Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.8 HIGH
CVE-2026-42215 — GitPython: Command injection via Git options bypass

GitPython is a python library used to interact with Git repositories. From version 3.1.30 to before version 3.1.47, GitPython blocks dangerous Git options such as --upload-pack and --receive-pack by …

gitpython | Remote | Injection
May 07, 2026 May 07, 2026
May 07, 2026
May 07, 2026
7.8 HIGH
CVE-2026-42214 — Improper Control of Generation of Code ('Code Injection') in dail8859/NotepadNext

Notepad Next is a cross-platform, reimplementation of Notepad++. Prior to version 0.14, NotepadNext's detectLanguageFromExtension() function interpolates a file's extension directly into a Lua script…

| Injection
May 07, 2026 May 07, 2026
May 07, 2026
May 07, 2026
7.1 HIGH
CVE-2026-41906 — FreeScout: Conversation Change-Customer Cross-Mailbox Authorization Bypass

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.214, the Change Customer modal correctly hides out-of-scope customers through the mailbox-filte…

Remote | Authorization
May 07, 2026 May 07, 2026
May 07, 2026
May 07, 2026
7.7 HIGH
CVE-2026-41905 — FreeScout vulnerable to SSRF via Helper::sanitizeRemoteUrl: redirect destination not re-v…

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.217, Helper::sanitizeRemoteUrl() in app/Misc/Helper.php follows HTTP redirects via curlGetLastR…

Remote | Server-Side Request Forgery
May 07, 2026 May 07, 2026
May 07, 2026
May 07, 2026
7.6 HIGH
CVE-2026-41904 — FreeScout Stored XSS vulnerability in mailbox auto-reply: payload reaches every customer'…

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.217, a user with updateAutoReply permission can store an XSS payload in the mailbox auto-reply …

Remote | Cross-Site Scripting
May 07, 2026 May 07, 2026
May 07, 2026
May 07, 2026
5.4 MEDIUM
CVE-2026-41903 — FreeScout IDOR Vulnerability: PERM_EDIT_USERS allows modifying any user's notification su…

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.217, a user holding the PERM_EDIT_USERS permission (intended for general user-profile editing) …

Remote | Authorization
May 07, 2026 May 07, 2026
May 07, 2026
May 07, 2026
9.1 CRITICAL
CVE-2026-41902 — FreeScout's user invitation hash never expires: permanent unauthenticated account takeove…

FreeScout is a free help desk and shared inbox built with PHP's Laravel framework. Prior to version 1.8.217, the /user-setup/{hash} endpoint accepts a 60-character random invite_hash to set a new use…

Remote | Authentication
May 07, 2026 May 07, 2026
May 07, 2026
May 07, 2026
7.0 HIGH
CVE-2026-41653 — BentoPDF: Stored XSS via Markdown Editor Leading to Persistent File Exfiltration

BentoPDF is a client-side PDF toolkit that is self hostable. Prior to version 2.8.3, a cross-site scripting vulnerability was identified in BentoPD. An attacker may be able to execute arbitrary JavaS…

Remote | Cross-Site Scripting
May 07, 2026 May 07, 2026
May 07, 2026
May 07, 2026
6.5 MEDIUM
CVE-2026-8081 — router-for-me CLIProxyAPI api_tools.go server-side request forgery

A vulnerability has been found in router-for-me CLIProxyAPI 6.9.29. Affected by this issue is some unknown functionality of the file internal/api/handlers/management/api_tools.go of the component API…

Remote | Server-Side Request Forgery
May 07, 2026 May 07, 2026
May 07, 2026
May 07, 2026
9.8 CRITICAL
CVE-2026-37709 — Snipe-IT Insecure Permissions Code Execution Vulnerability

Insecure Permissions vulnerability in grokability snipe-it v.8.4.0 and before and fixed after 2026-03-10 commit 676a9958 allows a remote attacker to execute arbitrary code via the app/Http/Controller…

