Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
0.0 NA
CVE-2026-7853 — D-Link DI-8100 HTTP auto_reboot.asp sprintf buffer overflow

A weakness has been identified in D-Link DI-8100 16.07.26A1. Affected is the function sprintf of the file /auto_reboot.asp of the component HTTP Handler. This manipulation of the argument enable/time…

| Memory Corruption
May 05, 2026 May 05, 2026
May 05, 2026
May 05, 2026
0.0 NA
CVE-2026-7851 — D-Link DI-8100 yyxz.asp sprintf stack-based overflow

A vulnerability was identified in D-Link DI-8100 16.07.26A1. This affects the function sprintf of the file yyxz.asp. The manipulation of the argument ID leads to stack-based buffer overflow. The atta…

| Memory Corruption
May 05, 2026 May 05, 2026
May 05, 2026
May 05, 2026
2.6 LOW
CVE-2026-7847 — chatchat-space Langchain-Chatchat Uploaded File openai_routes.py _get_file_id random valu…

A vulnerability was found in chatchat-space Langchain-Chatchat up to 0.3.1.3. The affected element is the function _get_file_id of the file libs/chatchat-server/chatchat/server/api_server/openai_rout…

| Information Disclosure
May 05, 2026 May 05, 2026
May 05, 2026
May 05, 2026
5.3 MEDIUM
CVE-2026-43002 — OpenStack Horizon Session Storage Exhaustion

An issue was discovered in OpenStack Horizon 25.6 and 25.7 before 25.7.3. There is a write operation to the session storage backend before authentication and thus storage can be exhausted by unauthen…

Remote | Misconfiguration
May 05, 2026 May 05, 2026
May 05, 2026
May 05, 2026
0.0 NA
CVE-2026-38432 — ERPNext Cross Site Scripting (XSS) Vulnerability

ERPNext v15.103.1 and before is vulnerable to Cross Site Scripting (XSS) in the Email Template engine. An attacker with permission to create or edit email templates can inject malicious JavaScript co…

| Cross-Site Scripting
May 05, 2026 May 05, 2026
May 05, 2026
May 05, 2026
0.0 NA
CVE-2026-38431 — ERPNext SSTI

ERPNext v15.103.1 and before is vulnerable to Server-Side Template Injection (SSTI). An attacker with permission to create or edit email templates can inject template expressions that are executed on…

| Injection
May 05, 2026 May 05, 2026
May 05, 2026
May 05, 2026
0.0 NA
CVE-2026-38429 — OpenCMS XXE Injection

OpenCMS v20 and before is vulnerable to XML External Entity (XXE) in the Admin Import DB feature due to insecure XML parsing of user supplied .zip files containing a manifest.xml.

| XML External Entity
May 05, 2026 May 05, 2026
May 05, 2026
May 05, 2026
7.7 HIGH
CVE-2026-25589 — RedisBloom RESTORE invalid memory access may allow remote code execution

RedisBloom is a probabilistic data structures module for Redis. In all versions of RedisBloom before 2.8.20, the module does not properly validate serialized values processed through the Redis RESTOR…

Remote | Memory Corruption
May 05, 2026 May 05, 2026
May 05, 2026
May 05, 2026
7.7 HIGH
CVE-2026-25588 — RedisTimeSeries RESTORE invalid memory access may allow remote code execution

RedisTimeSeries is a time-series module for Redis. In all versions before 1.12.14 of RedisTimeSeries, the module does not properly validate serialized values processed through the Redis RESTORE comma…

Remote | Memory Corruption
May 05, 2026 May 05, 2026
May 05, 2026
May 05, 2026
7.7 HIGH
CVE-2026-25243 — redis-server RESTORE invalid memory access may allow remote code execution

Redis is an in-memory data structure store. In versions of redis-server up to 8.6.3, the RESTORE command does not properly validate serialized values. An authenticated attacker with permission to exe…

Remote | Memory Corruption
May 05, 2026 May 05, 2026
May 05, 2026
May 05, 2026
6.1 MEDIUM
CVE-2026-23631 — redis-server Lua use-after-free may allow remote code execution

Redis is an in-memory data structure store. In all versions of redis-server with Lua scripting, an authenticated attacker can exploit the master-replica synchronization mechanism to trigger a use-aft…

