 2026
May 18, 2026
7.5 HIGH
CVE-2026-40902 — PhpSpreadsheet: CPU Denial of Service via Unbounded Row Number in XLSX Row Dimensions

PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. Prior to 1.30.4, 2.1.16, 2.4.5, 3.10.5, and 5.7.0, the XLSX reader's ColumnAndRowAttributes::readRowAttributes() method…

phpspreadsheet | Remote | Denial of Service
May 12, 2026 May 14, 2026
May 12, 2026
May 14, 2026
7.5 HIGH
CVE-2026-40863 — PhpSpreadsheet: CPU Denial of Service via Unbounded Row Index in SpreadsheetML XML Reader

PhpSpreadsheet is a pure PHP library for reading and writing spreadsheet files. Prior to 1.30.4, 2.1.16, 2.4.5, 3.10.5, and 5.7.0, the SpreadsheetML XML reader (Reader\Xml) does not validate the ss:I…

phpspreadsheet | Remote | Denial of Service
May 12, 2026 May 13, 2026
May 12, 2026
May 13, 2026
7.0 HIGH
CVE-2026-35555 — Subnet Solutions PowerSYSTEM Center Incorrect Authorization

PowerSYSTEM Center feature for device project groups allows an authenticated user with limited permissions to perform an unauthorized deletion of project groups.

| Authorization
May 12, 2026 May 13, 2026
May 12, 2026
May 13, 2026
6.9 MEDIUM
CVE-2026-33570 — Subnet Solutions PowerSYSTEM Center Incorrect Authorization

PowerSYSTEM Center REST API endpoint for devices allows a low privilege authenticated user to access information normally limited by operational permissions.

| Authorization
May 12, 2026 May 13, 2026
May 12, 2026
May 13, 2026
8.4 HIGH
CVE-2026-26289 — Subnet Solutions PowerSYSTEM Center Incorrect Authorization

PowerSYSTEM Center REST API endpoint for device account export allows an authenticated user with limited permissions to expose sensitive information normally restricted to administrative permissions …

| Authorization
May 12, 2026 May 13, 2026
May 12, 2026
May 13, 2026
Showing 20 of 7106 Results