Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.2 HIGH
CVE-2026-30923 — libModSecurity3 denial of service via segfault when using t:hexDecode on single-character…

ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. Libmodsecurity is one component of the ModSecurity v3 project. A segmentation fault occu…

modsecurity | Remote | Denial of Service
May 05, 2026 May 07, 2026
May 05, 2026
May 07, 2026
9.8 CRITICAL
CVE-2026-27960 — OpenCTI privilege escalation and unauthenticated access via default admin account

OpenCTI is an open source platform for managing cyber threat intelligence knowledge and observables. In versions 6.6.0 through 6.9.12, there is a privilege escalation vulnerability that can be exploi…

opencti | Remote | Authorization
May 05, 2026 May 07, 2026
May 05, 2026
May 07, 2026
10.0 HIGH
CVE-2026-7853 — D-Link DI-8100 HTTP auto_reboot.asp sprintf buffer overflow

A weakness has been identified in D-Link DI-8100 16.07.26A1. Affected is the function sprintf of the file /auto_reboot.asp of the component HTTP Handler. This manipulation of the argument enable/time…

di-8100_firmware di-8100 | Remote | Memory Corruption
May 05, 2026 May 06, 2026
May 05, 2026
May 06, 2026
8.3 HIGH
CVE-2026-7851 — D-Link DI-8100 yyxz.asp sprintf stack-based overflow

A vulnerability was identified in D-Link DI-8100 16.07.26A1. This affects the function sprintf of the file yyxz.asp. The manipulation of the argument ID leads to stack-based buffer overflow. The atta…

di-8100_firmware di-8100 | Remote | Memory Corruption
May 05, 2026 May 06, 2026
May 05, 2026
May 06, 2026
2.6 LOW
CVE-2026-7847 — chatchat-space Langchain-Chatchat Uploaded File openai_routes.py _get_file_id random valu…

A vulnerability was found in chatchat-space Langchain-Chatchat up to 0.3.1.3. The affected element is the function _get_file_id of the file libs/chatchat-server/chatchat/server/api_server/openai_rout…

langchain-chatchat | Information Disclosure
May 05, 2026 May 05, 2026
May 05, 2026
May 05, 2026
5.3 MEDIUM
CVE-2026-43002 — OpenStack Horizon Session Storage Exhaustion

An issue was discovered in OpenStack Horizon 25.6 and 25.7 before 25.7.3. There is a write operation to the session storage backend before authentication and thus storage can be exhausted by unauthen…

horizon horizon | Remote | Misconfiguration
May 05, 2026 May 07, 2026
May 05, 2026
May 07, 2026
6.1 MEDIUM
CVE-2026-38432 — ERPNext Cross Site Scripting (XSS) Vulnerability

ERPNext v15.103.1 and before is vulnerable to Cross Site Scripting (XSS) in the Email Template engine. An attacker with permission to create or edit email templates can inject malicious JavaScript co…

erpnext | Remote | Cross-Site Scripting
May 05, 2026 May 08, 2026
May 05, 2026
May 08, 2026
9.8 CRITICAL
CVE-2026-38431 — ERPNext SSTI

ERPNext v15.103.1 and before is vulnerable to Server-Side Template Injection (SSTI). An attacker with permission to create or edit email templates can inject template expressions that are executed on…

erpnext | Remote | Injection
May 05, 2026 May 08, 2026
May 05, 2026
May 08, 2026
9.8 CRITICAL
CVE-2026-38429 — OpenCMS XXE Injection

OpenCMS v20 and before is vulnerable to XML External Entity (XXE) in the Admin Import DB feature due to insecure XML parsing of user supplied .zip files containing a manifest.xml.

