Latest CVE Feed

Vulnerabilities published in the last 30 days. Filter by severity, exploit status, or attack vector.

Score
Vulnerability
Published
8.2 HIGH
CVE-2026-46510 — Prototype pollution in form-data-objectizer via bracket-notation form keys

form-data-objectizer converts FormData to object. Prior to 1.0.1, form-data-objectizer walks bracket-notation form keys (e.g. name[sub]) into nested objects without filtering __proto__, constructor, …

Remote | Misconfiguration
May 29, 2026 May 29, 2026
May 29, 2026
May 29, 2026
9.3 CRITICAL
CVE-2026-46376 — FreePBX: Unauthenticated Use of Hard-Coded Credentials Vulnerability in FreePBX UCP Inter…

FreePBX is an open source IP PBX. From 15.0.42 to before 16.0.45 and 17.0.7, unauthenticated users may be able to access the User Control Panel (UCP) using hard-coded initial template credentials if …

Remote | Authentication
May 29, 2026 May 29, 2026
May 29, 2026
May 29, 2026
6.9 MEDIUM
CVE-2026-46337 — WWBN AVideo: Unauthenticated Arbitrary Image Read via Path Traversal in `view/img/image40…

WWBN AVideo is an open source video platform. In 29.0 and earlier, an unauthenticated remote attacker can read arbitrary image files anywhere on disk that the PHP user can open — including private us…

avideo | Remote | Path Traversal
May 29, 2026 May 29, 2026
May 29, 2026
May 29, 2026
6.9 MEDIUM
CVE-2026-45731 — WWBN AVideo: Authenticated Arbitrary File Read in view/update.php

WWBN AVideo is an open source video platform. In 29.0 and earlier, view/update.php reads $_POST['updateFile'] as a relative path under updatedb/ and passes it to PHP's file() for line-by-line executi…

avideo | Remote | Path Traversal
May 29, 2026 May 29, 2026
May 29, 2026
May 29, 2026
8.1 HIGH
CVE-2026-45707 — n8n-MCP: Multi-tenant MCP requests fall back to process-level n8n credentials when tenant…

n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior to 2.51.2, when ENABLE_MULTI_TENANT=true, the HTTP transport documents that th…

n8n-mcp | Remote | Authorization
May 29, 2026 May 29, 2026
May 29, 2026
May 29, 2026
5.3 MEDIUM
CVE-2026-45620 — AVideo CVE-2026-43881 incomplete fix - `objects/mention.json.php:17` is an unauthenticate…

WWBN AVideo is an open source video platform. In 29.0 and earlier, objects/mention.json.php has no User::loginCheck() or admin gate. It only has an entry guard: preg_match('/^@/', $_REQUEST['term']) …

avideo | Remote | Authentication
May 29, 2026 May 29, 2026
May 29, 2026
May 29, 2026
6.5 MEDIUM
CVE-2026-45619 — AVideo CVE-2026-43884 incomplete fix - `isSSRFSafeURL()` call sites still discard the `$r…

WWBN AVideo is an open source video platform. In 29.0 and earlier, EpgParser.php, plugin/AI/receiveAsync.json.php, and other locations do not use the $resolvedIP out-param of isSSRFSafeURL() for DNS …

avideo | Remote | Server-Side Request Forgery
May 29, 2026 May 29, 2026
May 29, 2026
May 29, 2026
8.2 HIGH
CVE-2026-45615 — mouse07410/asn1c: 1-byte Heap Out-of-Bounds Read in `INTEGER_decode_oer` via Malformed OE…

mouse07410/asn1c is an ASN.1 compiler. In 1.4 and earlier, a memory safety vulnerability was identified in the OER decoding skeleton files generated by asn1c (specifically INTEGER_oer.c). When parsin…

Remote | Memory Corruption
May 29, 2026 May 29, 2026
May 29, 2026
May 29, 2026
5.7 MEDIUM
CVE-2026-45610 — WWBN AVideo plugin/LoginControl/set.json.php: 2FA toggle endpoint has no CSRF protection,…

WWBN AVideo is an open source video platform. In 29.0 and earlier, there is a cross-site request forgery vulnerability on the 2FA toggle. plugin/LoginControl/set.json.php accepts POST type=set2FA val…

avideo | Remote | Cross-Site Request Forgery
May 29, 2026 May 29, 2026
May 29, 2026
May 29, 2026
6.5 MEDIUM
CVE-2026-45582 — n8n-MCP: Workflow telemetry sanitizer could retain partial values from URL-shaped node pa…

n8n-MCP is an MCP server that provides AI assistants access to n8n node documentation, properties, and operations. Prior to 2.51.3, the workflow telemetry sanitizer could retain partial fragments of …

n8n-mcp | Remote | Information Disclosure
May 29, 2026 May 29, 2026
May 29, 2026
May 29, 2026
5.4 MEDIUM
CVE-2026-45580 — WWBN AVideo Live: stored XSS via unescaped stream key in modeYoutubeLive.php class attrib…