Remote | Misconfiguration
May 07, 2026 May 07, 2026
May 07, 2026
May 07, 2026
9.8 CRITICAL
CVE-2026-7415 — Open MQTT orchestration without read/write ACLs in Yarbo robot firmware

The MQTT broker embedded in Yarbo firmware v2.3.9 is configured to allow anonymous connections with no topic-level read or write ACLs. Any host on the same network can subscribe to sensitive telemetr…

Remote | Authentication
May 07, 2026 May 07, 2026
May 07, 2026
May 07, 2026
9.8 CRITICAL
CVE-2026-7414 — Hardcoded credentials in Yarbo robot firmware

Yarbo firmware v2.3.9 contains hardcoded administrative credentials embedded in the firmware image. These credentials are identical across all devices running this firmware and cannot be changed or r…

Remote | Authentication
May 07, 2026 May 07, 2026
May 07, 2026
May 07, 2026
7.2 HIGH
CVE-2026-7413 — Persistent undocumented backdoor access in Yarbo robot

A hidden, persistent backdoor was found in Yarbo firmware v2.3.9 that provides remote, unauthenticated (or weakly authenticated) access to privileged functionality. The backdoor is undocumented, cann…

Remote | Authentication
May 07, 2026 May 07, 2026
May 07, 2026
May 07, 2026
9.1 CRITICAL
CVE-2026-7821 — Ivanti EPMM Certificate Validation Vulnerability (Information Disclosure)

Improper certificate validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticated attacker to enroll a device belonging to a restricted set of unenrolled…

endpoint_manager_mobile | Remote | Misconfiguration
May 07, 2026 May 07, 2026
May 07, 2026
May 07, 2026
7.2 HIGH
CVE-2026-6973 — Ivanti EPMM Remote Code Execution Vulnerability

An Improper Input Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remotely authenticated user with administrative access to achieve remote code execution.

endpoint_manager_mobile | Remote | Injection
May 07, 2026 May 07, 2026
May 07, 2026
May 07, 2026
9.8 CRITICAL
CVE-2026-5788 — Ivanti EPMM Improper Access Control Remote Code Execution

An Improper Access Control in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticated attacker to invoke arbitrary methods.

endpoint_manager_mobile | Remote | Authorization
May 07, 2026 May 07, 2026
May 07, 2026
May 07, 2026
9.1 CRITICAL
CVE-2026-5787 — Ivanti EPMM Certificate Validation Vulnerability (Certificate Impersonation)

An Improper Certificate Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticated attacker to impersonate registered Sentry hosts and obtain valid CA-…

endpoint_manager_mobile | Remote | Misconfiguration
May 07, 2026 May 07, 2026
May 07, 2026
May 07, 2026
8.8 HIGH
CVE-2026-5786 — Ivanti EPMM Improper Access Control Remote Authentication Bypass

An Improper Access Control vulnerability in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote authenticated attacker to gain administrative access.

endpoint_manager_mobile | Remote | Authorization
May 07, 2026 May 07, 2026
May 07, 2026
May 07, 2026
5.4 MEDIUM
CVE-2026-36388 — "PHPGurukal Hospital Management System XSS"

A Cross-Site Scripting (XSS) vulnerability was found in PHPGurukal Hospital Management System v4.0 in the /hospital/hms/edit-profile.php page. This flaw allows an authenticated attacker (patient) to …

Remote | Cross-Site Scripting
May 07, 2026 May 07, 2026
May 07, 2026
May 07, 2026
6.5 MEDIUM
CVE-2026-36387 — Codeastro Membership Management System Remote File Upload RCE

A Remote Code Execution vulnerability was found in CODEASTRO Membership Management System v1.0 in /add_members.php. This vulnerability affects the file upload functionality, where improper file sanit…

Remote | Injection
May 07, 2026 May 07, 2026
May 07, 2026
May 07, 2026
Showing 20 of 5855 Results