Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
7.5 HIGH
CVE-2026-42561 — Python-Multipart: Denial of Service via unbounded multipart part headers

Python-Multipart is a streaming multipart parser for Python. Prior to 0.0.27, python-multipart has a denial of service vulnerability in multipart part header parsing. When parsing multipart/form-data…

python-multipart | Remote | Denial of Service
May 13, 2026 May 14, 2026
May 13, 2026
May 14, 2026
7.5 HIGH
CVE-2026-42304 — Twisted: Denial of Service (DoS) in twisted.names via Crafted DNS Compression Pointer Cha…

Twisted is an event-based framework for internet applications, supporting Python 3.6+. Prior to 26.4.0rc2, the twisted.names module is vulnerable to a Denial of Service (DoS) attack via resource exha…

twisted | Remote | Denial of Service
May 13, 2026 May 19, 2026
May 13, 2026
May 19, 2026
4.8 MEDIUM
CVE-2026-39428 — CubeCart: Stored Cross-Site Scripting (XSS)

CubeCart is an ecommerce software solution. Prior to 6.6.0, a Stored Cross-Site Scripting (XSS) vulnerability exists in CubeCart v6.x. An attacker with administrative privileges can inject malicious …

cubecart | Remote | Cross-Site Scripting
May 13, 2026 May 14, 2026
May 13, 2026
May 14, 2026
7.2 HIGH
CVE-2026-39358 — CubeCart: Time-based Blind SQL Injection

CubeCart is an ecommerce software solution. Prior to 6.6.0, Authenticated Time-Based Blind SQL Injection vulnerabilities were identified in the sorting parameters (sort[price], sort_activity, sort_ad…

cubecart | Remote | Injection
May 13, 2026 May 14, 2026
May 13, 2026
May 14, 2026
8.3 HIGH
CVE-2026-21821 — HCL BigFix SCM Reporting is affected by vulnerabilities in jQuery

The HCL BigFix SCM Reporting site contains an outdated and unsupported version of the jQuery 1.x library. Since jQuery 1.x has reached end-of-life and no longer receives security updates, it may expo…

Remote | Cross-Site Scripting
May 13, 2026 May 14, 2026
May 13, 2026
May 14, 2026
7.3 HIGH
CVE-2025-27853 — Garmin WDU Authentication Bypass Vulnerability

The locally served web site on the Garmin WDU (v1 1.4.6 and v2 5.0) allows its authentication to be bypassed. The WDU web site only performs authentication with the client within the client's browser…

May 13, 2026 Jun 02, 2026
May 13, 2026
Jun 02, 2026
5.0 MEDIUM
CVE-2025-27852 — Garmin WDU Reflected Cross-Site Scripting Vulnerability

The locally served web site on the Garmin WDU (v1 1.4.6 and v2 5.0) allows a reflected cross site scripting (XSS) attack. This allows an attacker on the local network segment to execute arbitrary Jav…

May 13, 2026 Jun 02, 2026
May 13, 2026
Jun 02, 2026
9.3 CRITICAL
CVE-2025-27851 — Garmin WDU Cross-Site Origin WebSocket Hijacking

The locally served web site on the Garmin WDU (v1 1.4.6 and v2 5.0) allows a cross-site origin WebSocket hijacking attack. Among other uses, the WDU utilizes WebSockets to control settings, including…

May 13, 2026 Jun 02, 2026
May 13, 2026
Jun 02, 2026
7.5 HIGH
CVE-2025-27850 — Garmin WDU Symlink File Disclosure

The locally served web site on the Garmin WDU (v1 1.4.6 and v2 5.0) allows a symlink attack. If a malicious graphics package containing symlinks is uploaded, the web server follows the supplied links…

May 13, 2026 Jun 02, 2026
May 13, 2026
Jun 02, 2026
Showing 20 of 6989 Results