Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.0 MEDIUM
CVE-2026-22726 — Route Services Firewall Bypass

Route Services can be leveraged to send app traffic to network destinations outside of an app's configured egress rules. As a result, a malicious developer with access to Cloudfoundry could configure…

Remote | Server-Side Request Forgery
May 01, 2026 May 01, 2026
May 01, 2026
May 01, 2026
0.0 NA
CVE-2026-37504 — V2Board Server Token Exposure

Sensitive server_token exposed via GET parameter in V2Board thru 1.7.4. In app/Http/Controllers/Server/UniProxyController.php, the server authentication token is accepted via GET parameter transmissi…

| Information Disclosure
May 01, 2026 May 01, 2026
May 01, 2026
May 01, 2026
0.0 NA
CVE-2026-42480 — Open CASCADE Technology (OCCT) VRML Parser Stack-Based Out-of-Bounds Read Denial of Servi…

A stack-based out-of-bounds read vulnerability in VrmlData_Scene::ReadLine in the VRML parser in Open CASCADE Technology (OCCT) V8_0_0_rc5 allows attackers to cause a denial of service via a crafted …

| Memory Corruption
May 01, 2026 May 01, 2026
May 01, 2026
May 01, 2026
0.0 NA
CVE-2026-42481 — Open CASCADE Technology (OCCT) Geometry Library IGES/STEP File Parsing vulnerabilities

Open CASCADE Technology (OCCT) V8_0_0_rc5 contains multiple vulnerabilities in its IGES and STEP file parsers that can be triggered by crafted IGES or STEP files. These issues include an out-of-bound…

| Memory Corruption
May 01, 2026 May 01, 2026
May 01, 2026
May 01, 2026
0.0 NA
CVE-2026-37503 — V2Board XSS

Cross-Site Scripting (XSS) in V2Board thru 1.7.4. The custom_html field in theme configuration is rendered using Blade unescaped output in public/theme/v2board/dashboard.blade.php. An admin can injec…

| Cross-Site Scripting
May 01, 2026 May 01, 2026
May 01, 2026
May 01, 2026
6.5 MEDIUM
CVE-2026-7510 — OWAP DefectDojo Benchmark/Engagement/Product/Survey authorization

A vulnerability was determined in OWAP DefectDojo up to 2.55.4. Affected by this vulnerability is an unknown functionality of the component Benchmark/Engagement/Product/Survey. Executing a manipulati…

Remote | Authorization
Apr 30, 2026 May 01, 2026
Apr 30, 2026
May 01, 2026
6.5 MEDIUM
CVE-2026-7508 — Bootstrap CMS Page Creation show.blade.php code injection

A vulnerability was found in Bootstrap CMS 0.9.0-alpha. Affected is an unknown function of the file resources/views/pages/show.blade.php of the component Page Creation Handler. Performing a manipulat…

Remote | Injection
Apr 30, 2026 May 01, 2026
Apr 30, 2026
May 01, 2026
7.5 HIGH
CVE-2026-7506 — SourceCodester Hotel Management System check sql injection

A vulnerability has been found in SourceCodester Hotel Management System 1.0. This impacts an unknown function of the file /index.php/reservation/check. Such manipulation of the argument room_type le…

hotel_management_system | Remote | Injection
Apr 30, 2026 May 01, 2026
Apr 30, 2026
May 01, 2026
7.5 HIGH
CVE-2026-7505 — nextlevelbuilder GoClaw/GoClaw Lite RPC improper authorization

A flaw has been found in nextlevelbuilder GoClaw and GoClaw Lite up to 3.8.5. This affects an unknown function of the component RPC Handler. This manipulation causes improper authorization. The attac…

Remote | Authorization
Apr 30, 2026 May 01, 2026
Apr 30, 2026
May 01, 2026
6.5 MEDIUM
CVE-2026-28909 — Apache Container Registry Unauthenticated Registry Credentials Exposure

Users who connect to malicious registries with hostnames matching the bypass patterns will have their registry credentials exposed in plaintext. This issue is fixed in container version 0.12.3.

macos | Remote | Misconfiguration
Apr 30, 2026 May 01, 2026
Apr 30, 2026
May 01, 2026
8.8 HIGH
CVE-2026-7551 — HKUDS OpenHarness Remote Command Execution via /bridge Slash Command