Remote | XML External Entity
May 05, 2026 May 06, 2026
May 05, 2026
May 06, 2026
8.8 HIGH
CVE-2026-25589 — RedisBloom RESTORE invalid memory access may allow remote code execution

RedisBloom is a probabilistic data structures module for Redis. In all versions of RedisBloom before 2.8.20, the module does not properly validate serialized values processed through the Redis RESTOR…

redis redisbloom | Remote | Memory Corruption
May 05, 2026 May 07, 2026
May 05, 2026
May 07, 2026
8.8 HIGH
CVE-2026-25588 — RedisTimeSeries RESTORE invalid memory access may allow remote code execution

RedisTimeSeries is a time-series module for Redis. In all versions before 1.12.14 of RedisTimeSeries, the module does not properly validate serialized values processed through the Redis RESTORE comma…

redis redistimeseries | Remote | Memory Corruption
May 05, 2026 May 07, 2026
May 05, 2026
May 07, 2026
8.8 HIGH
CVE-2026-25243 — redis-server RESTORE invalid memory access may allow remote code execution

Redis is an in-memory data structure store. In versions of redis-server up to 8.6.3, the RESTORE command does not properly validate serialized values. An authenticated attacker with permission to exe…

redis | Remote | Memory Corruption
May 05, 2026 May 06, 2026
May 05, 2026
May 06, 2026
8.1 HIGH
CVE-2026-23631 — redis-server Lua use-after-free may allow remote code execution

Redis is an in-memory data structure store. In all versions of redis-server with Lua scripting, an authenticated attacker can exploit the master-replica synchronization mechanism to trigger a use-aft…

redis | Remote | Memory Corruption
May 05, 2026 May 06, 2026
May 05, 2026
May 06, 2026
8.8 HIGH
CVE-2026-23479 — redis-server use-after-free in unblock client flow may allow remote code execution

Redis is an in-memory data structure store. In redis-server from 7.2.0 until 8.6.3, the unblock client flow does not handle an error return from `processCommandAndResetClient` when re-executing a blo…

redis | Remote | Memory Corruption
May 05, 2026 May 06, 2026
May 05, 2026
May 06, 2026
7.4 HIGH
CVE-2026-7865 — Hidden Console Command

A hidden console command is vulnerable to command injection flaw when control characters are passed to its second argument.  A third party researcher Eugene Lim had discovered vulnerability in the w…

Remote | Injection
May 05, 2026 May 07, 2026
May 05, 2026
May 07, 2026
2.6 LOW
CVE-2026-7846 — chatchat-space Langchain-Chatchat OpenAI-Compatible File Upload API openai_routes.py file…

A vulnerability has been found in chatchat-space Langchain-Chatchat up to 0.3.1.3. Impacted is the function files of the file libs/chatchat-server/chatchat/server/api_server/openai_routes.py of the c…

langchain-chatchat | Path Traversal
May 05, 2026 May 05, 2026
May 05, 2026
May 05, 2026
2.6 LOW
CVE-2026-7845 — chatchat-space Langchain-Chatchat Vision Chat Paste Image dialogue.py PIL.Image.tobytes w…

A flaw has been found in chatchat-space Langchain-Chatchat up to 0.3.1.3. This issue affects the function PIL.Image.tobytes of the file libs/chatchat-server/chatchat/webui_pages/dialogue/dialogue.py …

langchain-chatchat | Cryptography
May 05, 2026 May 05, 2026
May 05, 2026
May 05, 2026
6.3 MEDIUM
CVE-2026-7844 — chatchat-space Langchain-Chatchat Compatible File Service openai_routes.py delete_file mi…

A vulnerability was detected in chatchat-space Langchain-Chatchat up to 0.3.1.3. This vulnerability affects the function files/list_files/retrieve_file/retrieve_file_content/delete_file of the file l…

langchain-chatchat | Authentication
May 05, 2026 May 05, 2026
May 05, 2026
May 05, 2026
8.6 HIGH
CVE-2026-7412 — Eclipse BaSyx Java Server SDK Blind HTTP Request Forgery

In Eclipse BaSyx Java Server SDK versions prior to 2.0.0-milestone-10, the Operation Delegation feature fails to validate the destination URI of delegated requests. An unauthenticated remote attacker…

Remote | Server-Side Request Forgery
May 05, 2026 May 06, 2026
May 05, 2026
May 06, 2026
10.0 CRITICAL
CVE-2026-7411 — Eclipse BaSyx Java Server SDK Remote Code Execution (RCE) via Path Traversal

In Eclipse BaSyx Java Server SDK versions prior to 2.0.0-milestone-10, inadequate path normalization in the Submodel HTTP API allows an unauthenticated remote attacker to perform a path traversal att…

Remote | Path Traversal
May 05, 2026 May 06, 2026
May 05, 2026
May 06, 2026
Showing 20 of 5726 Results