Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
5.5 MEDIUM
CVE-2026-5475 — NASA cFS CCSDS Header Size cfe_sb_priv.c CFE_SB_TransmitMsg memory corruption

A vulnerability was determined in NASA cFS up to 7.0.0. This impacts the function CFE_SB_TransmitMsg of the file cfe_sb_priv.c of the component CCSDS Header Size Handler. Executing a manipulation can…

cfs | Memory Corruption
Apr 03, 2026 Apr 07, 2026
Apr 03, 2026
Apr 07, 2026
10.0 CRITICAL
CVE-2026-32186 — Microsoft Bing Elevation of Privilege Vulnerability

Server-side request forgery (ssrf) in Microsoft Bing allows an unauthorized attacker to elevate privileges over a network.

bing | Remote
Apr 03, 2026 Apr 13, 2026
Apr 03, 2026
Apr 13, 2026
9.8 CRITICAL
CVE-2026-0545 — Missing Authentication for Critical Function in mlflow/mlflow

In mlflow/mlflow, the FastAPI job endpoints under `/ajax-api/3.0/jobs/*` are not protected by authentication or authorization when the `basic-auth` app is enabled. This vulnerability affects the late…

mlflow | Remote | Authentication
Apr 03, 2026 Apr 21, 2026
Apr 03, 2026
Apr 21, 2026
8.8 HIGH
CVE-2026-5474 — NASA cFS CCSDS Packet Header to_lab_passthru_encode.c CFE_MSG_GetSize heap-based overflow

A vulnerability was found in NASA cFS up to 7.0.0. This affects the function CFE_MSG_GetSize of the file apps/to_lab/fsw/src/to_lab_passthru_encode.c of the component CCSDS Packet Header Handler. Per…

cfs core_flight_system | Memory Corruption
Apr 03, 2026 Apr 30, 2026
Apr 03, 2026
Apr 30, 2026
7.0 HIGH
CVE-2026-5473 — NASA cFS Pickle pickle.load deserialization

A vulnerability has been found in NASA cFS up to 7.0.0. The impacted element is the function pickle.load of the component Pickle Module. Such manipulation leads to deserialization. The attack needs t…

cfs core_flight_system | Injection
Apr 03, 2026 Apr 30, 2026
Apr 03, 2026
Apr 30, 2026
9.6 CRITICAL
CVE-2026-28373 — Stackfield Desktop App Path Traversal Vulnerability

The Stackfield Desktop App before 1.10.2 for macOS and Windows contains a path traversal vulnerability in certain decryption functionality when processing the filePath property. A malicious export ca…

Remote | Path Traversal
Apr 03, 2026 Apr 07, 2026
Apr 03, 2026
Apr 07, 2026
Showing 20 of 5566 Results