HKUDS OpenHarness contains a remote code execution vulnerability in the /bridge slash command that allows remote senders accepted by configuration to execute arbitrary operating system commands. Atta…

openharness | Remote | Injection
Apr 30, 2026 May 01, 2026
Apr 30, 2026
May 01, 2026
9.0 HIGH
CVE-2026-7503 — code-projects for Plugin cstecgi.cgi setWiFiMultipleConfig buffer overflow

A vulnerability was detected in code-projects for Plugin 4.1.2cu.5137. The impacted element is the function setWiFiMultipleConfig in the library /lib/cste_modules/wireless.so of the file /cgi-bin/cst…

online_music_site | Remote | Memory Corruption
Apr 30, 2026 May 01, 2026
Apr 30, 2026
May 01, 2026
5.5 MEDIUM
CVE-2026-7502 — LinkStackOrg LinkStack Management Endpoint UserController.php saveLink authorization

A security vulnerability has been detected in LinkStackOrg LinkStack up to 4.8.6. The affected element is the function saveLink of the file app/Http/Controllers/UserController.php of the component Ma…

Remote | Authorization
Apr 30, 2026 May 01, 2026
Apr 30, 2026
May 01, 2026
8.8 HIGH
CVE-2026-6543 — Authenticated Remote Code Execution Vulnerability in Langflow Code Validation Endpoint

IBM Langflow Desktop 1.0.0 through 1.8.4 Langflow allows an attacker to execute arbitrary commands with the privileges of the process running Langflow. This allows reading sensitive environment varia…

langflow_desktop | Remote | Injection
Apr 30, 2026 May 01, 2026
Apr 30, 2026
May 01, 2026
6.5 MEDIUM
CVE-2026-6542 — Monitor API allows cross-user read of transaction logs and deletion of build data via flo…

IBM Langflow OSS 1.0.0 through 1.8.4 could allow any user to supply a flow_id to read transaction logs and vertex build data belonging to other users, and to delete persisted vertex build data for an…

langflow_oss | Remote | Authorization
Apr 30, 2026 May 01, 2026
Apr 30, 2026
May 01, 2026
8.8 HIGH
CVE-2026-6389 — IBM Turbonomic Prometurbo agent used by IBM Turbonomic Application Resource Management is…

IBM Turbonomic prometurbo agent 8.16.0 through 8.17.6 IBM Turbonomic Application Resource Management grants excessive cluster‑wide permissions, including unrestricted read access to all secrets. An a…

turbonomic_prometurbo_agent | Authorization
Apr 30, 2026 May 01, 2026
Apr 30, 2026
May 01, 2026
4.8 MEDIUM
CVE-2026-40687 — Exim SPA Authentication Driver Uninitialized Memory Disclosure

In Exim before 4.99.2, when the SPA authentication driver is used with an adversarial SPA resource, there can be an out-of-bounds write that crashes the connection instance, or erroneous data process…

exim | Remote | Memory Corruption
Apr 30, 2026 May 01, 2026
Apr 30, 2026
May 01, 2026
3.7 LOW
CVE-2026-40686 — Exim UTF-8 Out-of-Bounds Read Information Disclosure

In Exim before 4.99.2, when utf8 operators are enabled, there is an out-of-bounds read if large UTF-8 trailing characters are present (malformed UTF-8 header data). Information might be divulged with…

exim | Remote | Information Disclosure
Apr 30, 2026 May 01, 2026
Apr 30, 2026
May 01, 2026
6.5 MEDIUM
CVE-2026-40685 — Exim JSON Heap Write Vulnerability

In Exim before 4.99.2, when JSON lookup is enabled, an out-of-bounds heap write can occur when a JSON operator encounters malformed JSON in an untrusted header, because of an incorrect implementation…

exim | Remote | Memory Corruption
Apr 30, 2026 May 01, 2026
Apr 30, 2026
May 01, 2026
5.9 MEDIUM
CVE-2026-40684 — Exim DNS Record Processing Denial of Service

In Exim before 4.99.2, on systems using musl libc (not glibc), an attacker can crash the connection instance when malformed DNS data is present in PTR records. This is caused by a dn_expand oddity in…

exim | Remote | Denial of Service
Apr 30, 2026 May 01, 2026
Apr 30, 2026
May 01, 2026
Showing 20 of 5916 Results