WWBN AVideo is an open source video platform. In 29.0 and earlier, there is a stored cross-site scripting vulnerability. The Live plugin's "YouTube-style" view renders the live transmission's stream …

avideo | Remote | Cross-Site Scripting
May 29, 2026 May 29, 2026
May 29, 2026
May 29, 2026
8.8 HIGH
CVE-2026-45578 — WWBN AVideo Live: OS command injection in on_publish.php execAsync via unescaped m3u8 URL

WWBN AVideo is an open source video platform. In 29.0 and earlier, there is a classic shell-metacharacter injection. The YPTSocket notification branch in plugin/Live/on_publish.php builds an execAsyn…

avideo | Remote | Injection
May 29, 2026 May 29, 2026
May 29, 2026
May 29, 2026
7.8 HIGH
CVE-2026-45555 — Roslyn CodeLens MCP Server: Untrusted Roslyn Analyzer Execution via get_diagnostics Leads…

Roslyn CodeLens MCP Server is a Roslyn-based MCP server providing semantic code intelligence for .NET codebases. From 0.0.9 to 1.17.0, the get_diagnostics MCP tool loads and executes all DiagnosticAn…

| Supply Chain
May 29, 2026 May 29, 2026
May 29, 2026
May 29, 2026
8.3 HIGH
CVE-2026-44698 — Home Assistant: Cross-origin iframe access token exfiltration via WebView JS bridge callb…

Home Assistant is open source home automation software that puts local control and privacy first. Prior to 2026.4.1 for iOS and 2026.4.4 for Android, he Home Assistant Companion apps for Android and …

Remote | Cross-Site Scripting
May 29, 2026 May 29, 2026
May 29, 2026
May 29, 2026
7.6 HIGH
CVE-2026-44239 — FreePBX: Authenticated Local File Inclusion in Dashboard Module

FreePBX is an open source IP PBX. Prior to 16.0.22 and 17.0.5, the Dashboard module's getcontent AJAX handler includes PHP files based on user-supplied input without path sanitization. The $_REQUEST[…

Remote | Path Traversal
May 29, 2026 May 29, 2026
May 29, 2026
May 29, 2026
8.5 HIGH
CVE-2026-44238 — FreePBX: Authenticated SQL Injection via ORDER BY in CDR Reports

FreePBX is an open source IP PBX. Prior to 16.0.50 and 17.0.11, the CDR Reports module page allows SQL injection through the order and sort POST parameters. Authentication with a FreePBX Administrati…

Remote | Injection
May 29, 2026 May 29, 2026
May 29, 2026
May 29, 2026
7.6 HIGH
CVE-2026-44237 — FreePBX: Authenticated Access can lead to Subsequent OAuth2 Authentication Bypass in API …

FreePBX is an open source IP PBX. Prior to 17.0.8, the FreePBX api module's OAuth2 implementation does not sufficiently validate client credentials during token issuance. Knowledge of a valid client_…

Remote | Authentication
May 29, 2026 May 29, 2026
May 29, 2026
May 29, 2026
3.8 LOW
CVE-2026-40528 — OpenSC < 0.27.0 Buffer Overrun in do_key_value() via profile.c

OpenSC before 0.27.0, fixed in commit 0358817, contains a stack and heap buffer overrun vulnerability in the do_key_value() function in src/pkcs15init/profile.c that allows attackers to corrupt memor…

| Memory Corruption
May 29, 2026 May 29, 2026
May 29, 2026
May 29, 2026
3.8 LOW
CVE-2026-40510 — OpenSC < 0.27.0-rc1 Stack Buffer Overflow via piv_process_history() in card-piv.c

OpenSC before 0.27.0-rc1, fixed in commit 3f24f0b, contains a stack buffer overflow vulnerability in piv_process_history() in src/libopensc/card-piv.c that allows physically present attackers to trig…

| Memory Corruption
May 29, 2026 May 29, 2026
May 29, 2026
May 29, 2026
5.3 MEDIUM
CVE-2026-10075 — Interinfo|DreamMaker - Path Traversal

DreamMaker developed by Interinfo has a Path Traversal vulnerability, allowing unauthenticated remote attackers to read file names under arbitrary path by exploiting an Absolute Path Traversal vulner…

Remote | Path Traversal
May 29, 2026 May 29, 2026
May 29, 2026
May 29, 2026
Showing 20 of 6987 Results