Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
9.3 CRITICAL
CVE-2026-40329 — SQL Injection vulnerability via sortBy in beanFeed

Masa CMS is an open source content management system. In versions 7.5.2 and earlier, a SQL injection vulnerability exists in the beanFeed.cfc component within the getQuery function's processing of th…

masacms | Remote | Injection
May 05, 2026 May 05, 2026
May 05, 2026
May 05, 2026
7.8 HIGH
CVE-2026-40280 — Gotenberg SSRF via case-insensitive URL scheme bypass in webhook and downloadFrom deny-li…

Gotenberg is an API-based document conversion tool. In versions 8.30.1 and earlier, the default private-IP deny-lists for the --webhook-deny-list and --api-download-from-deny-list flags use a case-se…

gotenberg | Remote | Server-Side Request Forgery
May 05, 2026 May 08, 2026
May 05, 2026
May 08, 2026
6.1 MEDIUM
CVE-2026-38947 — FluentCMS TextHTML Plugin Cross Site Scripting Vulnerability

FluentCMS 1.2.3 is vulnerable to Cross Site Scripting (XSS) in TextHTML plugin.

Remote | Cross-Site Scripting
May 05, 2026 May 06, 2026
May 05, 2026
May 06, 2026
5.4 MEDIUM
CVE-2026-35453 — PhpSpreadsheet XSS via number format text substitution in HTML Writer

PhpSpreadsheet is a library for reading and writing spreadsheet files. In versions 1.30.3 and earlier, 2.0.0 through 2.1.15, 2.2.0 through 2.4.4, 3.3.0 through 3.10.4, and 4.0.0 through 5.6.0, the HT…

phpspreadsheet | Remote | Cross-Site Scripting
May 05, 2026 May 08, 2026
May 05, 2026
May 08, 2026
8.8 HIGH
CVE-2026-35397 — jupyter-server path traversal allows access to sibling directories sharing root_dir name …

Jupyter Server is the backend for Jupyter web applications. In versions 2.17.0 and earlier, a path traversal vulnerability in the REST API allows an authenticated user to escape the configured root_d…

jupyter_server | Remote | Path Traversal
May 05, 2026 May 08, 2026
May 05, 2026
May 08, 2026
7.0 HIGH
CVE-2026-34596 — Sandboxie-Plus local privilege escalation via TOCTOU race condition in UpdUtil addon inst…

Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, a Time-of-Check-to-Time-of-Use (TOCTOU) race condition exists during addon installation.…

sandboxie | Race Condition
May 05, 2026 May 07, 2026
May 05, 2026
May 07, 2026
5.3 MEDIUM
CVE-2026-34527 — Sandboxie-Plus EditPassword hash entropy reduced from 160 bits to 80 bits due to incorrec…

Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, SbieIniServer::HashPassword converts a SHA-1 digest to hexadecimal incorrectly. The high…

sandboxie | Remote | Cryptography
May 05, 2026 May 08, 2026
May 05, 2026
May 08, 2026
8.8 HIGH
CVE-2026-34464 — Sandboxie-Plus NamedPipeServer OpenHandler stack overflow via unterminated server field

Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, NamedPipeServer::OpenHandler copies the server field from NAMED_PIPE_OPEN_REQ into a fix…

sandboxie | Memory Corruption
May 05, 2026 May 07, 2026
May 05, 2026
May 07, 2026
7.8 HIGH
CVE-2026-34462 — Sandboxie-Plus ProcessServer boxname stack buffer overflows via unterminated wide string …

Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, several ProcessServer handlers (KillAllHandler, SuspendAllHandler, and RunSandboxedHandl…

sandboxie | Memory Corruption
May 05, 2026 May 07, 2026
May 05, 2026
May 07, 2026
7.8 HIGH
CVE-2026-34461 — Sandboxie-Plus SbieIniServer RunSbieCtrl stack buffer overflow allows local privilege esc…

Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, the SbieIniServer RunSbieCtrl handler contains a stack buffer overflow. The MSGID_SBIE_I…

sandboxie | Memory Corruption
May 05, 2026 May 07, 2026
May 05, 2026
May 07, 2026
8.8 HIGH
CVE-2026-34459 — Sandboxie-Plus sandbox escape via uninitialized memory leak and stack overflow in GetRawI…

Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, the SbieSvc proxy service's GetRawInputDeviceInfoSlave handler contains two vulnerabilit…

sandboxie | Information Disclosure
May 05, 2026 May 07, 2026
May 05, 2026
May 07, 2026
9.3 CRITICAL
CVE-2026-34458 — Sandboxie-Plus privilege escalation via INI CRLF injection bypassing EditAdminOnly

Sandboxie-Plus is an open source sandbox-based isolation software for Windows. In versions 1.17.2 and earlier, an INI injection vulnerability allows any standard local user to bypass configuration re…

sandboxie | Injection
May 05, 2026 May 07, 2026
May 05, 2026
May 07, 2026
9.8 CRITICAL
CVE-2026-34084 — PhpSpreadsheet SSRF and RCE via PHP stream wrappers in IOFactory::load

PhpSpreadsheet is a library for reading and writing spreadsheet files. In versions 1.30.2 and earlier, 2.0.0 through 2.1.14, 2.2.0 through 2.4.3, 3.3.0 through 3.10.3, and 4.0.0 through 5.5.0, when t…

phpspreadsheet | Remote | Server-Side Request Forgery
May 05, 2026 May 08, 2026
May 05, 2026
May 08, 2026
8.3 HIGH
CVE-2026-33975 — twenty-server SSRF protection bypass via IPv4-mapped IPv6 address normalization

Twenty is an open source CRM built with NestJS (Node.js). In versions 1.18.0 and earlier, the SSRF protection in twenty-server's SecureHttpClientService can be bypassed using IPv4-mapped IPv6 address…

twenty | Remote | Server-Side Request Forgery
May 05, 2026 May 06, 2026
May 05, 2026
May 06, 2026
8.2 HIGH
CVE-2026-33489 — CoreDNS transfer plugin subzone ACL bypass via lexicographic zone comparison

CoreDNS is a DNS server that chains plugins. In versions prior to 1.14.3, the transfer plugin can select the wrong ACL stanza when both a parent zone and a more-specific subzone are configured. The l…

coredns | Remote | Misconfiguration
May 05, 2026 May 08, 2026
May 05, 2026
May 08, 2026
5.3 MEDIUM
CVE-2026-33420 — Vaultwarden missing authorization check allows Manager-role users to enumerate all collec…

Vaultwarden is a Bitwarden-compatible server written in Rust. In version 1.35.4 and earlier, the get_org_collections_details endpoint (GET /api/organizations/{org_id}/collections/details) is missing …

vaultwarden | Remote | Authorization
May 05, 2026 May 08, 2026
May 05, 2026
May 08, 2026
9.4 CRITICAL
CVE-2026-33324 — SQLBot prompt injection allows arbitrary SQL execution and remote code execution

SQLBot is an intelligent Text-to-SQL system based on large language models and RAG. In versions 1.7.0 and earlier, the Text2SQL chat interface is vulnerable to prompt injection. The user-provided que…

sqlbot | Remote | Injection
May 05, 2026 May 08, 2026
May 05, 2026
May 08, 2026
8.7 HIGH
CVE-2026-33190 — CoreDNS TSIG authentication bypass on encrypted DNS transports

CoreDNS is a DNS server that chains plugins. In versions prior to 1.14.3, the tsig plugin can be bypassed on non-plain-DNS transports (DoT, DoH, DoH3, DoQ, and gRPC) because it trusts the transport w…

coredns | Remote | Authentication
May 05, 2026 May 08, 2026
May 05, 2026
May 08, 2026
8.7 HIGH
CVE-2026-32936 — CoreDNS DoH GET path missing size validation causes CPU and memory amplification

CoreDNS is a DNS server that chains plugins. In versions prior to 1.14.3, the DNS-over-HTTPS (DoH) GET path accepts oversized dns= query parameter values and performs URL query parsing, base64 decodi…

coredns | Remote | Denial of Service
May 05, 2026 May 08, 2026
May 05, 2026
May 08, 2026
8.7 HIGH
CVE-2026-32934 — CoreDNS DNS-over-QUIC unbounded goroutine growth leads to denial of service

CoreDNS is a DNS server that chains plugins. In versions prior to 1.14.3, the DNS-over-QUIC (DoQ) server can be driven into unbounded goroutine and memory growth by a remote client that opens many QU…

coredns | Remote | Denial of Service
May 05, 2026 May 08, 2026
May 05, 2026
May 08, 2026
Showing 20 of 5591 Results