Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.5 HIGH
CVE-2026-7736 — osrg GoBGP mrt.go parseRibEntry integer underflow

A vulnerability was determined in osrg GoBGP up to 4.3.0. Affected by this vulnerability is the function parseRibEntry of the file pkg/packet/mrt/mrt.go. Executing a manipulation can lead to integer …

Remote | Memory Corruption
May 04, 2026 May 04, 2026
May 04, 2026
May 04, 2026
0.0 NA
CVE-2026-5335 — Magic Export & Import < 1.2.0 - Unauthenticated PII Disclosure

The Magic Export & Import WordPress plugin before 1.2.0 stores exported CSV files at a publicly accessible location, making it possible for any visitors to leak sensitive user information.

| Information Disclosure
May 04, 2026 May 04, 2026
May 04, 2026
May 04, 2026
2.5 LOW
CVE-2026-43864 — Mutt NULL Pointer Dereference Vulnerability

mutt before 2.3.2 has a show_sig_summary NULL pointer dereference.

| Memory Corruption
May 04, 2026 May 04, 2026
May 04, 2026
May 04, 2026
3.7 LOW
CVE-2026-43863 — Mutt GPGME Infinite Loop Vulnerability

mutt before 2.3.2 has an infinite loop in data_object_to_stream in crypt-gpgme.c.

Remote | Denial of Service
May 04, 2026 May 04, 2026
May 04, 2026
May 04, 2026
3.7 LOW
CVE-2026-43862 — Mutt IMAP GSS Mishandling Vulnerability

In mutt before 2.3.2, the imap_auth_gss security level is mishandled.

Remote | Authentication
May 04, 2026 May 04, 2026
May 04, 2026
May 04, 2026
3.7 LOW
CVE-2026-43861 — Mutt URL Decode Buffer Overflow Vulnerability

mutt before 2.3.2 does not check for '\0' in url_pct_decode.

Remote | Misconfiguration
May 04, 2026 May 04, 2026
May 04, 2026
May 04, 2026
3.7 LOW
CVE-2026-43860 — Mutt IMAP Auth Cram MD5 Hash Truncation Vulnerability

mutt before 2.3.2 sometimes truncates the hash_passwd by one byte for IMAP auth_cram MD5 digest.

Remote | Cryptography
May 04, 2026 May 04, 2026
May 04, 2026
May 04, 2026
3.7 LOW
CVE-2026-43859 — Mutt IMAP Auth Cram MD5 Buffer Overflow

mutt before 2.3.2 sometimes uses strfcpy instead of memcpy for the IMAP auth_cram MD5 digest.

Remote | Cryptography
May 04, 2026 May 04, 2026
May 04, 2026
May 04, 2026
9.9 CRITICAL
CVE-2026-29200 — Comet Backup Tenant Impersonation IDOR

A critical IDOR vulnerability has been discovered in Comet Backup affecting all versions from 20.11.0 to 26.1.1 and 26.2.1. The vulnerability allows a tenant administrator to impersonate any end-user…

Remote | Authorization
May 04, 2026 May 04, 2026
May 04, 2026
May 04, 2026
0.0 NA
CVE-2026-29199 — phpBB Host Header Injection Vulnerability

phpBB before 3.3.16 is vulnerable to Host Header Injection that can lead to password rest link poisoning. When force_server_vars is disabled, the servers hostname may be extracted from the HTTP Host …

| Misconfiguration
May 04, 2026 May 04, 2026
May 04, 2026
May 04, 2026
0.0 NA
CVE-2026-20451 — Samsung Linux Base Console (SLBC) Type Confusion Out-of-Bounds Write Vulnerability

In slbc, there is a possible out of bounds write due to type confusion. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interacti…

| Memory Corruption
May 04, 2026 May 04, 2026
May 04, 2026
May 04, 2026
0.0 NA
CVE-2026-20450 — "Huawei Modem Remote Denial of Service Vulnerability"

In Modem, there is a possible system crash due to incorrect error handling. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with…

| Denial of Service
May 04, 2026 May 04, 2026
May 04, 2026
May 04, 2026
0.0 NA
CVE-2026-20449 — "Modem HEAP Buffer Overflow Vulnerability"

In Modem, there is a possible system crash due to a heap buffer overflow. This could lead to remote denial of service, if a UE has connected to a rogue base station controlled by the attacker, with n…

| Memory Corruption
May 04, 2026 May 04, 2026
May 04, 2026
May 04, 2026
0.0 NA
CVE-2026-20448 — Geniezone Missing Permission Check Privilege Escalation Vulnerability

In geniezone, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege if a malicious actor has already obtained the System priv…

| Authorization
May 04, 2026 May 04, 2026
May 04, 2026
May 04, 2026
0.0 NA
CVE-2026-20447 — Geniezone Privilege Escalation Vulnerability

In geniezone, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privileg…

| Memory Corruption
May 04, 2026 May 04, 2026
May 04, 2026
May 04, 2026
7.5 HIGH
CVE-2026-7735 — osrg GoBGP AIGP Attribute bgp.go PathAttributeAigp.DecodeFromBytes buffer overflow

A vulnerability was found in osrg GoBGP up to 4.3.0. Affected is the function PathAttributeAigp.DecodeFromBytes of the file pkg/packet/bgp/bgp.go of the component AIGP Attribute Parser. Performing a …

Remote | Memory Corruption
May 04, 2026 May 04, 2026
May 04, 2026
May 04, 2026
6.9 MEDIUM
CVE-2026-7734 — osrg GoBGP SRv6 L3 Service prefix_sid.go SRv6L3ServiceAttribute.DecodeFromBytes denial of…

A vulnerability has been found in osrg GoBGP up to 4.3.0. This impacts the function SRv6L3ServiceAttribute.DecodeFromBytes of the file pkg/packet/bgp/prefix_sid.go of the component SRv6 L3 Service. S…

Remote | Denial of Service
May 04, 2026 May 04, 2026
May 04, 2026
May 04, 2026
7.5 HIGH
CVE-2026-7733 — funadmin Frontend Chunked Upload Endpoint UploadService.php chunkUpload unrestricted uplo…

A flaw has been found in funadmin up to 7.1.0-rc6. This affects the function UploadService::chunkUpload of the file app/common/service/UploadService.php of the component Frontend Chunked Upload Endpo…

Remote | Misconfiguration
May 04, 2026 May 04, 2026
May 04, 2026
May 04, 2026
6.5 MEDIUM
CVE-2026-7732 — code-projects BloodBank Managing System request_blood.php unrestricted upload

A vulnerability was detected in code-projects BloodBank Managing System 1.0. The impacted element is an unknown function of the file request_blood.php. The manipulation results in unrestricted upload…

Remote | Misconfiguration
May 04, 2026 May 04, 2026
May 04, 2026
May 04, 2026
6.5 MEDIUM
CVE-2026-7731 — code-projects BloodBank Managing System get_state.php sql injection

A security vulnerability has been detected in code-projects BloodBank Managing System 1.0. The affected element is an unknown function of the file get_state.php. The manipulation of the argument G_ST…

Remote | Injection
May 04, 2026 May 04, 2026
May 04, 2026
May 04, 2026
Showing 20 of 5524 Results