Remote | Memory Corruption
May 05, 2026 May 05, 2026
May 05, 2026
May 05, 2026
7.7 HIGH
CVE-2026-23479 — redis-server use-after-free in unblock client flow may allow remote code execution

Redis is an in-memory data structure store. In redis-server from 7.2.0 until 8.6.3, the unblock client flow does not handle an error return from `processCommandAndResetClient` when re-executing a blo…

Remote | Memory Corruption
May 05, 2026 May 05, 2026
May 05, 2026
May 05, 2026
7.4 HIGH
CVE-2026-7865 — Hidden Console Command

A hidden console command is vulnerable to command injection flaw when control characters are passed to its second argument.  A third party researcher Eugene Lim had discovered vulnerability in the w…

Remote | Injection
May 05, 2026 May 05, 2026
May 05, 2026
May 05, 2026
2.6 LOW
CVE-2026-7846 — chatchat-space Langchain-Chatchat OpenAI-Compatible File Upload API openai_routes.py file…

A vulnerability has been found in chatchat-space Langchain-Chatchat up to 0.3.1.3. Impacted is the function files of the file libs/chatchat-server/chatchat/server/api_server/openai_routes.py of the c…

| Path Traversal
May 05, 2026 May 05, 2026
May 05, 2026
May 05, 2026
2.6 LOW
CVE-2026-7845 — chatchat-space Langchain-Chatchat Vision Chat Paste Image dialogue.py PIL.Image.tobytes w…

A flaw has been found in chatchat-space Langchain-Chatchat up to 0.3.1.3. This issue affects the function PIL.Image.tobytes of the file libs/chatchat-server/chatchat/webui_pages/dialogue/dialogue.py …

| Cryptography
May 05, 2026 May 05, 2026
May 05, 2026
May 05, 2026
6.3 MEDIUM
CVE-2026-7844 — chatchat-space Langchain-Chatchat Compatible File Service openai_routes.py delete_file mi…

A vulnerability was detected in chatchat-space Langchain-Chatchat up to 0.3.1.3. This vulnerability affects the function files/list_files/retrieve_file/retrieve_file_content/delete_file of the file l…

| Authentication
May 05, 2026 May 05, 2026
May 05, 2026
May 05, 2026
8.6 HIGH
CVE-2026-7412 — Eclipse BaSyx Java Server SDK Blind HTTP Request Forgery

In Eclipse BaSyx Java Server SDK versions prior to 2.0.0-milestone-10, the Operation Delegation feature fails to validate the destination URI of delegated requests. An unauthenticated remote attacker…

Remote | Server-Side Request Forgery
May 05, 2026 May 05, 2026
May 05, 2026
May 05, 2026
10.0 CRITICAL
CVE-2026-7411 — Eclipse BaSyx Java Server SDK Remote Code Execution (RCE) via Path Traversal

In Eclipse BaSyx Java Server SDK versions prior to 2.0.0-milestone-10, inadequate path normalization in the Submodel HTTP API allows an unauthenticated remote attacker to perform a path traversal att…

Remote | Path Traversal
May 05, 2026 May 05, 2026
May 05, 2026
May 05, 2026
4.3 MEDIUM
CVE-2026-6907 — Potential exposure of private data due to incorrect handling of Vary: * in UpdateCacheMid…

An issue was discovered in 6.0 before 6.0.5 and 5.2 before 5.2.14. `django.middleware.cache.UpdateCacheMiddleware` erroneously caches requests where the `Vary` header contained an asterisk (`'*'`). T…

Remote | Information Disclosure
May 05, 2026 May 05, 2026
May 05, 2026
May 05, 2026
6.3 MEDIUM
CVE-2026-5766 — Potential denial-of-service vulnerability in ASGI requests via file upload limit bypass

An issue was discovered in 6.0 before 6.0.5 and 5.2 before 5.2.14. ASGI requests with a missing or understated `Content-Length` header can bypass the `FILE_UPLOAD_MAX_MEMORY_SIZE` limit, potentially …

Remote | Denial of Service
May 05, 2026 May 05, 2026
May 05, 2026
May 05, 2026
Showing 20 of 5699 Results